Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.0 HIGH
CVE-2026-28425 — Statamic vulnerable to remote code execution via Antlers-enabled control panel inputs

Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, an authenticated control panel user with access to Antlers-enabled inputs may be able to a…

statamic | Remote | Injection
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
6.5 MEDIUM
CVE-2026-28424 — Statamic's missing authorization allows access to email addresses

Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, user email addresses were included in responses from the user fieldtype’s data endpoint fo…

statamic | Remote | Information Disclosure
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
8.6 HIGH
CVE-2026-28423 — Statamic Vulnerable to Server-Side Request Forgery via Glide

Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, when Glide image manipulation is used in insecure mode (which is not the default), the ima…

statamic | Remote | Server-Side Request Forgery
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
5.3 MEDIUM
CVE-2026-27759 — Featured Image from Content < 1.7 Authenticated SSRF via save_post

Featured Image from Content (featured-image-from-content) WordPress plugin versions prior to 1.7 contain an authenticated server-side request forgery vulnerability that allows Author-level users to f…

Remote | Server-Side Request Forgery
Feb 27, 2026 Mar 02, 2026
Feb 27, 2026
Mar 02, 2026
2.2 LOW
CVE-2026-28422 — Vim has stack-buffer-overflow in build_stl_str_hl()

Vim is an open source, command line text editor. Prior to version 9.2.0078, a stack-buffer-overflow occurs in `build_stl_str_hl()` when rendering a statusline with a multi-byte fill character on a ve…

vim | Memory Corruption
Feb 27, 2026 Mar 04, 2026
Feb 27, 2026
Mar 04, 2026
7.8 HIGH
CVE-2026-28421 — Vim has a heap-buffer-overflow and a segmentation fault

Vim is an open source, command line text editor. Versions prior to 9.2.0077 have a heap-buffer-overflow and a segmentation fault (SEGV) exist in Vim's swap file recovery logic. Both are caused by unv…

vim | Memory Corruption
Feb 27, 2026 Mar 04, 2026
Feb 27, 2026
Mar 04, 2026
4.4 MEDIUM
CVE-2026-28420 — Vim has Heap-based Buffer Overflow and OOB Read in :terminal

Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an out-of-bounds READ exist in Vim's terminal emulator when processing maximum combi…

vim | Memory Corruption
Feb 27, 2026 Mar 04, 2026
Feb 27, 2026
Mar 04, 2026
6.6 MEDIUM
CVE-2026-28419 — Vim has Heap-based Buffer Underflow in Emacs tags parsing

Vim is an open source, command line text editor. Prior to version 9.2.0075, a heap-based buffer underflow exists in Vim's Emacs-style tags file parsing logic. When processing a malformed tags file wh…

vim | Memory Corruption
Feb 27, 2026 Mar 04, 2026
Feb 27, 2026
Mar 04, 2026
5.5 MEDIUM
CVE-2026-28418 — Vim has Heap-based Buffer Overflow in Emacs tags parsing

Vim is an open source, command line text editor. Prior to version 9.2.0074, a heap-based buffer overflow out-of-bounds read exists in Vim's Emacs-style tags file parsing logic. When processing a malf…

vim | Memory Corruption
Feb 27, 2026 Mar 03, 2026
Feb 27, 2026
Mar 03, 2026
7.8 HIGH
CVE-2026-28417 — Vim has OS Command Injection in netrw

Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a …

vim | Injection
Feb 27, 2026 Mar 03, 2026
Feb 27, 2026
Mar 03, 2026
8.6 HIGH
CVE-2026-28416 — Gradio has SSRF via Malicious `proxy_url` Injection in `gr.load()` Config Processing

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Server-Side Request Forgery (SSRF) vulnerability in Gradio allows an attacker to make arbitrary HTTP …

gradio | Remote | Server-Side Request Forgery
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
4.7 MEDIUM
CVE-2026-28415 — Gradio has Open Redirect in OAuth Flow

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, the _redirect_to_target() function in Gradio's OAuth flow accepts an unvalidated _target_url query para…

gradio | Remote | Misconfiguration
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
7.5 HIGH
CVE-2026-28414 — Gradio has Absolute Path Traversal on Windows with Python 3.13+

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Window with Python 3.13+ are vulnerable to an absolute path traversal issue that e…

gradio | Remote | Path Traversal
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2026-28411 — WeGIA Vulnerable to Authentication Bypass via `extract($_REQUEST)`

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, an unsafe use of the `extract()` function on the `$_REQUEST` superglobal allows an unauthenticated attacker to overwrite lo…

wegia | Remote | Authentication
Feb 27, 2026 Mar 03, 2026
Feb 27, 2026
Mar 03, 2026
10.0 CRITICAL
CVE-2026-28409 — WeGIA Vulnerable to Remote Code Execution (RCE) via OS Command Injection

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulnerability exists in the WeGIA application's database restoration functionality. …

wegia | Remote | Injection
Feb 27, 2026 Mar 03, 2026
Feb 27, 2026
Mar 03, 2026
9.8 CRITICAL
CVE-2026-28408 — WeGIA lacks authentication verification in adicionar_tipo_docs_atendido.php

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, the script in adicionar_tipo_docs_atendido.php does not go through the project's central controller and does not have its o…

wegia | Remote | Authorization
Feb 27, 2026 Mar 03, 2026
Feb 27, 2026
Mar 03, 2026
6.9 MEDIUM
CVE-2026-28407 — malcontent's nested archive extraction failure can drop content from scan inputs

malcontent is software for discovering supply-chain compromises through context, differential analysis, and YARA. Prior to version 1.21.0, malcontent would remove nested archives which failed to extr…

malcontent | Remote | Supply Chain
Feb 27, 2026 Mar 03, 2026
Feb 27, 2026
Mar 03, 2026
8.2 HIGH
CVE-2026-28406 — kaniko has tar archive path traversal in build context extraction allows writing files ou…

kaniko is a tool to build container images from a Dockerfile, inside a container or Kubernetes cluster. Starting in version 1.25.4 and prior to version 1.25.10, kaniko unpacks build context archives …

kaniko | Remote | Path Traversal
Feb 27, 2026 Mar 06, 2026
Feb 27, 2026
Mar 06, 2026
7.1 HIGH
CVE-2026-28402 — nimiq/core-rs-albatross's nimiq-blockchain missing proposal body root verification

nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.2.2, a malicious or compromised validator that is …

Remote | Misconfiguration
Feb 27, 2026 Mar 02, 2026
Feb 27, 2026
Mar 02, 2026
7.5 HIGH
CVE-2026-28400 — Docker Model Runner Unauthenticated Runtime Flag Injection via _configure Endpoint

Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Versions prior to 1.0.16 expose a POST `/engines/_configure` endpoint that accepts arbitrary runtime fl…

| Misconfiguration
Feb 27, 2026 Mar 02, 2026
Feb 27, 2026
Mar 02, 2026
Showing 20 of 5070 Results