Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-25505 — Bambuddy Uses Hardcoded Secret Key + Many API Endpoints do not Require Authentication

Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardcoded secret key used for signing JWTs is checked into source code and ManyAPI r…

bambuddy | Remote | Authentication
Feb 04, 2026 Feb 27, 2026
Feb 04, 2026
Feb 27, 2026
9.6 CRITICAL
CVE-2026-25481 — Langroid has WAF Bypass Leading to RCE in TableChatAgent

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.59.32, there is a bypass to the fix for CVE-2025-46724. TableChatAgent can call pandas_eval tool to …

langroid | Remote | Injection
Feb 04, 2026 Feb 20, 2026
Feb 04, 2026
Feb 20, 2026
6.5 MEDIUM
CVE-2026-25475 — OpenClaw Vulnerable to Local File Inclusion via MEDIA: Path Extraction

OpenClaw is a personal AI assistant. Prior to version 2026.1.30, the isValidMedia() function in src/media/parse.ts allows arbitrary file paths including absolute paths, home directory paths, and dire…

openclaw | Remote | Path Traversal
Feb 04, 2026 Feb 13, 2026
Feb 04, 2026
Feb 13, 2026
8.8 HIGH
CVE-2026-25161 — Alist vulnerable to Path Traversal in multiple file operation handlers

Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the application contains path traversal vulnerability in multiple file operation han…

alist | Remote | Path Traversal
Feb 04, 2026 Feb 13, 2026
Feb 04, 2026
Feb 13, 2026
9.1 CRITICAL
CVE-2026-25160 — Alist has Insecure TLS Config

Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the application disables TLS certificate verification by default for all outgoing st…

alist | Remote | Misconfiguration
Feb 04, 2026 Feb 13, 2026
Feb 04, 2026
Feb 13, 2026
7.7 HIGH
CVE-2026-25157 — OpenClaw/Clawdbot has OS Command Injection via Project Root Path in sshNodeCommand

OpenClaw is a personal AI assistant. Prior to version 2026.1.29, there is an OS command injection vulnerability via the Project Root Path in sshNodeCommand. The sshNodeCommand function constructed a …

macos openclaw | Injection
Feb 04, 2026 Feb 13, 2026
Feb 04, 2026
Feb 13, 2026
5.5 MEDIUM
CVE-2026-25145 — melange has a path traversal in license-path which allows reading files outside workspace

melange allows users to build apk packages using declarative pipelines. From version 0.14.0 to before 0.40.3, an attacker who can influence a melange configuration file (e.g., through pull request-dr…

melange | Path Traversal
Feb 04, 2026 Feb 18, 2026
Feb 04, 2026
Feb 18, 2026
7.8 HIGH
CVE-2026-25143 — melange affected by potential host command execution via license-check YAML mode patch pi…

melange allows users to build apk packages using declarative pipelines. From version 0.10.0 to before 0.40.3, an attacker who can influence inputs to the patch pipeline could execute arbitrary shell …

melange | Injection
Feb 04, 2026 Feb 18, 2026
Feb 04, 2026
Feb 18, 2026
8.4 HIGH
CVE-2026-24884 — Compressing Vulnerable to Arbitrary File Write via Symlink Extraction

Compressing is a compressing and uncompressing lib for node. In version 2.0.0 and 1.10.3 and prior, Compressing extracts TAR archives while restoring symbolic links without validating their targets. …

compressing | Path Traversal
Feb 04, 2026 Feb 27, 2026
Feb 04, 2026
Feb 27, 2026
8.8 HIGH
CVE-2026-24844 — melange pipeline working-directory could allow command injection

melange allows users to build apk packages using declarative pipelines. From version 0.3.0 to before 0.40.3, an attacker who can provide build input values, but not modify pipeline definitions, could…

melange | Injection
Feb 04, 2026 Feb 18, 2026
Feb 04, 2026
Feb 18, 2026
8.4 HIGH
CVE-2026-24843 — melange QEMU runner could write files outside workspace directory

melange allows users to build apk packages using declarative pipelines. In version 0.11.3 to before 0.40.3, an attacker who can influence the tar stream from a QEMU guest VM could write files outside…

melange | Path Traversal
Feb 04, 2026 Feb 18, 2026
Feb 04, 2026
Feb 18, 2026
7.5 HIGH
CVE-2026-23897 — Apollo Server is vulnerable to denial of service with `startStandaloneServer`

Apollo Server is an open-source, spec-compliant GraphQL server that's compatible with any GraphQL client, including Apollo Client. In versions from 2.0.0 to 3.13.0, 4.2.0 to before 4.13.0, and 5.0.0 …

Remote | Denial of Service
Feb 04, 2026 Feb 05, 2026
Feb 04, 2026
Feb 05, 2026
7.5 HIGH
CVE-2025-71031 — Apache Water-Melon HTTP Denial of Service

Water-Melon Melon commit 9df9292 and below is vulnerable to Denial of Service. The HTTP component doesn't have any maximum length. As a result, an excessive request header could cause a denial of ser…

melon | Remote | Denial of Service
Feb 04, 2026 Feb 25, 2026
Feb 04, 2026
Feb 25, 2026
6.5 MEDIUM
CVE-2025-68699 — NanoMQ $share/ Subscription Validation and Forwarding Parsing Inconsistency: NULL Pointer…

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, NanoMQ has a protocol parsing / forwarding inconsistency when handling shared subscriptions ($share/). A malfo…

nanomq | Remote | Injection
Feb 04, 2026 Feb 20, 2026
Feb 04, 2026
Feb 20, 2026
7.5 HIGH
CVE-2026-25140 — apko affected by potential unbounded resource consumption in expandapk.ExpandApk on attac…

apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1, an attacker who controls or compromises an APK repository used by apko could …

apko | Remote | Denial of Service
Feb 04, 2026 Feb 20, 2026
Feb 04, 2026
Feb 20, 2026
5.5 MEDIUM
CVE-2026-25122 — apko is vulnerable to unbounded resource consumption in expandapk.Split on attacker-contr…

apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.0, expandapk.Split drains the first gzip stream of an APK archive via io.Copy(io…

apko | Denial of Service
Feb 04, 2026 Feb 20, 2026
Feb 04, 2026
Feb 20, 2026
7.5 HIGH
CVE-2026-25121 — apko is vulnerable to path traversal in apko dirFS which allows filesystem writes outside…

apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1, a path traversal vulnerability was discovered in apko's dirFS filesystem abst…

apko | Remote | Path Traversal
Feb 04, 2026 Feb 20, 2026
Feb 04, 2026
Feb 20, 2026
7.8 HIGH
CVE-2026-0536 — GIF File Parsing Stack Based Buffer Overflow

A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary cod…

3ds_max | Memory Corruption
Feb 04, 2026 Feb 05, 2026
Feb 04, 2026
Feb 05, 2026
8.0 HIGH
CVE-2026-25532 — ESF-IDF is Vulnerable to WPS Enrollee Fragment Integer Underflow

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.2, 5.4.3, 5.3.4, 5.2.6, and 5.1.6, a vulnerability exists in the WPS (Wi-Fi Protected Setup) Enrollee implemen…

esp-idf | Memory Corruption
Feb 04, 2026 Feb 20, 2026
Feb 04, 2026
Feb 20, 2026
6.3 MEDIUM
CVE-2026-25508 — ESF-IDF Has Memory Safety Vulnerabilities in BLE Provisioning

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.2, 5.4.3, 5.3.4, 5.2.6, and 5.1.6, an out-of-bounds read vulnerability was reported in the BLE ATT Prepare Wri…

esp-idf | Memory Corruption
Feb 04, 2026 Feb 20, 2026
Feb 04, 2026
Feb 20, 2026
Showing 20 of 5149 Results