Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.8 HIGH
CVE-2026-25731 — Calibre Affected by Arbitrary Code Execution via Server-Side Template Injection in Calibr…

calibre is an e-book manager. Prior to 9.2.0, a Server-Side Template Injection (SSTI) vulnerability in Calibre's Templite templating engine allows arbitrary code execution when a user converts an ebo…

calibre | Injection
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
6.5 MEDIUM
CVE-2026-25729 — DeepAudit Affected by User Enumeration via Broken Access Control

DeepAudit is a multi-agent system for code vulnerability discovery. In 3.0.4 and earlier, there is an improper access control vulnerability in the /api/v1/users/ endpoint allows any authenticated use…

deepaudit | Remote | Authorization
Feb 06, 2026 Feb 28, 2026
Feb 06, 2026
Feb 28, 2026
8.2 HIGH
CVE-2026-25636 — calibre has a Path Traversal Leading to Arbitrary File Corruption and Code Execution

calibre is an e-book manager. In 9.1.0 and earlier, a path traversal vulnerability in Calibre's EPUB conversion allows a malicious EPUB file to corrupt arbitrary existing files writable by the Calibr…

calibre | Path Traversal
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
8.6 HIGH
CVE-2026-25635 — calibre has a Path Traversal Leading to Arbitrary File Write and Potential Code Execution

calibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains a path traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions. On Windows (haven…

calibre | Path Traversal
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
7.8 HIGH
CVE-2026-25634 — iccDEV memcpy-param-overlap in CIccTagMultiProcessElement::Apply()

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to 2.3.1.4, SrcPixel and DestPixel stack buffers ove…

iccdev | Memory Corruption
Feb 06, 2026 Feb 19, 2026
Feb 06, 2026
Feb 19, 2026
10.0 CRITICAL
CVE-2026-25632 — EPyT-Flow has unsafe JSON deserialization (__type__)

EPyT-Flow is a Python package designed for the easy generation of hydraulic and water quality scenario data of water distribution networks. Prior to 0.16.1, EPyT-Flow’s REST API parses attacker-contr…

Remote | Injection
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
6.5 MEDIUM
CVE-2026-25631 — Domain allowlist bypass enables credential exfiltration

n8n is an open source workflow automation platform. Prior to 1.121.0, there is a vulnerability in the HTTP Request node's credential domain validation allowed an authenticated attacker to send reques…

n8n | Remote | Server-Side Request Forgery
Feb 06, 2026 Feb 19, 2026
Feb 06, 2026
Feb 19, 2026
8.8 HIGH
CVE-2026-25628 — Qdrant affected by arbitrary file write via `/logger` endpoint

Qdrant is a vector similarity search engine and vector database. From 1.9.3 to before 1.16.0, it is possible to append to arbitrary files via /logger endpoint using an attacker-controlled on_disk.log…

qdrant | Remote | Path Traversal
Feb 06, 2026 Feb 19, 2026
Feb 06, 2026
Feb 19, 2026
5.3 MEDIUM
CVE-2026-25597 — PrestaShop has a time based enumeration in FO login form

PrestaShop is an open source e-commerce web application. Prior to 8.2.4 and 9.0.3, there is a time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vu…

prestashop | Remote | Authentication
Feb 06, 2026 Feb 19, 2026
Feb 06, 2026
Feb 19, 2026
8.4 HIGH
CVE-2026-25593 — OpenClaw Affected by Unauthenticated Local RCE via WebSocket config.apply

OpenClaw is a personal AI assistant. Prior to 2026.1.20, an unauthenticated local client could use the Gateway WebSocket API to write config via config.apply and set unsafe cliPath values that were l…

openclaw | Injection
Feb 06, 2026 Feb 13, 2026
Feb 06, 2026
Feb 13, 2026
9.9 CRITICAL
CVE-2026-25592 — Semantic Kernel has an Arbitrary File Write via AI Agent Function Calling in .NET SDK

Semantic Kernel is an SDK used to build, orchestrate, and deploy AI agents and multi-agent systems. Prior to 1.71.0, an Arbitrary File Write vulnerability has been identified in Microsoft's Semantic …

semantic_kernel | Remote | Path Traversal
Feb 06, 2026 Feb 19, 2026
Feb 06, 2026
Feb 19, 2026
5.4 MEDIUM
CVE-2026-25581 — SCEditor affected by DOM XSS via emoticon URL/HTML injection

SCEditor is a lightweight WYSIWYG BBCode and XHTML editor. Prior to 3.2.1, if an attacker has the ability control configuration options passed to sceditor.create(), like emoticons, charset, etc. then…

sceditor | Remote | Cross-Site Scripting
Feb 06, 2026 Feb 19, 2026
Feb 06, 2026
Feb 19, 2026
8.6 HIGH
CVE-2026-25580 — Pydantic AI Affected by Server-Side Request Forgery (SSRF) in URL Download Handling

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.0.26 to before 1.56.0, aServer-Side Request Forgery (SSRF) vulnerability exists in Pydantic …

pydantic_ai | Remote | Server-Side Request Forgery
Feb 06, 2026 Feb 20, 2026
Feb 06, 2026
Feb 20, 2026
8.8 HIGH
CVE-2026-2065 — Flycatcher Toys smART Pixelator Bluetooth Low Energy missing authentication

A security flaw has been discovered in Flycatcher Toys smART Pixelator 2.0. Affected by this issue is some unknown functionality of the component Bluetooth Low Energy Interface. Performing a manipula…

Feb 06, 2026 Mar 05, 2026
Feb 06, 2026
Mar 05, 2026
5.4 MEDIUM
CVE-2026-2064 — Portabilis i-Educar User Data meusdadod.php cross site scripting

A vulnerability was identified in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/meusdadod.php of the component User Data Page. Such …

i-educar | Remote | Cross-Site Scripting
Feb 06, 2026 Feb 11, 2026
Feb 06, 2026
Feb 11, 2026
6.8 MEDIUM
CVE-2026-25727 — time affected by a stack exhaustion denial of service attack

time provides date and time handling in Rust. From 0.3.6 to before 0.3.47, when user-provided input is provided to any type that parses with the RFC 2822 format, a denial of service attack via stack …

time | Remote | Denial of Service
Feb 06, 2026 Feb 24, 2026
Feb 06, 2026
Feb 24, 2026
9.1 CRITICAL
CVE-2026-25643 — Frigate Affected by Authenticated Remote Command Execution (RCE) and Container Escape

Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.4, a critical Remote Command Execution (RCE) vulnerability has been identified in the Frig…

frigate | Remote | Injection
Feb 06, 2026 Feb 11, 2026
Feb 06, 2026
Feb 11, 2026
6.1 MEDIUM
CVE-2026-25642 — HedgeDoc security headers for uploaded files were not working

HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.6, files served below the /uploads/ endpoint did not use a more strict security-policy. This resulted i…

hedgedoc | Remote | Misconfiguration
Feb 06, 2026 Feb 25, 2026
Feb 06, 2026
Feb 25, 2026
10.0 CRITICAL
CVE-2026-25641 — SandboxJS has a sandbox escape via TOCTOU bug on keys in property accesses

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, there is a sandbox escape vulnerability due to a mismatch between the key on which the validation is performed and the key used for acce…

sandboxjs | Remote | Misconfiguration
Feb 06, 2026 Feb 18, 2026
Feb 06, 2026
Feb 18, 2026
7.1 HIGH
CVE-2026-25640 — Pydantic AI affected by Stored XSS via Path Traversal in Web UI CDN URL

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 to before 1.51.0, a path traversal vulnerability in the Pydantic AI web UI allows an a…

pydantic_ai | Remote | Path Traversal
Feb 06, 2026 Feb 20, 2026
Feb 06, 2026
Feb 20, 2026
Showing 20 of 5134 Results