Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.0 MEDIUM
CVE-2026-27973 — Audiobookshelf has Stored XSS in ItemSearchCard.vue via Audiobook Metadata (Search Result…

Audiobookshelf is a self-hosted audiobook and podcast server. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 0.12.0-beta of the Audiobookshelf mobile application that a…

audiobookshelf | Remote | Cross-Site Scripting
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
7.6 HIGH
CVE-2026-27970 — Angular i18n vulnerable to Cross-Site Scripting (XSS)

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Versions prior to 21.2.0, 21.1.16, 20.3.17, and 19.2.19 have a cros…

angular | Remote | Cross-Site Scripting
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
9.3 CRITICAL
CVE-2026-27969 — Vitess users with backup storage access can write to arbitrary file paths on restore

Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage location (e.g. an S3 bucket) can manip…

vitess | Remote | Path Traversal
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
4.3 MEDIUM
CVE-2026-27968 — Packistry accepts expired access tokens

Packistry is a self-hosted Composer repository designed to handle PHP package distribution. Prior to version 0.13.0, RepositoryAwareController::authorize() verified token presence and ability, but di…

packistry | Remote | Authentication
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
9.8 CRITICAL
CVE-2026-27966 — Langflow has Remote Code Execution in CSV Agent

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent node in Langflow hardcodes `allow_dangerous_code=True`, which automatically expose…

langflow | Remote | Injection
Feb 26, 2026 Feb 28, 2026
Feb 26, 2026
Feb 28, 2026
9.9 CRITICAL
CVE-2026-27965 — Vitess users with backup storage access can gain unauthorized access to production deploy…

Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage location (e.g. an S3 bucket) can manip…

vitess | Remote | Misconfiguration
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
8.8 HIGH
CVE-2026-27961 — Agenta's Server-Side Template Injection (SSTI) via custom evaluator Jinja2 templates allo…

Agenta is an open-source LLMOps platform. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior to 0.86.8 in Agenta's API server evaluator template rendering. Although the vu…

agenta | Remote | Injection
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
7.5 HIGH
CVE-2026-27959 — Koa has Host Header Injection via `ctx.hostname`

Koa is middleware for Node.js using ES2017 async functions. Prior to versions 3.1.2 and 2.16.4, Koa's `ctx.hostname` API performs naive parsing of the HTTP Host header, extracting everything before t…

koa | Remote | Information Disclosure
Feb 26, 2026 Feb 28, 2026
Feb 26, 2026
Feb 28, 2026
6.5 MEDIUM
CVE-2026-27954 — LiveHelperChat has department-level authorization bypass in holdaction, blockuser, and tr…

Live Helper Chat is an open-source application that enables live support websites. In versions up to and including 4.52, three chat action endpoints (holdaction.php, blockuser.php, and transferchat.…

live_helper_chat livehelperchat | Remote | Authorization
Feb 26, 2026 Feb 28, 2026
Feb 26, 2026
Feb 28, 2026
9.9 CRITICAL
CVE-2026-27952 — Agenta has Python Sandbox Escape, Leading to Remote Code Execution (RCE)

Agenta is an open-source LLMOps platform. In Agenta-API prior to version 0.48.1, a Python sandbox escape vulnerability existed in Agenta's custom code evaluator. Agenta used RestrictedPython as a san…

agenta | Remote | Injection
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
6.1 MEDIUM
CVE-2026-27948 — Copyparty vulnerable to eflected cross-site scripting via setck parameter

Copyparty is a portable file server. In versions prior to 1.20.9, an XSS allows for reflected cross-site scripting via URL-parameter `?setck=...`. Version 1.20.9 fixes the issue.

copyparty | Remote | Cross-Site Scripting
Feb 26, 2026 Feb 28, 2026
Feb 26, 2026
Feb 28, 2026
6.5 MEDIUM
CVE-2026-27943 — OpenEMR's Eye Exam View Trusts form_id Without Verifying Patient/Encounter Ownership

OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, the eye exam (eye_mag) view loads data by `form_id` (or…

openemr | Remote | Authorization
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
7.5 HIGH
CVE-2026-27942 — fast-xml-parser has stack overflow in XMLBuilder with preserveOrder

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. Prior to version 5.3.8, the application crashes with s…

fast-xml-parser fast-xml-parser | Remote | Denial of Service
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
9.9 CRITICAL
CVE-2026-27941 — OpenLIT Vulnerable to Remote Code Execution and Secret Exposure via Misuse of `pull_reque…

OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repository use the `pull_request_target` event while checking out …

openlit_software_development_kit | Remote | Misconfiguration
Feb 26, 2026 Mar 06, 2026
Feb 26, 2026
Mar 06, 2026
7.7 HIGH
CVE-2026-27938 — WPGraphQL Repo Vulnerable to Command Injection via Unsanitized GitHub Actions Expression …

WPGraphQL provides a GraphQL API for WordPress sites. Prior to version 2.9.1, the `wp-graphql/wp-graphql` repository contains a GitHub Actions workflow (`release.yml`) vulnerable to OS command inject…

wpgraphql | Remote | Injection
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
7.5 HIGH
CVE-2026-27904 — minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expre…

minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extg…

minimatch | Remote | Denial of Service
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
7.5 HIGH
CVE-2026-27903 — minimatch has a ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GL…

minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne()` perf…

minimatch | Remote | Denial of Service
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
5.4 MEDIUM
CVE-2026-27902 — Svelte Vulnerable to XSS via HTML Comment Injection in SSR Error Boundary Hydration Marke…

Svelte performance oriented web framework. Prior to version 5.53.5, errors from `transformError` were not correctly escaped prior to being embedded in the HTML output, causing potential HTML injectio…

svelte | Remote | Cross-Site Scripting
Feb 26, 2026 Mar 05, 2026
Feb 26, 2026
Mar 05, 2026
6.1 MEDIUM
CVE-2026-27901 — Svelte vulnerable to XSS during SSR with contenteditable `bind:innerText` and `bind:textC…

Svelte performance oriented web framework. Prior to version 5.53.5, the contents of `bind:innerText` and `bind:textContent` on `contenteditable` elements were not properly escaped. This could enable …

svelte | Remote | Cross-Site Scripting
Feb 26, 2026 Mar 05, 2026
Feb 26, 2026
Mar 05, 2026
5.0 MEDIUM
CVE-2026-27900 — Terraform Provider Debug Logs Vulnerable to Sensitive Information Exposure

The Terraform Provider for Linode versions prior to v3.9.0 logged sensitive information including some passwords, StackScript content, and object storage data in debug logs without redaction. Provide…

Remote | Information Disclosure
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
Showing 20 of 5066 Results