Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.5 MEDIUM
CVE-2025-43417 — Apple macOS Sonoma Path Handling Vulnerability

A path handling issue was addressed with improved logic. This issue is fixed in macOS Sonoma 14.8.4. An app may be able to access user-sensitive data.

macos | Path Traversal
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
5.5 MEDIUM
CVE-2025-43403 — "Apple macOS Authorization State Management Vulnerability"

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4. An app may be able to access sensitive user data.

macos | Authorization
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
5.3 MEDIUM
CVE-2026-26031 — Frappe LMS affected by unauthorised user was able to access the full list of batch enroll…

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.44.0, security issue was identified in Frappe Learning, where unauthorised users were…

learning | Remote | Authorization
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
7.5 HIGH
CVE-2026-26029 — sf-mcp-server has a Command Injection in query_records tool due to unsafe use of child_pr…

sf-mcp-server is an implementation of Salesforce MCP server for Claude for Desktop. A command injection vulnerability exists in sf-mcp-server due to unsafe use of child_process.exec when constructing…

Remote | Injection
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
6.1 MEDIUM
CVE-2026-26023 — Client‑side DOM XSS in the web chat app of Dify when using echarts

Dify is an open-source LLM app development platform. Prior to 1.13.0, a cross site scripting vulnerability has been found in the web application chat frontend when using echarts. User or llm inputs c…

dify | Remote | Cross-Site Scripting
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
9.8 CRITICAL
CVE-2026-26021 — Prototype pollution in set-in

set-in provides the set value of nested associative structure given array of keys. A prototype pollution vulnerability exists in the the npm package set-in (>=2.0.1, < 2.0.5). Despite a previous fix …

set-in | Remote | Misconfiguration
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
4.1 MEDIUM
CVE-2026-26019 — @langchain/community affected by SSRF Bypass in RecursiveUrlLoader via insufficient URL o…

LangChain is a framework for building LLM-powered applications. Prior to 1.1.14, the RecursiveUrlLoader class in @langchain/community is a web crawler that recursively follows links from a starting U…

langchain_community | Remote | Server-Side Request Forgery
Feb 11, 2026 Feb 19, 2026
Feb 11, 2026
Feb 19, 2026
6.5 MEDIUM
CVE-2026-26012 — vaultwarden has Full Cipher Enumeration Ignoring Organization Collection Permissions

vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to 1.35.3, a regular organization member can retrieve all ciphers within an organizatio…

vaultwarden | Remote | Authorization
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
8.8 HIGH
CVE-2024-50619 — CIPPlanner CIPAce Account Elevation and Privilege Escalation Vulnerability

Vulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attackers to escalate their access levels. A low-privileged authenticated user can gain access…

cipace | Remote | Authorization
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
7.5 HIGH
CVE-2024-50617 — CIPPlanner CIPAce File Download and Get File Unauthenticated File Retrieval Vulnerability

Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow attackers to download unauthorized files. An authenticated user can easily change the file …

cipace | Remote | Path Traversal
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
7.0 HIGH
CVE-2026-26158 — Busybox: busybox: arbitrary file modification and privilege escalation via unvalidated ta…

A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction directory by crafting a malicious tar archive containing unvalidated hardlink or …

| Path Traversal
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
7.0 HIGH
CVE-2026-26157 — Busybox: busybox: arbitrary file overwrite and potential code execution via incomplete pa…

A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may wr…

| Path Traversal
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
9.1 CRITICAL
CVE-2026-26014 — Pion DTLS uses random nonce generation with AES GCM ciphers risks leaking the authenticat…

Pion DTLS is a Go implementation of Datagram Transport Layer Security. Pion DTLS versions v1.0.0 through v3.0.10 and 3.1.0 use random nonce generation with AES GCM ciphers, which makes it easier for …

dtls | Remote | Cryptography
Feb 11, 2026 Feb 25, 2026
Feb 11, 2026
Feb 25, 2026
7.6 HIGH
CVE-2026-26010 — Leaky JWTs in OpenMetadata exposing highly-privileged bot users

OpenMetadata is a unified metadata platform. Prior to 1.11.8, calls issued by the UI against /api/v1/ingestionPipelines leak JWTs used by ingestion-bot for certain services (Glue / Redshift / Postgre…

openmetadata | Remote | Authorization
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
7.1 HIGH
CVE-2026-25999 — Klaw has an improper authorisation check on /resetMemoryCache

Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to 2.10.2, there is an improper access control vulnerability that allows unauthorized users to trigger a reset or de…

klaw | Remote | Authorization
Feb 11, 2026 Feb 26, 2026
Feb 11, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-25994 — PJSIP has a heap buffer overflow in ICE with long username

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a buffer overflow vulnerability exists in PJNATH ICE Session when processing credentials with exces…

pjsip pjsip | Remote | Memory Corruption
Feb 11, 2026 Feb 19, 2026
Feb 11, 2026
Feb 19, 2026
8.9 HIGH
CVE-2026-25990 — Pillow has an out-of-bounds write when loading PSD images

Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, n out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.

pillow | Remote | Memory Corruption
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
8.6 HIGH
CVE-2026-25935 — Vikunja Affected by XSS Via Task Preview

Vikunja is a todo-app to organize your life. Prior to 1.1.0, TaskGlanceTooltip.vue temporarily creates a div and sets the innerHtml to the description. Since there is no escaping on either the server…

vikunja | Remote | Cross-Site Scripting
Feb 11, 2026 Feb 20, 2026
Feb 11, 2026
Feb 20, 2026
8.4 HIGH
CVE-2026-25924 — Kanboard is Missing Access Control on Plugin Installation leading to Administrative RCE

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a security control bypass vulnerability in Kanboard allows an authenticated administrator to achieve full Remot…

kanboard | Remote | Authentication
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
8.7 HIGH
CVE-2026-25759 — Statmatic affected by privilege escalation via stored cross-site scripting

Statmatic is a Laravel and Git powered content management system (CMS). From 6.0.0 to before 6.2.3, a stored XSS vulnerability in content titles allows authenticated users with content creation permi…

statamic | Remote | Cross-Site Scripting
Feb 11, 2026 Feb 18, 2026
Feb 11, 2026
Feb 18, 2026
Showing 20 of 5068 Results