Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-22860 — Rack has a Directory Traversal via Rack:Directory

Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory`’s path check used a string prefix match on the expanded path. A request like `/../root_exam…

rack | Remote | Path Traversal
Feb 18, 2026 Feb 19, 2026
Feb 18, 2026
Feb 19, 2026
8.8 HIGH
CVE-2025-70064 — PHPGurukul Hospital Management System Privilege Escalation

PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient) can directly access the Administrator Dashboard and all sub-modules (e.g., Us…

hospital_management_system | Remote | Authorization
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
6.5 MEDIUM
CVE-2025-70063 — PHPGurukul Hospital Management System IDOR

The 'Medical History' module in PHPGurukul Hospital Management System v4.0 contains an Insecure Direct Object Reference (IDOR) vulnerability. The application fails to verify that the requested 'viewi…

hospital_management_system | Remote | Authorization
Feb 18, 2026 Feb 26, 2026
Feb 18, 2026
Feb 26, 2026
6.5 MEDIUM
CVE-2025-70062 — PHPGurukul Hospital Management System CSRF Vulnerability

PHPGurukul Hospital Management System v4.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the 'Add Doctor' module. The application fails to enforce CSRF token validation on the add-doc…

hospital_management_system | Remote | Cross-Site Request Forgery
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
5.4 MEDIUM
CVE-2025-69287 — BSV Blockchain SDK has an Authentication Signature Data Preparation Vulnerability

The BSV Blockchain SDK is a unified TypeScript SDK for developing scalable apps on the BSV Blockchain. Prior to version 2.0.0, a cryptographic vulnerability in the TypeScript SDK's BRC-104 authentica…

Remote | Cryptography
Feb 18, 2026 Feb 19, 2026
Feb 18, 2026
Feb 19, 2026
7.8 HIGH
CVE-2026-2659 — Squirrel sqfuncstate.cpp PopTarget out-of-bounds

A vulnerability was determined in Squirrel up to 3.2. Affected by this vulnerability is the function SQFuncState::PopTarget of the file src/squirrel/squirrel/sqfuncstate.cpp. Executing a manipulation…

squirrel | Memory Corruption
Feb 18, 2026 Feb 20, 2026
Feb 18, 2026
Feb 20, 2026
5.3 MEDIUM
CVE-2026-2658 — newbee-ltd newbee-mall Multiple Endpoints cross-site request forgery

A vulnerability was found in newbee-ltd newbee-mall up to a069069b07027613bf0e7f571736be86f431faee. Affected is an unknown function of the component Multiple Endpoints. Performing a manipulation resu…

newbee-mall | Remote | Cross-Site Request Forgery
Feb 18, 2026 Feb 19, 2026
Feb 18, 2026
Feb 19, 2026
8.2 HIGH
CVE-2026-24708 — OpenStack Nova Data Destruction Vulnerability

An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user ma…

nova | Remote | Path Traversal
Feb 18, 2026 Feb 21, 2026
Feb 18, 2026
Feb 21, 2026
6.8 MEDIUM
CVE-2026-20144 — Sensitive Information Disclosure in ''_internal'' index in Splunk Enterprise

In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.8, and 9.2.11, and Splunk Cloud Platform versions below 10.2.2510.0, 10.1.2507.11, 10.0.2503.9, and 9.3.2411.120, a user of a Splunk Sea…

splunk splunk_cloud_platform | Information Disclosure
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
6.8 MEDIUM
CVE-2026-20142 — Sensitive Information Disclosure in "_internal" index in Splunk Enterprise

In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.9, and 9.2.11, a user of a Splunk Search Head Cluster (SHC) deployment who holds a role with access to the Splunk `_internal` index coul…

splunk | Information Disclosure
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
6.5 MEDIUM
CVE-2026-20141 — Improper Access Control in Splunk Monitoring Console App

In Splunk Enterprise versions below 10.0.2, 10.0.3, 9.4.8, and 9.3.9, a low-privileged user who does not hold the "admin" Splunk role could access the Splunk Monitoring Console App endpoints due to a…

splunk | Remote | Authorization
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
4.3 MEDIUM
CVE-2026-20139 — Client-Side Denial of Service (DoS) through ''/splunkd/__raw/services/authentication/user…

In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.8, 9.3.9, and 9.2.12, and Splunk Cloud Platform versions below 10.2.2510.3, 10.1.2507.8, 10.0.2503.9, and 9.3.2411.121, a low-privileged user t…

splunk splunk_cloud_platform | Denial of Service
Feb 18, 2026 Feb 20, 2026
Feb 18, 2026
Feb 20, 2026
6.8 MEDIUM
CVE-2026-20138 — Sensitive Information Disclosure in "_internal" index in Splunk Enterprise

In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.9, and 9.2.11, a user of a Splunk Search Head Cluster (SHC) deployment who holds a role with access to the Splunk `_internal` index coul…

splunk | Information Disclosure
Feb 18, 2026 Feb 20, 2026
Feb 18, 2026
Feb 20, 2026
5.7 MEDIUM
CVE-2026-20137 — Risky Commands Safeguards Bypass through preloaded Data Models due to Path Traversal vuln…

In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.5, 9.3.7, and 9.2.9, and Splunk Cloud Platform versions below 10.1.2507.0, 10.0.2503.9, 9.3.2411.112, and 9.3.2408.122, a low-privileged user w…

splunk splunk_cloud_platform | Remote | Injection
Feb 18, 2026 Feb 20, 2026
Feb 18, 2026
Feb 20, 2026
9.8 CRITICAL
CVE-2025-70152 — Code-Projects Community Project Scholars Tracking System SQL Injection Vulnerability

code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php. These endpoints lac…

scholars_tracking_system | Remote | Injection
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
8.8 HIGH
CVE-2025-70151 — Code-Projects Scholars Tracking System Remote Code Execution Vulnerability

code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload. The endpoints update_profile_picture.php and upload_picture.…

scholars_tracking_system | Remote | Authentication
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
9.8 CRITICAL
CVE-2025-70150 — CodeAstro Membership Management System Unauthenticated Delete Member Vulnerability

CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id pa…

membership_management_system | Remote | Authentication
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
7.5 HIGH
CVE-2025-70148 — CodeAstro Membership Management System IDOR

Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users …

membership_management_system | Remote | Authentication
Feb 18, 2026 Feb 20, 2026
Feb 18, 2026
Feb 20, 2026
10.0 CRITICAL
CVE-2025-14009 — Zip Slip Vulnerability in nltk/nltk Leading to Remote Code Execution

A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py uses zipfile.extractall() without performing path…

nltk | Remote | Path Traversal
Feb 18, 2026 Mar 06, 2026
Feb 18, 2026
Mar 06, 2026
5.5 MEDIUM
CVE-2026-2657 — wren-lang wren Error Message wren_compiler.c printError stack-based overflow

A vulnerability has been found in wren-lang wren up to 0.4.0. This impacts the function printError of the file src/vm/wren_compiler.c of the component Error Message Handler. Such manipulation leads t…

wren | Memory Corruption
Feb 18, 2026 Feb 20, 2026
Feb 18, 2026
Feb 20, 2026
Showing 20 of 5065 Results