Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.3 HIGH
CVE-2026-27616 — Vikunja Vulnerable to Stored Cross-Site Scripting (XSS) via Unsanitized SVG Attachment Up…

Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to upload SVG files as task attachments. SVG is an XML-based format that supports …

vikunja | Remote | Cross-Site Scripting
Feb 25, 2026 Mar 05, 2026
Feb 25, 2026
Mar 05, 2026
9.1 CRITICAL
CVE-2026-27575 — Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change

Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to set weak passwords (e.g., 1234, password) without enforcing minimum strength re…

vikunja | Remote | Authentication
Feb 25, 2026 Mar 05, 2026
Feb 25, 2026
Mar 05, 2026
8.9 HIGH
CVE-2026-27148 — Storybook Dev Server Vulnerable to WebSocket Hijacking

Storybook is a frontend workshop for building user interface components and pages in isolation. Prior to versions 7.6.23, 8.6.17, 9.1.19, and 10.2.10, the WebSocket functionality in Storybook's dev s…

Remote | Cross-Site Scripting
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
6.1 MEDIUM
CVE-2026-27116 — Vikunja has Reflected HTML Injection via filter Parameter in Projects Module

Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, a reflected HTML injection vulnerability exists in the Projects module where the `filter` URL parameter is rend…

vikunja | Remote | Cross-Site Scripting
Feb 25, 2026 Mar 05, 2026
Feb 25, 2026
Mar 05, 2026
7.5 HIGH
CVE-2026-26986 — FreeRDP has heap-use-after-free in rail_window_free

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `rail_window_free` dereferences a freed `xfAppWindow` pointer during `HashTable_Free` cleanup because `xf_rai…

freerdp | Remote | Memory Corruption
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
8.1 HIGH
CVE-2026-26985 — LORIS vulnerable to path traversal in electrophysiology_browser

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Starting in version 24.0.0 and prior to …

loris | Remote | Path Traversal
Feb 25, 2026 Mar 05, 2026
Feb 25, 2026
Mar 05, 2026
8.8 HIGH
CVE-2026-26984 — LORIS media module vulnerable to remote code execution

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Prior to versions 26.0.5, 27.0.2, and 28…

loris | Remote | Path Traversal
Feb 25, 2026 Mar 05, 2026
Feb 25, 2026
Mar 05, 2026
7.5 HIGH
CVE-2026-3200 — z-9527 admin user.js getUsers sql injection

A vulnerability was identified in z-9527 admin 1.0/2.0. The affected element is the function checkName/register/login/getUser/getUsers of the file /server/controller/user.js. The manipulation leads t…

Remote | Injection
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
8.1 HIGH
CVE-2026-3172 — pgvector buffer overflow in parallel HNSW index build

Buffer overflow in parallel HNSW index build in pgvector 0.6.0 through 0.8.1 allows a database user to leak sensitive data from other relations or crash the database server.

| Memory Corruption
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
6.5 MEDIUM
CVE-2026-2845 — Allocation of Resources Without Limits or Throttling in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an authenticated user to cause denial o…

gitlab | Remote | Denial of Service
Feb 25, 2026 Feb 28, 2026
Feb 25, 2026
Feb 28, 2026
6.5 MEDIUM
CVE-2026-27015 — FreeRDP: Smartcard NDR Alignment Padding Triggers Reachable WINPR_ASSERT Abort (Client Do…

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a missing bounds check in `smartcard_unpack_read_size_align()` (`libfreerdp/utils/smartcard_pack.c:1703`) all…

freerdp | Remote | Memory Corruption
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
8.8 HIGH
CVE-2026-26965 — FreeRDP has Out-of-bounds Write

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, in the RLE planar decode path, `planar_decompress_plane_rle()` writes into `pDstData` at `((nYDst+y) * nDstSt…

freerdp | Remote | Memory Corruption
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
8.8 HIGH
CVE-2026-26955 — FreeRDP has Out-of-bounds Write

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a malicious RDP server can trigger a heap buffer overflow in FreeRDP clients using the GDI surface pipeline (…

freerdp | Remote | Memory Corruption
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
5.5 MEDIUM
CVE-2026-26271 — Buffer Overread in FreeRDP Icon Processing

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a buffer overread in `freerdp_image_copy_from_icon_data()` (libfreerdp/codec/color.c) can be triggered by cra…

freerdp | Remote
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
9.8 CRITICAL
CVE-2026-25997 — FreeRDP has heap-use-after-free in xf_clipboard_format_equal

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_clipboard_format_equal` reads freed `lastSentFormats` memory because `xf_clipboard_formats_free` (called …

freerdp | Remote | Memory Corruption
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
9.8 CRITICAL
CVE-2026-25959 — FreeRDP has heap-use-after-free in xf_cliprdr_provide_data_

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_cliprdr_provide_data_` passes freed `pDstData` to `XChangeProperty` because the cliprdr channel thread ca…

freerdp | Remote | Memory Corruption
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
9.8 CRITICAL
CVE-2026-25955 — FreeRDP has heap-use-after-free in xf_AppUpdateWindowFromSurface (stale XImage)

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_AppUpdateWindowFromSurface` reuses a cached `XImage` whose `data` pointer references a freed RDPGFX surfa…

freerdp | Remote | Memory Corruption
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
7.5 HIGH
CVE-2026-25954 — FreeRDP has heap-use-after-free in xf_rail_server_local_move_size

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_rail_server_local_move_size` dereferences a freed `xfAppWindow` pointer because `xf_rail_get_window` retu…

freerdp | Remote | Memory Corruption
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
9.8 CRITICAL
CVE-2026-25953 — FreeRDP has heap-use-after-free in xf_AppUpdateWindowFromSurface (freed appWindow)

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_AppUpdateWindowFromSurface` reads from a freed `xfAppWindow` because the RDPGFX DVC thread obtains a bare…

freerdp | Remote | Memory Corruption
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
9.8 CRITICAL
CVE-2026-25952 — FreeRDP has heap-use-after-free in xf_SetWindowMinMaxInfo

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_SetWindowMinMaxInfo` dereferences a freed `xfAppWindow` pointer because `xf_rail_get_window` in `xf_rail_…

freerdp | Remote | Memory Corruption
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
Showing 20 of 5068 Results