Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.5 HIGH
CVE-2026-26286 — SillyTavern has Server-Side Request Forgery (SSRF) via Asset Download Endpoint that Allow…

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. In versions prio…

sillytavern | Remote | Server-Side Request Forgery
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
6.6 MEDIUM
CVE-2026-26282 — NanaZip has DotNet Single file OOB Heap Read

NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, NanaZip has an out-of-bounds heap read in `.NET Single File` bundle header parser due to missing…

nanazip | Memory Corruption
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
9.8 CRITICAL
CVE-2025-67305 — RUCKUS Network Director SSH Key Hardcoded Vulnerability

In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user. These keys are identical across all deployments, allowing an attacker with network ac…

Remote | Authentication
Feb 19, 2026 Feb 23, 2026
Feb 19, 2026
Feb 23, 2026
7.6 HIGH
CVE-2026-27013 — Fabric.js Affected by Stored XSS via SVG Export

Fabric.js is a Javascript HTML5 canvas library. Prior to version 7.2.0, Fabric.js applies `escapeXml()` to text content during SVG export (`src/shapes/Text/TextSVGExportMixin.ts:186`) but fails to ap…

fabric.js | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 23, 2026
Feb 19, 2026
Feb 23, 2026
8.8 HIGH
CVE-2026-26318 — systeminformation has Command Injection via Unsanitized `locate` Output in `versions()`

systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in `versions()`. Version 5.31.0 fixe…

systeminformation | Injection
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
8.4 HIGH
CVE-2026-26280 — Systeminformation has a Command Injection via unsanitized interface parameter in wifi.js …

systeminformation is a System and OS information library for node.js. In versions prior to 5.30.8, a command injection vulnerability in the `wifiNetworks()` function allows an attacker to execute arb…

systeminformation | Injection
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
7.5 HIGH
CVE-2026-26278 — fast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit)

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 through 5.3.5, the XML parser can be…

fast-xml-parser fast-xml-parser | Remote | XML External Entity
Feb 19, 2026 Feb 23, 2026
Feb 19, 2026
Feb 23, 2026
7.5 HIGH
CVE-2026-26267 — rs-soroban-sdk #[contractimpl] macro calls inherent function instead of trait function wh…

soroban-sdk is a Rust SDK for Soroban contracts. Prior to versions 22.0.10, 23.5.2, and 25.1.1, the `#[contractimpl]` macro contains a bug in how it wires up function calls. `#[contractimpl]` generat…

rs-soroban-sdk | Remote | Authorization
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
7.1 HIGH
CVE-2026-26205 — opa-envoy-plugin has an Authorization Bypass via Double-Slash Path Misinterpretation in `…

opa-envoy-plugun is a plugin to enforce OPA policies with Envoy. Versions prior to 1.13.2-envoy-2 have a vulnerability in how the `input.parsed_path` field is constructed. HTTP request paths are trea…

Remote | Path Traversal
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
6.5 MEDIUM
CVE-2026-26203 — PJSIP's pjmedia-video has use-after-free in H264 packetizer when packetizing fragmented N…

PJSIP is a free and open source multimedia communication library. Versions prior to 2.17 have a critical heap buffer underflow vulnerability in PJSIP's H.264 packetizer. The bug occurs when processin…

pjsip | Memory Corruption
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
7.5 HIGH
CVE-2026-26202 — Penpot has Arbitrary File Read via create-font-variant RPC endpoint

Penpot is an open-source design tool for design and code collaboration. Prior to version 2.13.2, an authenticated user can read arbitrary files from the server by supplying a local file path (e.g. `/…

penpot | Remote | Path Traversal
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
7.5 HIGH
CVE-2026-26201 — emp3r0r Affected by Concurrent Map Access DoS (panic/crash)

emp3r0r is a C2 designed by Linux users for Linux environments. Prior to version 3.21.2, multiple shared maps are accessed without consistent synchronization across goroutines. Under concurrent activ…

emp3r0r | Remote | Race Condition
Feb 19, 2026 Feb 26, 2026
Feb 19, 2026
Feb 26, 2026
7.8 HIGH
CVE-2026-26200 — HDF5 Affected by H5T__conv_struct_opt Heap Buffer Overflow

HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 can trigger a write-based heap buffer overflow condition. This can lead to a den…

hdf5 | Memory Corruption
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
7.3 HIGH
CVE-2026-26193 — Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.44, aanually modifying chat history allows setting the `embeds` property on a r…

open_webui | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
7.3 HIGH
CVE-2026-26192 — Open WebUI vulnerable to Stored XSS via iFrame in citations model

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.7.0, aanually modifying chat history allows setting the `html` property within do…

open_webui | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
8.1 HIGH
CVE-2026-26189 — Trivy Action has a script injection via sourced env file in composite action

Trivy Action runs Trivy as GitHub action to scan a Docker container image for vulnerabilities. A command injection vulnerability exists in `aquasecurity/trivy-action` versions 0.31.0 through 0.33.1 d…

trivy_action | Remote | Injection
Feb 19, 2026 Feb 26, 2026
Feb 19, 2026
Feb 26, 2026
8.8 HIGH
CVE-2026-26063 — CediPay Affected by Improper Input Validation in Payment Processing

CediPay is a crypto-to-fiat app for the Ghanaian market. A vulnerability in CediPay prior to version 1.2.3 allows attackers to bypass input validation in the transaction API. The issue has been fixed…

Remote | Injection
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
9.8 CRITICAL
CVE-2025-67304 — Ruckus Network Director Hardcoded Database Credentials Vulnerability (Authentication Bypa…

In Ruckus Network Director (RND) < 4.5.0.54, the OVA appliance contains hardcoded credentials for the ruckus PostgreSQL database user. In the default configuration, the PostgreSQL service is accessib…

Remote | Authentication
Feb 19, 2026 Feb 23, 2026
Feb 19, 2026
Feb 23, 2026
9.2 CRITICAL
CVE-2026-27475 — SPIP < 4.4.9 Insecure Deserialization

SPIP before 4.4.9 allows Insecure Deserialization in the public area through the table_valeur filter and the DATA iterator, which accept serialized data. An attacker who can place malicious serialize…

spip | Remote | Information Disclosure
Feb 19, 2026 Feb 24, 2026
Feb 19, 2026
Feb 24, 2026
6.1 MEDIUM
CVE-2026-27474 — SPIP < 4.4.9 Cross-Site Scripting in Private Area (Incomplete Fix)

SPIP before 4.4.9 allows Cross-Site Scripting (XSS) in the private area, complementing an incomplete fix from SPIP 4.4.8. The echappe_anti_xss() function was not systematically applied to input, form…

spip | Remote | Cross-Site Scripting
Feb 19, 2026 Mar 02, 2026
Feb 19, 2026
Mar 02, 2026
Showing 20 of 5066 Results