Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.8 MEDIUM
CVE-2026-25765 — Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url

Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Prior to 2.14.1, Faraday's build_exclusive_url method (in lib/faraday/connection.rb) uses Ruby…

faraday | Remote | Server-Side Request Forgery
Feb 09, 2026 Feb 20, 2026
Feb 09, 2026
Feb 20, 2026
8.8 HIGH
CVE-2026-25761 — Command injection via crafted filenames in Super-linter Action

Super-linter is a combination of multiple linters to run as a GitHub Action or standalone. From 6.0.0 to 8.3.0, the Super-linter GitHub Action is vulnerable to command injection via crafted filenames…

super-linter | Remote | Injection
Feb 09, 2026 Feb 28, 2026
Feb 09, 2026
Feb 28, 2026
5.8 MEDIUM
CVE-2026-25740 — Privilege escalation to the `CAP_NET_RAW` capability via the `programs.captive-browser` N…

captive browser, a dedicated Chrome instance to log into captive portals without messing with DNS settings. In 25.05 and earlier, when programs.captive-browser is enabled, any user of the system can …

| Misconfiguration
Feb 09, 2026 Feb 09, 2026
Feb 09, 2026
Feb 09, 2026
7.5 HIGH
CVE-2026-25639 — Axios affected by Denial of Service via __proto__ Key in mergeConfig

Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects…

axios | Remote | Denial of Service
Feb 09, 2026 Feb 18, 2026
Feb 09, 2026
Feb 18, 2026
5.8 MEDIUM
CVE-2026-25528 — LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. The LangSmith SDK's distributed tracing feature is vulnerable to Server-Side Request Forgery via malicious HTTP header…

Remote | Server-Side Request Forgery
Feb 09, 2026 Feb 09, 2026
Feb 09, 2026
Feb 09, 2026
4.8 MEDIUM
CVE-2026-2246 — AprilRobotics apriltag apriltag.c apriltag_detector_detect memory corruption

A security vulnerability has been detected in AprilRobotics apriltag up to 3.4.5. Affected by this vulnerability is the function apriltag_detector_detect of the file apriltag.c. The manipulation lead…

| Memory Corruption
Feb 09, 2026 Feb 09, 2026
Feb 09, 2026
Feb 09, 2026
4.8 MEDIUM
CVE-2026-2245 — CCExtractor MPEG-TS File ts_tables.c parse_PMT out-of-bounds

A vulnerability was identified in CCExtractor up to 183. This affects the function parse_PAT/parse_PMT in the library src/lib_ccx/ts_tables.c of the component MPEG-TS File Parser. Such manipulation l…

| Memory Corruption
Feb 09, 2026 Feb 09, 2026
Feb 09, 2026
Feb 09, 2026
6.3 MEDIUM
CVE-2026-25598 — Bypassing Logging of Outbound Connections Using sendto, sendmsg, and sendmmsg in Harden-R…

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Prior to 2.14.2, a security vulnerability has been identified in the Harden-Runner GitHub Action (Community …

harden-runner | Remote | Misconfiguration
Feb 09, 2026 Feb 28, 2026
Feb 09, 2026
Feb 28, 2026
8.6 HIGH
CVE-2026-25498 — Craft has a potential authenticated Remote Code Execution via malicious attached Behavior

Craft is a platform for creating digital experiences. In versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, a Remote Code Execution (RCE) vulnerability exists in Craft CMS where the ass…

craft_cms | Remote | Injection
Feb 09, 2026 Feb 19, 2026
Feb 09, 2026
Feb 19, 2026
8.8 HIGH
CVE-2026-25497 — Craft has a GraphQL Asset Mutation Privilege Escalation

Craft is a platform for creating digital experiences. In Craft versions from 4.0.0-RC1 to before 4.17.0-beta.1 and 5.9.0-beta.1, there is a Privilege Escalation vulnerability in Craft CMS’s GraphQL A…

craft_cms | Remote | Authorization
Feb 09, 2026 Feb 19, 2026
Feb 09, 2026
Feb 19, 2026
4.8 MEDIUM
CVE-2026-25496 — Craft has a stored XSS in Number Prefix & Suffix Fields

Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, a stored XSS vulnerability exists in the Number field type settings. Th…

craft_cms | Remote | Cross-Site Scripting
Feb 09, 2026 Feb 19, 2026
Feb 09, 2026
Feb 19, 2026
8.8 HIGH
CVE-2026-25495 — Craft has a SQL Injection in Element Indexes via criteria[orderBy]

Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the element-indexes/get-elements endpoint is vulnerable to SQL Injectio…

craft_cms | Remote | Injection
Feb 09, 2026 Feb 19, 2026
Feb 09, 2026
Feb 19, 2026
6.9 MEDIUM
CVE-2026-25494 — Craft has a SSRF in GraphQL Asset Mutation via Alternative IP Notation

Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the saveAsset GraphQL mutation uses filter_var(..., FILTER_VALIDATE_IP…

craft_cms | Remote | Injection
Feb 09, 2026 Feb 19, 2026
Feb 09, 2026
Feb 19, 2026
6.9 MEDIUM
CVE-2026-25493 — Craft has a SSRF in GraphQL Asset Mutation via HTTP Redirect

Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the saveAsset GraphQL mutation validates the initial URL hostname and r…

craft_cms | Remote | Server-Side Request Forgery
Feb 09, 2026 Feb 19, 2026
Feb 09, 2026
Feb 19, 2026
6.5 MEDIUM
CVE-2026-25492 — Craft has a save_images_Asset graphql mutation can be abused to exfiltrate AWS credential…

Craft CMS is a content management system. In Craft versions 3.5.0 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the save_images_Asset GraphQL mutation can be abused to fetch internal URLs by providin…

craft_cms | Remote | Server-Side Request Forgery
Feb 09, 2026 Feb 19, 2026
Feb 09, 2026
Feb 19, 2026
4.8 MEDIUM
CVE-2026-25491 — Craft has a Stored XSS in Entry Types Name

Craft is a platform for creating digital experiences. From 5.0.0-RC1 to 5.8.21, Craft has a stored XSS via Entry Type names. The name is not sanitized when displayed in the Entry Types list. This vul…

craft_cms | Remote | Cross-Site Scripting
Feb 09, 2026 Feb 19, 2026
Feb 09, 2026
Feb 19, 2026
6.5 MEDIUM
CVE-2026-25480 — FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord…

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, FileStore maps cache keys to filenames using Unicode NFKD normalization and ord() substitution without separato…

litestar | Remote | Misconfiguration
Feb 09, 2026 Feb 17, 2026
Feb 09, 2026
Feb 17, 2026
6.5 MEDIUM
CVE-2026-25479 — Litestar has an AllowedHosts validation bypass due to unescaped regex metacharacters in c…

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, in litestar.middleware.allowed_hosts, allowlist entries are compiled into regex patterns in a way that allows r…

litestar | Remote | Misconfiguration
Feb 09, 2026 Feb 17, 2026
Feb 09, 2026
Feb 17, 2026
7.4 HIGH
CVE-2026-25478 — Litestar has a CORS origin allowlist bypass due to unescaped regex metacharacters in allo…

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, CORSConfig.allowed_origins_regex is constructed using a regex built from configured allowlist values and used w…

litestar | Remote | Information Disclosure
Feb 09, 2026 Feb 17, 2026
Feb 09, 2026
Feb 17, 2026
7.5 HIGH
CVE-2026-25231 — FileRise affected by an Unauthenticated File Read Due to Insufficient Access Control

FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 3.3.0, the application contains an unauthenticated file read vulnerability due to the lack of access control on the /uplo…

filerise | Remote | Information Disclosure
Feb 09, 2026 Feb 19, 2026
Feb 09, 2026
Feb 19, 2026
Showing 20 of 5121 Results