Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.2 HIGH
CVE-2026-25754 — AdonisJS multipart body parsing has Prototype Pollution issue

AdonisJS is a TypeScript-first web framework. Prior to versions 10.1.3 and 11.0.0-next.9, a prototype pollution vulnerability in AdonisJS multipart form-data parsing may allow a remote attacker to ma…

Remote | Misconfiguration
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
6.6 MEDIUM
CVE-2026-25749 — Heap Overflow in Vim

Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists in Vim's tag file resolution logic when processing the 'helpfile' option. The v…

vim | Memory Corruption
Feb 06, 2026 Feb 20, 2026
Feb 06, 2026
Feb 20, 2026
7.5 HIGH
CVE-2026-25644 — DataHub's LDAP Ingestion Source vulnerable to MITM attack through TLS downgrade

DataHub is an open-source metadata platform. Prior to version 1.3.1.8, the LDAP ingestion source is vulnerable to MITM attack through TLS downgrade. This issue has been patched in version 1.3.1.8.

datahub datahub | Remote | Misconfiguration
Feb 06, 2026 Feb 20, 2026
Feb 06, 2026
Feb 20, 2026
4.8 MEDIUM
CVE-2026-2069 — ggml-org llama.cpp GBNF Grammar llama-grammar.cpp llama_grammar_advance_stack stack-based…

A flaw has been found in ggml-org llama.cpp up to 55abc39. Impacted is the function llama_grammar_advance_stack of the file llama.cpp/src/llama-grammar.cpp of the component GBNF Grammar Handler. This…

llama.cpp | Memory Corruption
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
9.0 HIGH
CVE-2026-2068 — UTT 进取 520W formSyslogConf strcpy buffer overflow

A vulnerability was detected in UTT 进取 520W 1.7.7-180627. This issue affects the function strcpy of the file /goform/formSyslogConf. The manipulation of the argument ServerIp results in buffer overfl…

520w_firmware 520w | Remote | Memory Corruption
Feb 06, 2026 Feb 13, 2026
Feb 06, 2026
Feb 13, 2026
3.5 LOW
CVE-2026-25764 — OpenProject vulnerable to Stored HTML injection

OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an HTML injection vulnerability occurs in the time tracking function of OpenProject. The app…

openproject | Remote | Injection
Feb 06, 2026 Feb 13, 2026
Feb 06, 2026
Feb 13, 2026
9.9 CRITICAL
CVE-2026-25763 — Command Injection on OpenProject repositories leads to Remote Code Execution

OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an arbitrary file write vulnerability exists in OpenProject’s repository changes endpoint (/…

openproject | Remote | Path Traversal
Feb 06, 2026 Feb 13, 2026
Feb 06, 2026
Feb 13, 2026
6.5 MEDIUM
CVE-2026-25760 — Website Path Traversal / Arbitrary File Read (Authenticated) in Sliver

Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.6.11, a path traversal in the website content subsystem lets an authenticated operator read arbitrary files…

sliver | Remote | Path Traversal
Feb 06, 2026 Feb 19, 2026
Feb 06, 2026
Feb 19, 2026
7.7 HIGH
CVE-2026-25758 — Spree allows unauthenticated users can access all guest addresses

Spree is an open source e-commerce solution built with Ruby on Rails. A critical IDOR vulnerability exists in Spree Commerce's guest checkout flow that allows any guest user to bind arbitrary guest a…

spree | Remote | Authorization
Feb 06, 2026 Feb 19, 2026
Feb 06, 2026
Feb 19, 2026
7.5 HIGH
CVE-2026-25732 — NiceGUI's Path Traversal via Unsanitized FileUpload.name Enables Arbitrary File Write

NiceGUI is a Python-based UI framework. Prior to 3.7.0, NiceGUI's FileUpload.name property exposes client-supplied filename metadata without sanitization, enabling path traversal when developers use …

nicegui | Remote | Path Traversal
Feb 06, 2026 Feb 20, 2026
Feb 06, 2026
Feb 20, 2026
5.4 MEDIUM
CVE-2026-25574 — Payload Affected by Cross-Collection IDOR in payload-preferences Access Control (Multi-Au…

Payload is a free and open source headless content management system. Prior to 3.74.0, a cross-collection Insecure Direct Object Reference (IDOR) vulnerability exists in the payload-preferences inter…

payload | Remote | Authorization
Feb 06, 2026 Feb 20, 2026
Feb 06, 2026
Feb 20, 2026
9.8 CRITICAL
CVE-2026-25544 — Payload has an SQL Injection in JSON/RichText Queries on PostgreSQL/SQLite Adapters

Payload is a free and open source headless content management system. Prior to 3.73.0, when querying JSON or richText fields, user input was directly embedded into SQL without escaping, enabling blin…

payload | Remote | Injection
Feb 06, 2026 Feb 20, 2026
Feb 06, 2026
Feb 20, 2026
8.8 HIGH
CVE-2026-25533 — Enclave has a sandbox escape via infinite recursion and error objects

Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.10.1, the existing layers of security in enclave-vm are insufficient: The AST sanitization can be bypassed…

enclave | Misconfiguration
Feb 06, 2026 Feb 20, 2026
Feb 06, 2026
Feb 20, 2026
6.1 MEDIUM
CVE-2026-25516 — NiceGUI's XSS vulnerability in ui.markdown() allows arbitrary JavaScript execution throug…

NiceGUI is a Python-based UI framework. The ui.markdown() component uses the markdown2 library to convert markdown content to HTML, which is then rendered via innerHTML. By default, markdown2 allows …

nicegui | Remote | Cross-Site Scripting
Feb 06, 2026 Feb 20, 2026
Feb 06, 2026
Feb 20, 2026
5.3 MEDIUM
CVE-2026-25123 — Homarr affected by Unauthenticated SSRF / Port-Scan Primitive via widget.app.ping

Homarr is an open-source dashboard. Prior to 1.52.0, a public (unauthenticated) tRPC endpoint widget.app.ping accepts an arbitrary url and performs a server-side request to that URL. This allows an u…

homarr | Remote | Server-Side Request Forgery
Feb 06, 2026 Feb 18, 2026
Feb 06, 2026
Feb 18, 2026
9.9 CRITICAL
CVE-2026-1731 — BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection V…

BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted re…

remote_support privileged_remote_access | CISA KEV Remote | Injection
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
9.1 CRITICAL
CVE-2026-1727 — Information Disclosure via Bucket Squatting in Google Cloud Agentspace.

The Agentspace service was affected by a vulnerability that exposed sensitive information due to the use of predictable Google Cloud Storage bucket names. These names were utilized for error logs and…

Remote | Information Disclosure
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
7.4 HIGH
CVE-2025-68621 — Trilium Notes has a Timing Attack Vulnerability in /api/login/sync

Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large personal knowledge bases. Prior to 0.101.0, a critical timing attack vulnerability i…

trilium | Remote | Authentication
Feb 06, 2026 Feb 24, 2026
Feb 06, 2026
Feb 24, 2026
9.0 HIGH
CVE-2026-2067 — UTT 进取 520W formTimeGroupConfig strcpy buffer overflow

A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /goform/formTimeGroupConfig. The manipulation of the argument year1 …

520w_firmware 520w | Remote | Memory Corruption
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
9.0 HIGH
CVE-2026-2066 — UTT 进取 520W formIpGroupConfig strcpy buffer overflow

A weakness has been identified in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/formIpGroupConfig. Executing a manipulation of the argument groupName can lead to buff…

520w_firmware 520w | Remote | Memory Corruption
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
Showing 20 of 5134 Results