Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-26056 — Arbitrary WASM Code Execution via AnnotationOverrideFlight Injection in Yoke ATC

Yoke is a Helm-inspired infrastructure-as-code (IaC) package deployer. In 0.19.0 and earlier, a vulnerability exists in the Air Traffic Controller (ATC) component of Yoke. It allows users with CR cre…

Remote | Injection
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
7.5 HIGH
CVE-2026-26055 — Unauthenticated Admission Webhook Endpoints in Yoke ATC

Yoke is a Helm-inspired infrastructure-as-code (IaC) package deployer. In 0.19.0 and earlier, a vulnerability exists in the Air Traffic Controller (ATC) component of Yoke. The ATC webhook endpoints l…

Remote | Authentication
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
5.4 MEDIUM
CVE-2026-25828 — Grub-Btrfs Command Injection Vulnerability

grub-btrfs through 2026-01-31 (on Arch Linux and derivative distributions) allows initramfs OS command injection because it does not sanitize the $root parameter to resolve_device(). NOTE: a third pa…

Remote | Injection
Feb 12, 2026 Mar 04, 2026
Feb 12, 2026
Mar 04, 2026
9.8 CRITICAL
CVE-2026-1358 — Airleader Master Unrestricted Upload of File with Dangerous Type

Airleader Master versions 6.381 and prior allow for file uploads without restriction to multiple webpages running maximum privileges. This could allow an unauthenticated user to potentially obtain …

Remote | Authentication
Feb 12, 2026 Mar 03, 2026
Feb 12, 2026
Mar 03, 2026
6.1 MEDIUM
CVE-2025-70845 — "Lty628 Aidigu XSS"

lty628 aidigu v1.9.1 is vulnerable to Cross Site Scripting (XSS) exists in the /setting/ page where the "intro" field is not properly sanitized or escaped.

Remote | Cross-Site Scripting
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
5.4 MEDIUM
CVE-2025-14282 — Dropbear: privilege escalation via unix domain socket forwardings

A flaw was found in Dropbear. When running in multi-user mode and authenticating users, the dropbear ssh server does the socket forwardings requested by the remote client as root, only switching to t…

Remote | Authorization
Feb 12, 2026 Feb 18, 2026
Feb 12, 2026
Feb 18, 2026
9.4 CRITICAL
CVE-2026-26020 — AutoGPT Affected by Remote Code Execution via Dynamic Module Import in Block Loading (__i…

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to 0.6.48, an authenticated user could achieve R…

autogpt_platform | Remote | Authentication
Feb 12, 2026 Feb 17, 2026
Feb 12, 2026
Feb 17, 2026
9.8 CRITICAL
CVE-2026-26011 — Critical Heap Out-of-bounds Access in `pf_cluster_stats()` via Malicious /initialpose Cov…

navigation2 is a ROS 2 Navigation Framework and System. In 1.3.11 and earlier, a critical heap out-of-bounds write vulnerability exists in Nav2 AMCL's particle filter clustering logic. By publishing …

nav2 | Remote | Memory Corruption
Feb 12, 2026 Feb 23, 2026
Feb 12, 2026
Feb 23, 2026
5.0 MEDIUM
CVE-2026-26005 — ClipBucket v5 enables internal network scans via an SSRF vulnerability

ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #45, in Clip Bucket V5, The Remote Play allows creating video entries that reference external video URLs without uploading the…

clipbucket | Remote | Server-Side Request Forgery
Feb 12, 2026 Feb 18, 2026
Feb 12, 2026
Feb 18, 2026
6.1 MEDIUM
CVE-2026-26000 — XWiki Platform affected by click-jacking through CSS injection in comments

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.9.0, 17.4.6, and 16.10.13, it's possible using comments to inject CSS that would t…

xwiki | Remote | Cross-Site Scripting
Feb 12, 2026 Feb 19, 2026
Feb 12, 2026
Feb 19, 2026
9.8 CRITICAL
CVE-2026-25996 — Inspektor Gadget uses unsanitized ANSI Escape Sequences In `columns` Output Mode

Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. String fields from eBPF events in columns output mode are…

inspektor_gadget | Remote | Information Disclosure
Feb 12, 2026 Feb 23, 2026
Feb 12, 2026
Feb 23, 2026
6.0 MEDIUM
CVE-2026-0619 — Integer Wraparound DoS in Silicon Labs Matter Implementation

A reachable infinite loop via an integer wraparound is present in Silicon Labs' Matter SDK which allows an attacker to trigger a denial of service. A hard reset is required to recover the device.

Remote | Denial of Service
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
7.5 HIGH
CVE-2026-25949 — Traefik: TCP readTimeout bypass via STARTTLS on Postgres

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.8, there is a potential vulnerability in Traefik managing STARTTLS requests. An unauthenticated client can bypass Traefik entrypoint r…

traefik | Remote | Denial of Service
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
6.8 MEDIUM
CVE-2026-25933 — Arduino App Lab has Improper Data Validation in Internal Terminal Interface

Arduino App Lab is a cross-platform IDE for developing Arduino Apps. Prior to 0.4.0, a vulnerability was identified in the Terminal component of the arduino-app-lab application. The issue stems from …

app_lab | Injection
Feb 12, 2026 Feb 19, 2026
Feb 12, 2026
Feb 19, 2026
8.8 HIGH
CVE-2026-25922 — authentik has a Signature Verification Bypass via SAML Assertion Wrapping

authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Assertion Signature under Verification Certificate enab…

authentik | Remote | Authentication
Feb 12, 2026 Feb 18, 2026
Feb 12, 2026
Feb 18, 2026
7.1 HIGH
CVE-2026-25768 — LavinMQ is missing vhost access control

LavinMQ is a high-performance message queue & streaming server. Before 2.6.6, an authenticated user could access metadata in the broker they should not have access to. This vulnerability is fixed in …

lavinmq | Remote | Authorization
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
8.6 HIGH
CVE-2026-25767 — LavinMQ has incomplete shovel configuration validation

LavinMQ is a high-performance message queue & streaming server. Before 2.6.8, an authenticated user, with the “Policymaker” tag, could create shovels bypassing access controls. an authenticated user …

lavinmq | Remote | Authorization
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
8.6 HIGH
CVE-2026-25748 — authentik has a forward authentication bypass with broken cookie

authentik is an open-source identity provider. Prior to 2025.10.4 and 2025.12.4, with a malformed cookie it was possible to bypass authentication when using forward authentication in the authentik Pr…

authentik | Remote | Authentication
Feb 12, 2026 Feb 19, 2026
Feb 12, 2026
Feb 19, 2026
9.1 CRITICAL
CVE-2026-25227 — authentik affected by Remote Code Execution via Context Key Injection in PropertyMapping …

authentik is an open-source identity provider. From 2021.3.1 to before 2025.8.6, 2025.10.4, and 2025.12.4, when using delegated permissions, a User that has the permission Can view * Property Mapping…

authentik | Remote | Authorization
Feb 12, 2026 Feb 19, 2026
Feb 12, 2026
Feb 19, 2026
9.8 CRITICAL
CVE-2026-24895 — FrankenPHP affected by Path Confusion via Unicode casing in CGI path splitting allows exe…

FrankenPHP is a modern application server for PHP. Prior to 1.11.2, FrankenPHP’s CGI path splitting logic improperly handles Unicode characters during case conversion. The logic computes the split in…

frankenphp | Remote | Path Traversal
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
Showing 20 of 5007 Results