Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.6 HIGH
CVE-2026-25498 — Craft has a potential authenticated Remote Code Execution via malicious attached Behavior

Craft is a platform for creating digital experiences. In versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, a Remote Code Execution (RCE) vulnerability exists in Craft CMS where the ass…

craft_cms | Remote | Injection
Feb 09, 2026 Feb 19, 2026
Feb 09, 2026
Feb 19, 2026
8.8 HIGH
CVE-2026-25497 — Craft has a GraphQL Asset Mutation Privilege Escalation

Craft is a platform for creating digital experiences. In Craft versions from 4.0.0-RC1 to before 4.17.0-beta.1 and 5.9.0-beta.1, there is a Privilege Escalation vulnerability in Craft CMS’s GraphQL A…

craft_cms | Remote | Authorization
Feb 09, 2026 Feb 19, 2026
Feb 09, 2026
Feb 19, 2026
4.8 MEDIUM
CVE-2026-25496 — Craft has a stored XSS in Number Prefix & Suffix Fields

Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, a stored XSS vulnerability exists in the Number field type settings. Th…

craft_cms | Remote | Cross-Site Scripting
Feb 09, 2026 Feb 19, 2026
Feb 09, 2026
Feb 19, 2026
8.8 HIGH
CVE-2026-25495 — Craft has a SQL Injection in Element Indexes via criteria[orderBy]

Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the element-indexes/get-elements endpoint is vulnerable to SQL Injectio…

craft_cms | Remote | Injection
Feb 09, 2026 Feb 19, 2026
Feb 09, 2026
Feb 19, 2026
6.9 MEDIUM
CVE-2026-25494 — Craft has a SSRF in GraphQL Asset Mutation via Alternative IP Notation

Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the saveAsset GraphQL mutation uses filter_var(..., FILTER_VALIDATE_IP…

craft_cms | Remote | Injection
Feb 09, 2026 Feb 19, 2026
Feb 09, 2026
Feb 19, 2026
6.9 MEDIUM
CVE-2026-25493 — Craft has a SSRF in GraphQL Asset Mutation via HTTP Redirect

Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the saveAsset GraphQL mutation validates the initial URL hostname and r…

craft_cms | Remote | Server-Side Request Forgery
Feb 09, 2026 Feb 19, 2026
Feb 09, 2026
Feb 19, 2026
6.5 MEDIUM
CVE-2026-25492 — Craft has a save_images_Asset graphql mutation can be abused to exfiltrate AWS credential…

Craft CMS is a content management system. In Craft versions 3.5.0 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the save_images_Asset GraphQL mutation can be abused to fetch internal URLs by providin…

craft_cms | Remote | Server-Side Request Forgery
Feb 09, 2026 Feb 19, 2026
Feb 09, 2026
Feb 19, 2026
4.8 MEDIUM
CVE-2026-25491 — Craft has a Stored XSS in Entry Types Name

Craft is a platform for creating digital experiences. From 5.0.0-RC1 to 5.8.21, Craft has a stored XSS via Entry Type names. The name is not sanitized when displayed in the Entry Types list. This vul…

craft_cms | Remote | Cross-Site Scripting
Feb 09, 2026 Feb 19, 2026
Feb 09, 2026
Feb 19, 2026
6.5 MEDIUM
CVE-2026-25480 — FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord…

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, FileStore maps cache keys to filenames using Unicode NFKD normalization and ord() substitution without separato…

litestar | Remote | Misconfiguration
Feb 09, 2026 Feb 17, 2026
Feb 09, 2026
Feb 17, 2026
6.5 MEDIUM
CVE-2026-25479 — Litestar has an AllowedHosts validation bypass due to unescaped regex metacharacters in c…

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, in litestar.middleware.allowed_hosts, allowlist entries are compiled into regex patterns in a way that allows r…

litestar | Remote | Misconfiguration
Feb 09, 2026 Feb 17, 2026
Feb 09, 2026
Feb 17, 2026
7.4 HIGH
CVE-2026-25478 — Litestar has a CORS origin allowlist bypass due to unescaped regex metacharacters in allo…

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, CORSConfig.allowed_origins_regex is constructed using a regex built from configured allowlist values and used w…

litestar | Remote | Information Disclosure
Feb 09, 2026 Feb 17, 2026
Feb 09, 2026
Feb 17, 2026
7.5 HIGH
CVE-2026-25231 — FileRise affected by an Unauthenticated File Read Due to Insufficient Access Control

FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 3.3.0, the application contains an unauthenticated file read vulnerability due to the lack of access control on the /uplo…

filerise | Remote | Information Disclosure
Feb 09, 2026 Feb 19, 2026
Feb 09, 2026
Feb 19, 2026
5.4 MEDIUM
CVE-2026-25230 — FileRise affected by HTML Injection using color property in file tags

FileRise is a self-hosted web file manager / WebDAV server. Prior to 3.3.0, an HTML Injection vulnerability allows an authenticated user to modify the DOM and add e.g. form elements that call certain…

filerise | Remote | Cross-Site Scripting
Feb 09, 2026 Feb 19, 2026
Feb 09, 2026
Feb 19, 2026
9.1 CRITICAL
CVE-2026-25057 — Zip Slip in MarkUs config upload allowing RCE

MarkUs is a web application for the submission and grading of student assignments. Prior to 2.9.1, instructors are able to upload a zip file to create an assignment from an exported configuration (co…

markus | Remote | Path Traversal
Feb 09, 2026 Feb 19, 2026
Feb 09, 2026
Feb 19, 2026
6.5 MEDIUM
CVE-2026-24900 — MarkUs has a submission-view IDOR exposes all student submissions

MarkUs is a web application for the submission and grading of student assignments. Prior to 2.9.1, the courses/<:course_id>/assignments/<:assignment_id>/submissions/html_content accepted a select_fil…

markus | Remote | Authorization
Feb 09, 2026 Feb 19, 2026
Feb 09, 2026
Feb 19, 2026
8.1 HIGH
CVE-2026-1529 — Org.keycloak.services.resources.organizations: keycloak: unauthorized organization regist…

A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target email within a legitimate invitation token's JSON Web Token (JWT) payload. This la…

keycloak | Remote | Authentication
Feb 09, 2026 Feb 10, 2026
Feb 09, 2026
Feb 10, 2026
8.8 HIGH
CVE-2026-1486 — Org.keycloak.protocol.oidc.grants: disabled identity providers are still accepted for jwt…

A flaw was found in Keycloak. A vulnerability exists in the jwt-authorization-grant flow where the server fails to verify if an Identity Provider (IdP) is enabled before issuing tokens. The issuer lo…

Remote | Authentication
Feb 09, 2026 Feb 10, 2026
Feb 09, 2026
Feb 10, 2026
5.4 MEDIUM
CVE-2025-14778 — Keycloak: incorrect ownership checks in /uma-policy/

A flaw was found in Keycloak. A significant Broken Access Control vulnerability exists in the UserManagedPermissionService (UMA Protection API). When updating or deleting a UMA policy associated with…

keycloak | Remote | Authorization
Feb 09, 2026 Feb 10, 2026
Feb 09, 2026
Feb 10, 2026
6.7 MEDIUM
CVE-2026-24777 — OpenProject has Improper Access Control on User Management allows user managers to lock a…

OpenProject is an open-source, web-based project management software. Prior to 17.0.2, users with the Manage Users permission can lock and unlock users. This functionality should only be possible for…

openproject | Remote | Authorization
Feb 09, 2026 Feb 11, 2026
Feb 09, 2026
Feb 11, 2026
8.7 HIGH
CVE-2026-24684 — FreeRDP has a Heap-use-after-free in play_thread

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, the RDPSND async playback thread can process queued PDUs after the channel is closed and internal state is freed, lea…

freerdp | Remote | Memory Corruption
Feb 09, 2026 Feb 10, 2026
Feb 09, 2026
Feb 10, 2026
Showing 20 of 5134 Results