Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.1 HIGH
CVE-2026-27134 — Strimzi: All CAs from a custom CA chain consisting of multiple CAs are trusted for mTLS u…

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In versions 0.49.0 through 0.50.0, when using a custom Cluster or Clients CA wi…

strimzi_kafka_operator | Remote | Authentication
Feb 21, 2026 Feb 25, 2026
Feb 21, 2026
Feb 25, 2026
9.8 CRITICAL
CVE-2026-2635 — MLflow Use of Default Password Authentication Bypass Vulnerability

MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not requ…

mlflow | Authentication
Feb 20, 2026 Feb 23, 2026
Feb 20, 2026
Feb 23, 2026
7.0 HIGH
CVE-2026-2492 — TensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation Vulne…

TensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Tensor…

tensorflow | Misconfiguration
Feb 20, 2026 Feb 23, 2026
Feb 20, 2026
Feb 23, 2026
5.5 MEDIUM
CVE-2026-2490 — RustDesk Client for Windows Transfer File Link Following Information Disclosure Vulnerabi…

RustDesk Client for Windows Transfer File Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of…

| Information Disclosure
Feb 20, 2026 Feb 23, 2026
Feb 20, 2026
Feb 23, 2026
7.8 HIGH
CVE-2026-2048 — GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction…

gimp | Memory Corruption
Feb 20, 2026 Feb 24, 2026
Feb 20, 2026
Feb 24, 2026
7.8 HIGH
CVE-2026-2047 — GIMP ICNS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

GIMP ICNS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User int…

gimp | Memory Corruption
Feb 20, 2026 Feb 24, 2026
Feb 20, 2026
Feb 24, 2026
7.8 HIGH
CVE-2026-2045 — GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction…

gimp | Memory Corruption
Feb 20, 2026 Feb 24, 2026
Feb 20, 2026
Feb 24, 2026
7.8 HIGH
CVE-2026-2044 — GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability

GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interactio…

gimp | Memory Corruption
Feb 20, 2026 Feb 24, 2026
Feb 20, 2026
Feb 24, 2026
8.8 HIGH
CVE-2026-2043 — Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution …

Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations …

nagios_xi | Remote | Injection
Feb 20, 2026 Feb 24, 2026
Feb 20, 2026
Feb 24, 2026
8.8 HIGH
CVE-2026-2042 — Nagios Host monitoringwizard Command Injection Remote Code Execution Vulnerability

Nagios Host monitoringwizard Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Auth…

nagios_xi | Remote | Injection
Feb 20, 2026 Feb 24, 2026
Feb 20, 2026
Feb 24, 2026
8.8 HIGH
CVE-2026-2041 — Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnera…

Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagi…

nagios_xi | Remote | Injection
Feb 20, 2026 Feb 24, 2026
Feb 20, 2026
Feb 24, 2026
7.3 HIGH
CVE-2026-2040 — PDF-XChange Editor TrackerUpdate Uncontrolled Search Path Element Local Privilege Escalat…

PDF-XChange Editor TrackerUpdate Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations …

pdf-xchange_editor | Path Traversal
Feb 20, 2026 Feb 23, 2026
Feb 20, 2026
Feb 23, 2026
9.8 CRITICAL
CVE-2026-2039 — GFI Archiver MArc.Store Missing Authorization Authentication Bypass Vulnerability

GFI Archiver MArc.Store Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of GFI Archiver. Authe…

archiver | Remote | Authentication
Feb 20, 2026 Feb 24, 2026
Feb 20, 2026
Feb 24, 2026
9.8 CRITICAL
CVE-2026-2038 — GFI Archiver MArc.Core Missing Authorization Authentication Bypass Vulnerability

GFI Archiver MArc.Core Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of GFI Archiver. Authen…

archiver | Remote | Authentication
Feb 20, 2026 Feb 24, 2026
Feb 20, 2026
Feb 24, 2026
8.8 HIGH
CVE-2026-2037 — GFI Archiver MArc.Core Deserialization of Untrusted Data Remote Code Execution Vulnerabil…

GFI Archiver MArc.Core Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Arc…

archiver | Authentication
Feb 20, 2026 Feb 24, 2026
Feb 20, 2026
Feb 24, 2026
8.8 HIGH
CVE-2026-2036 — GFI Archiver MArc.Store Deserialization of Untrusted Data Remote Code Execution Vulnerabi…

GFI Archiver MArc.Store Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Ar…

archiver | Injection
Feb 20, 2026 Feb 24, 2026
Feb 20, 2026
Feb 24, 2026
6.8 MEDIUM
CVE-2026-2035 — Deciso OPNsense diag_backup.php filename Command Injection Remote Code Execution Vulnerab…

Deciso OPNsense diag_backup.php filename Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installation…

| Injection
Feb 20, 2026 Feb 23, 2026
Feb 20, 2026
Feb 23, 2026
7.8 HIGH
CVE-2026-2034 — Sante DICOM Viewer Pro DCM File Parsing Buffer Overflow Remote Code Execution Vulnerabili…

Sante DICOM Viewer Pro DCM File Parsing Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DI…

dicom_viewer_pro | Memory Corruption
Feb 20, 2026 Feb 26, 2026
Feb 20, 2026
Feb 26, 2026
8.1 HIGH
CVE-2026-2033 — MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnera…

MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MLfl…

mlflow | Path Traversal
Feb 20, 2026 Feb 23, 2026
Feb 20, 2026
Feb 23, 2026
5.9 MEDIUM
CVE-2026-27133 — Strimzi All CAs from CA chain will be trusted in Kafka Connect and Kafka MirrorMaker 2 ta…

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. From 0.47.0 to before 0.50.1, when a chain consisting of multiple CA (Certificat…

strimzi_kafka_operator strimzi | Remote | Authentication
Feb 20, 2026 Feb 27, 2026
Feb 20, 2026
Feb 27, 2026
Showing 20 of 5265 Results