Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.0 MEDIUM
CVE-2026-26005 — ClipBucket v5 enables internal network scans via an SSRF vulnerability

ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #45, in Clip Bucket V5, The Remote Play allows creating video entries that reference external video URLs without uploading the…

clipbucket | Remote | Server-Side Request Forgery
Feb 12, 2026 Feb 18, 2026
Feb 12, 2026
Feb 18, 2026
6.1 MEDIUM
CVE-2026-26000 — XWiki Platform affected by click-jacking through CSS injection in comments

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.9.0, 17.4.6, and 16.10.13, it's possible using comments to inject CSS that would t…

xwiki | Remote | Cross-Site Scripting
Feb 12, 2026 Feb 19, 2026
Feb 12, 2026
Feb 19, 2026
9.8 CRITICAL
CVE-2026-25996 — Inspektor Gadget uses unsanitized ANSI Escape Sequences In `columns` Output Mode

Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. String fields from eBPF events in columns output mode are…

inspektor_gadget | Remote | Information Disclosure
Feb 12, 2026 Feb 23, 2026
Feb 12, 2026
Feb 23, 2026
6.0 MEDIUM
CVE-2026-0619 — Integer Wraparound DoS in Silicon Labs Matter Implementation

A reachable infinite loop via an integer wraparound is present in Silicon Labs' Matter SDK which allows an attacker to trigger a denial of service. A hard reset is required to recover the device.

Remote | Denial of Service
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
7.5 HIGH
CVE-2026-25949 — Traefik: TCP readTimeout bypass via STARTTLS on Postgres

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.8, there is a potential vulnerability in Traefik managing STARTTLS requests. An unauthenticated client can bypass Traefik entrypoint r…

traefik | Remote | Denial of Service
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
6.8 MEDIUM
CVE-2026-25933 — Arduino App Lab has Improper Data Validation in Internal Terminal Interface

Arduino App Lab is a cross-platform IDE for developing Arduino Apps. Prior to 0.4.0, a vulnerability was identified in the Terminal component of the arduino-app-lab application. The issue stems from …

app_lab | Injection
Feb 12, 2026 Feb 19, 2026
Feb 12, 2026
Feb 19, 2026
8.8 HIGH
CVE-2026-25922 — authentik has a Signature Verification Bypass via SAML Assertion Wrapping

authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Assertion Signature under Verification Certificate enab…

authentik | Remote | Authentication
Feb 12, 2026 Feb 18, 2026
Feb 12, 2026
Feb 18, 2026
7.1 HIGH
CVE-2026-25768 — LavinMQ is missing vhost access control

LavinMQ is a high-performance message queue & streaming server. Before 2.6.6, an authenticated user could access metadata in the broker they should not have access to. This vulnerability is fixed in …

lavinmq | Remote | Authorization
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
8.6 HIGH
CVE-2026-25767 — LavinMQ has incomplete shovel configuration validation

LavinMQ is a high-performance message queue & streaming server. Before 2.6.8, an authenticated user, with the “Policymaker” tag, could create shovels bypassing access controls. an authenticated user …

lavinmq | Remote | Authorization
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
8.6 HIGH
CVE-2026-25748 — authentik has a forward authentication bypass with broken cookie

authentik is an open-source identity provider. Prior to 2025.10.4 and 2025.12.4, with a malformed cookie it was possible to bypass authentication when using forward authentication in the authentik Pr…

authentik | Remote | Authentication
Feb 12, 2026 Feb 19, 2026
Feb 12, 2026
Feb 19, 2026
9.1 CRITICAL
CVE-2026-25227 — authentik affected by Remote Code Execution via Context Key Injection in PropertyMapping …

authentik is an open-source identity provider. From 2021.3.1 to before 2025.8.6, 2025.10.4, and 2025.12.4, when using delegated permissions, a User that has the permission Can view * Property Mapping…

authentik | Remote | Authorization
Feb 12, 2026 Feb 19, 2026
Feb 12, 2026
Feb 19, 2026
9.8 CRITICAL
CVE-2026-24895 — FrankenPHP affected by Path Confusion via Unicode casing in CGI path splitting allows exe…

FrankenPHP is a modern application server for PHP. Prior to 1.11.2, FrankenPHP’s CGI path splitting logic improperly handles Unicode characters during case conversion. The logic computes the split in…

frankenphp | Remote | Path Traversal
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
8.7 HIGH
CVE-2026-24894 — FrankenPHP leaks session data between requests in worker mode

FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSION superglobal is not correctly reset between requests. This allows a subsequent…

frankenphp | Remote | Information Disclosure
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
9.2 CRITICAL
CVE-2026-24044 — ESS Community Helm Chart has a weak server key generation method

Element Server Suite Community Edition (ESS Community) deploys a Matrix stack using the provided Helm charts and Kubernetes distribution. The ESS Community Helm Chart secrets initialization hook (usi…

Remote | Cryptography
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
9.8 CRITICAL
CVE-2025-70314 — Webfsd Buffer Overflow Vulnerability

webfsd 1.21 is vulnerable to a Buffer Overflow via a crafted request. This is due to the filename variable

webfsd | Remote | Memory Corruption
Feb 12, 2026 Feb 18, 2026
Feb 12, 2026
Feb 18, 2026
7.5 HIGH
CVE-2025-67433 — Open TFTP Server MultiThreaded Heap Buffer Overflow

A heap buffer overflow in the processRequest function of Open TFTP Server MultiThreaded v1.7 allows attackers to cause a Denial of Service (DoS) via a crafted DATA packet.

Remote | Memory Corruption
Feb 12, 2026 Feb 26, 2026
Feb 12, 2026
Feb 26, 2026
7.5 HIGH
CVE-2025-67432 — Monkeybread Software MBS DynaPDF Plugin Stack Overflow DoS

A stack overflow in the ZBarcode_Encode function of Monkeybread Software MBS DynaPDF Plugin v21.3.1.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

Remote | Memory Corruption
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
7.5 HIGH
CVE-2019-25347 — thesystem App 1.0 - 'username' SQL Injection

thesystem App 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating the username parameter. Attackers can inject malicious SQL code like ' or '1=1 …

password_management_application | Remote | Injection
Feb 12, 2026 Mar 02, 2026
Feb 12, 2026
Mar 02, 2026
7.5 HIGH
CVE-2019-25346 — thesystem 1.0 - 'server_name' SQL Injection

TheSystem 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating the 'server_name' parameter. Attackers can inject malicious SQL code like ' or '1=1…

password_management_application | Remote | Injection
Feb 12, 2026 Mar 02, 2026
Feb 12, 2026
Mar 02, 2026
8.5 HIGH
CVE-2019-25345 — RTK IIS Codec Service 6.4.10041.133 - 'RtkI2SCodec' Unquote Service Path

Realtek IIS Codec Service 6.4.10041.133 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in t…

| Misconfiguration
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
Showing 20 of 5070 Results