Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.1 CRITICAL
CVE-2026-25876 — PlaciPy is Missing Authorization on Assessment Results Endpoint

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes/results.routes.ts verify authentication but fails to enforce object-level auth…

placipy | Remote | Authorization
Feb 09, 2026 Feb 11, 2026
Feb 09, 2026
Feb 11, 2026
9.1 CRITICAL
CVE-2026-25810 — PlaciPy is Missing Object-Level Authorization in student.submission.routes.ts

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes/student.submission.routes.ts verify authentication but fails to enforce object…

placipy | Remote | Authorization
Feb 09, 2026 Feb 11, 2026
Feb 09, 2026
Feb 11, 2026
9.8 CRITICAL
CVE-2026-25809 — PlaciPy Code Execution Allowed Without Assessment Active State Validation

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the code evaluation endpoint does not validate the assessment lifecycle state before allowing executi…

placipy | Remote | Authorization
Feb 09, 2026 Feb 11, 2026
Feb 09, 2026
Feb 11, 2026
6.5 MEDIUM
CVE-2026-25806 — PlaciPy has Missing Authorization Checks on Student Management Endpoints (IDOR)

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the GET /api/students/:email PUT /api/students/:email/status, and DELETE /api/students/:email routes …

placipy | Remote | Authorization
Feb 09, 2026 Feb 11, 2026
Feb 09, 2026
Feb 11, 2026
7.5 HIGH
CVE-2026-25791 — Sliver has a DNS C2 OTP Bypass Allows Unauthenticated Session Flooding and Denial of Serv…

Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.7.0, the DNS C2 listener accepts unauthenticated TOTP bootstrap messages and allocates server-side DNS sess…

sliver | Remote | Authentication
Feb 09, 2026 Feb 23, 2026
Feb 09, 2026
Feb 23, 2026
5.8 MEDIUM
CVE-2026-25765 — Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url

Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Prior to 2.14.1, Faraday's build_exclusive_url method (in lib/faraday/connection.rb) uses Ruby…

faraday | Remote | Server-Side Request Forgery
Feb 09, 2026 Feb 20, 2026
Feb 09, 2026
Feb 20, 2026
8.8 HIGH
CVE-2026-25761 — Command injection via crafted filenames in Super-linter Action

Super-linter is a combination of multiple linters to run as a GitHub Action or standalone. From 6.0.0 to 8.3.0, the Super-linter GitHub Action is vulnerable to command injection via crafted filenames…

super-linter | Remote | Injection
Feb 09, 2026 Feb 28, 2026
Feb 09, 2026
Feb 28, 2026
5.8 MEDIUM
CVE-2026-25740 — Privilege escalation to the `CAP_NET_RAW` capability via the `programs.captive-browser` N…

captive browser, a dedicated Chrome instance to log into captive portals without messing with DNS settings. In 25.05 and earlier, when programs.captive-browser is enabled, any user of the system can …

| Misconfiguration
Feb 09, 2026 Feb 09, 2026
Feb 09, 2026
Feb 09, 2026
7.5 HIGH
CVE-2026-25639 — Axios affected by Denial of Service via __proto__ Key in mergeConfig

Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects…

axios | Remote | Denial of Service
Feb 09, 2026 Feb 18, 2026
Feb 09, 2026
Feb 18, 2026
5.8 MEDIUM
CVE-2026-25528 — LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. The LangSmith SDK's distributed tracing feature is vulnerable to Server-Side Request Forgery via malicious HTTP header…

Remote | Server-Side Request Forgery
Feb 09, 2026 Feb 09, 2026
Feb 09, 2026
Feb 09, 2026
4.8 MEDIUM
CVE-2026-2246 — AprilRobotics apriltag apriltag.c apriltag_detector_detect memory corruption

A security vulnerability has been detected in AprilRobotics apriltag up to 3.4.5. Affected by this vulnerability is the function apriltag_detector_detect of the file apriltag.c. The manipulation lead…

| Memory Corruption
Feb 09, 2026 Feb 09, 2026
Feb 09, 2026
Feb 09, 2026
4.8 MEDIUM
CVE-2026-2245 — CCExtractor MPEG-TS File ts_tables.c parse_PMT out-of-bounds

A vulnerability was identified in CCExtractor up to 183. This affects the function parse_PAT/parse_PMT in the library src/lib_ccx/ts_tables.c of the component MPEG-TS File Parser. Such manipulation l…

| Memory Corruption
Feb 09, 2026 Feb 09, 2026
Feb 09, 2026
Feb 09, 2026
6.3 MEDIUM
CVE-2026-25598 — Bypassing Logging of Outbound Connections Using sendto, sendmsg, and sendmmsg in Harden-R…

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Prior to 2.14.2, a security vulnerability has been identified in the Harden-Runner GitHub Action (Community …

harden-runner | Remote | Misconfiguration
Feb 09, 2026 Feb 28, 2026
Feb 09, 2026
Feb 28, 2026
8.6 HIGH
CVE-2026-25498 — Craft has a potential authenticated Remote Code Execution via malicious attached Behavior

Craft is a platform for creating digital experiences. In versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, a Remote Code Execution (RCE) vulnerability exists in Craft CMS where the ass…

craft_cms | Remote | Injection
Feb 09, 2026 Feb 19, 2026
Feb 09, 2026
Feb 19, 2026
8.8 HIGH
CVE-2026-25497 — Craft has a GraphQL Asset Mutation Privilege Escalation

Craft is a platform for creating digital experiences. In Craft versions from 4.0.0-RC1 to before 4.17.0-beta.1 and 5.9.0-beta.1, there is a Privilege Escalation vulnerability in Craft CMS’s GraphQL A…

craft_cms | Remote | Authorization
Feb 09, 2026 Feb 19, 2026
Feb 09, 2026
Feb 19, 2026
4.8 MEDIUM
CVE-2026-25496 — Craft has a stored XSS in Number Prefix & Suffix Fields

Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, a stored XSS vulnerability exists in the Number field type settings. Th…

craft_cms | Remote | Cross-Site Scripting
Feb 09, 2026 Feb 19, 2026
Feb 09, 2026
Feb 19, 2026
8.8 HIGH
CVE-2026-25495 — Craft has a SQL Injection in Element Indexes via criteria[orderBy]

Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the element-indexes/get-elements endpoint is vulnerable to SQL Injectio…

craft_cms | Remote | Injection
Feb 09, 2026 Feb 19, 2026
Feb 09, 2026
Feb 19, 2026
6.9 MEDIUM
CVE-2026-25494 — Craft has a SSRF in GraphQL Asset Mutation via Alternative IP Notation

Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the saveAsset GraphQL mutation uses filter_var(..., FILTER_VALIDATE_IP…

craft_cms | Remote | Injection
Feb 09, 2026 Feb 19, 2026
Feb 09, 2026
Feb 19, 2026
6.9 MEDIUM
CVE-2026-25493 — Craft has a SSRF in GraphQL Asset Mutation via HTTP Redirect

Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the saveAsset GraphQL mutation validates the initial URL hostname and r…

craft_cms | Remote | Server-Side Request Forgery
Feb 09, 2026 Feb 19, 2026
Feb 09, 2026
Feb 19, 2026
6.5 MEDIUM
CVE-2026-25492 — Craft has a save_images_Asset graphql mutation can be abused to exfiltrate AWS credential…

Craft CMS is a content management system. In Craft versions 3.5.0 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the save_images_Asset GraphQL mutation can be abused to fetch internal URLs by providin…

craft_cms | Remote | Server-Side Request Forgery
Feb 09, 2026 Feb 19, 2026
Feb 09, 2026
Feb 19, 2026
Showing 20 of 5071 Results