Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.1 HIGH
CVE-2026-26189 — Trivy Action has a script injection via sourced env file in composite action

Trivy Action runs Trivy as GitHub action to scan a Docker container image for vulnerabilities. A command injection vulnerability exists in `aquasecurity/trivy-action` versions 0.31.0 through 0.33.1 d…

trivy_action | Remote | Injection
Feb 19, 2026 Feb 26, 2026
Feb 19, 2026
Feb 26, 2026
8.8 HIGH
CVE-2026-26063 — CediPay Affected by Improper Input Validation in Payment Processing

CediPay is a crypto-to-fiat app for the Ghanaian market. A vulnerability in CediPay prior to version 1.2.3 allows attackers to bypass input validation in the transaction API. The issue has been fixed…

Remote | Injection
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
9.8 CRITICAL
CVE-2025-67304 — Ruckus Network Director Hardcoded Database Credentials Vulnerability (Authentication Bypa…

In Ruckus Network Director (RND) < 4.5.0.54, the OVA appliance contains hardcoded credentials for the ruckus PostgreSQL database user. In the default configuration, the PostgreSQL service is accessib…

Remote | Authentication
Feb 19, 2026 Feb 23, 2026
Feb 19, 2026
Feb 23, 2026
9.2 CRITICAL
CVE-2026-27475 — SPIP < 4.4.9 Insecure Deserialization

SPIP before 4.4.9 allows Insecure Deserialization in the public area through the table_valeur filter and the DATA iterator, which accept serialized data. An attacker who can place malicious serialize…

spip | Remote | Information Disclosure
Feb 19, 2026 Feb 24, 2026
Feb 19, 2026
Feb 24, 2026
6.1 MEDIUM
CVE-2026-27474 — SPIP < 4.4.9 Cross-Site Scripting in Private Area (Incomplete Fix)

SPIP before 4.4.9 allows Cross-Site Scripting (XSS) in the private area, complementing an incomplete fix from SPIP 4.4.8. The echappe_anti_xss() function was not systematically applied to input, form…

spip | Remote | Cross-Site Scripting
Feb 19, 2026 Mar 02, 2026
Feb 19, 2026
Mar 02, 2026
6.4 MEDIUM
CVE-2026-27473 — SPIP < 4.4.9 Stored Cross-Site Scripting via Syndicated Sites

SPIP before 4.4.9 allows Stored Cross-Site Scripting (XSS) via syndicated sites in the private area. The #URL_SYNDIC output is not properly sanitized on the private syndicated site page, allowing an …

spip | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 24, 2026
Feb 19, 2026
Feb 24, 2026
5.3 MEDIUM
CVE-2026-27472 — SPIP < 4.4.9 Blind Server-Side Request Forgery via Syndicated Sites

SPIP before 4.4.9 allows Blind Server-Side Request Forgery (SSRF) via syndicated sites in the private area. When editing a syndicated site, the application does not verify that the syndication URL is…

spip | Remote | Server-Side Request Forgery
Feb 19, 2026 Feb 24, 2026
Feb 19, 2026
Feb 24, 2026
5.4 MEDIUM
CVE-2026-26059 — ChurchCRM has Stored Cross-Site Scripting (XSS) in GroupEditor.php

ChurchCRM is an open-source church management system. In versions prior to 6.8.2, it was possible for an authenticated user with permission to edit groups to store a JavaScript payload that would exe…

churchcrm | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
9.1 CRITICAL
CVE-2026-26057 — Skill Scanner Unsecured Network Binding Vulnerability

Skill Scanner is a security scanner for AI Agent Skills that detects prompt injection, data exfiltration, and malicious code patterns. A vulnerability in the API Server of Skill Scanner could allow a…

skill_scanner | Remote | Denial of Service
Feb 19, 2026 Feb 26, 2026
Feb 19, 2026
Feb 26, 2026
5.3 MEDIUM
CVE-2026-23621 — GFI MailEssentials AI < 22.4 ListServer.IsPathExist() Absolute Directory Traversal to Fil…

GFI MailEssentials AI versions prior to 22.4 contain an arbitrary directory existence enumeration vulnerability in the ListServer.IsPathExist() web method exposed at /MailEssentials/pages/MailSecurit…

mailessentials | Remote | Information Disclosure
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
4.8 MEDIUM
CVE-2026-2817 — Spring Data Geode Insecure Temporary Directory Usage

Use of insecure directory in Spring Data Geode snapshot import extracts archives into predictable, permissive directories under the system temp location. On shared hosts, a local user with basic priv…

| Information Disclosure
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
9.3 CRITICAL
CVE-2026-2409 — Delinea Cloud Suite SQL Injection

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Delinea Cloud Suite allows Argument Injection.This issue affects Cloud Suite: before 25.2 HF1.

Remote | Injection
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
5.1 MEDIUM
CVE-2026-2243 — Qemu-kvm: heap buffer out-of-bounds read in vmdk compressed grain parsing

A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of-bounds read vulnerability, potentially leading to a 12-byte leak of sensitive information or a denial of service condi…

qemu | Information Disclosure
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
9.8 CRITICAL
CVE-2026-26339 — Hyland Alfresco Transformation Service Argument Injection RCE

Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the argument injection vulnerability, which exists in the document processing function…

Feb 19, 2026 Mar 02, 2026
Feb 19, 2026
Mar 02, 2026
9.8 CRITICAL
CVE-2026-26338 — Hyland Alfresco Transformation Service SSRF

Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve server-side request forgery (SSRF) through the document processing functionality.

Feb 19, 2026 Mar 02, 2026
Feb 19, 2026
Mar 02, 2026
8.8 HIGH
CVE-2026-26337 — Hyland Alfresco Transformation Service Absolute Path Traversal Arbitrary File Read and SS…

Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve both arbitrary file read and server-side request forgery through the absolute path traversal.

Feb 19, 2026 Mar 02, 2026
Feb 19, 2026
Mar 02, 2026
5.3 MEDIUM
CVE-2026-23620 — GFI MailEssentials AI < 22.4 ListServer.IsDbExist() Absolute Directory Traversal to File …

GFI MailEssentials AI versions prior to 22.4 contain an arbitrary file existence enumeration vulnerability in the ListServer.IsDBExist() web method exposed at /MailEssentials/pages/MailSecurity/ListS…

mailessentials | Remote | Information Disclosure
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
5.4 MEDIUM
CVE-2026-23619 — GFI MailEssentials AI < 22.4 General Settings Local Domains Domain Description Stored XSS

GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Local Domains settings page. An authenticated user can supply HTML/JavaScript in the ctl00$Cont…

mailessentials | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
5.4 MEDIUM
CVE-2026-23618 — GFI MailEssentials AI < 22.4 Anti-Spam Spam Keyword Checking Subject Condition Stored XSS

GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Spam Keyword Checking (Subject) conditions interface. An authenticated user can supply HTML/Jav…

mailessentials | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
5.4 MEDIUM
CVE-2026-23617 — GFI MailEssentials AI < 22.4 Anti-Spam Spam Keyword Checking Body Condition Stored XSS

GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Spam Keyword Checking (Body) conditions interface. An authenticated user can supply HTML/JavaSc…

mailessentials | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
Showing 20 of 5070 Results