Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.9 HIGH
CVE-2026-27830 — c3p0 vulnerable to Remote Code Execution via unsafe deserialization of userOverridesAsStr…

c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances. Several c3p0 `ConnectionPoolDataSource` implem…

| Injection
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
7.2 HIGH
CVE-2026-27829 — Astro is vulnerable to SSRF due to missing allowlist enforcement in remote image inferSize

Astro is a web framework. In versions 9.0.0 through 9.5.3, a bug in Astro's image pipeline allows bypassing `image.domains` / `image.remotePatterns` restrictions, enabling the server to fetch content…

\@astrojs\/node | Remote | Server-Side Request Forgery
Feb 26, 2026 Mar 09, 2026
Feb 26, 2026
Mar 09, 2026
8.8 HIGH
CVE-2026-27976 — Zed Extension Sandbox Escape via Tar Symlink Following

Zed, a code editor, has an extension installer allows tar/gzip downloads. Prior to version 0.224.4, the tar extractor (`async_tar::Archive::unpack`) creates symlinks from the archive without validati…

zed | Remote | Path Traversal
Feb 26, 2026 Mar 05, 2026
Feb 26, 2026
Mar 05, 2026
7.1 HIGH
CVE-2026-27967 — Symlink Escape in Agent File Tools

Zed, a code editor, has a symlink escape vulnerability in versions prior to 0.225.9 in Agent file tools (`read_file`, `edit_file`). It allows reading and writing files **outside the project directory…

zed | Path Traversal
Feb 26, 2026 Mar 05, 2026
Feb 26, 2026
Mar 05, 2026
6.8 MEDIUM
CVE-2026-27933 — Manyfold vulnerable to session hijack via cookie leakage in proxy caches

Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. Versions prior to 0.133.0 are vulnerable to session hijack via coo…

manyfold | Remote | Misconfiguration
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
7.7 HIGH
CVE-2026-27821 — GPAC NHML Demuxer (dmx_nhml.c) Vulnerable to Stack Buffer Overflow

GPAC is an open-source multimedia framework. In versions up to and including 26.02.0, a stack buffer overflow occurs during NHML file parsing in `src/filters/dmx_nhml.c`. The value of the xmlHeaderEn…

gpac | Remote | Memory Corruption
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
8.7 HIGH
CVE-2026-27818 — TerriaJS-Server has a domain validation bypass vulnerability in its proxy allowlist

TerriaJS-Server is a NodeJS Express server for TerriaJS, a library for building web-based geospatial data explorers. A validation bug in versions prior to 4.0.3 allows an attacker to proxy domains no…

terriajs-server | Remote | Misconfiguration
Feb 26, 2026 Mar 04, 2026
Feb 26, 2026
Mar 04, 2026
9.1 CRITICAL
CVE-2026-27812 — Sub2API Vulnerable to Password Reset Poisoning via Host Header Trust Issue, Leading to Ac…

Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. A vulnerability in versions prior to 0.1.85 is a Password Reset Poisoning (Host Heade…

sub2api sub2api | Remote | Authentication
Feb 26, 2026 Mar 05, 2026
Feb 26, 2026
Mar 05, 2026
9.1 CRITICAL
CVE-2026-27809 — psd-tools: Compression module has unguarded zlib decompression, missing dimension validat…

psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.12.2, when a PSD file contains malformed RLE-compressed image data (e.g. a literal run that extends past t…

psd-tools | Remote | Information Disclosure
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
8.6 HIGH
CVE-2026-27808 — Mailpit is Vulnerable to Server-Side Request Forgery (SSRF) via Link Check API

Mailpit is an email testing tool and API for developers. Prior to version 1.29.2, the Link Check API (/api/v1/message/{ID}/link-check) is vulnerable to Server-Side Request Forgery (SSRF). The server …

mailpit | Remote | Server-Side Request Forgery
Feb 26, 2026 Feb 28, 2026
Feb 26, 2026
Feb 28, 2026
9.3 CRITICAL
CVE-2026-27804 — Parse Server: Account takeover via JWT algorithm confusion in Google auth adapter

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.3 and 9.1.1-alpha.4, an unauthenticated attacker can forge a Google authe…

parse-server | Remote | Authentication
Feb 26, 2026 Mar 04, 2026
Feb 26, 2026
Mar 04, 2026
7.4 HIGH
CVE-2026-27800 — Zed has Zip Slip Path Traversal in Extension Archive Extraction

Zed, a code editor, has a Zip Slip (Path Traversal) vulnerability exists in its extension archive extraction functionality prior to version 0.224.4. The `extract_zip()` function in `crates/util/src/a…

zed | Remote | Path Traversal
Feb 26, 2026 Mar 04, 2026
Feb 26, 2026
Mar 04, 2026
4.4 MEDIUM
CVE-2026-27799 — ImageMagick has a heap Buffer Over-read in its DJVU image format handler

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in the DJVU image…

imagemagick magick.net | Memory Corruption
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
7.1 HIGH
CVE-2026-27798 — ImageMagick: Heap Buffer Over-read in WaveletDenoise when processing small images

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability occurs when processing a…

imagemagick magick.net | Memory Corruption
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
6.4 MEDIUM
CVE-2026-27735 — mcp-server-git : Path traversal in git_add allows staging files outside repository bounda…

Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git versions prior to 2026.1.14, the git_add tool did not validate that…

Remote | Path Traversal
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
6.6 MEDIUM
CVE-2026-27711 — NanaZip UFS Archive Parser Memory Corruption via Unvalidated Directory Record Length

NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, a memory corruption vulnerability in NanaZip’s UFS parser allows a crafted `.uf…

nanazip | Memory Corruption
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
5.1 MEDIUM
CVE-2026-27710 — NanaZip .NET Single-File Parser Integer Underflow Leads to Unbounded Allocation (DoS)

NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, a denial-of-service vulnerability exists in NanaZip’s `.NET Single File Applica…

nanazip | Denial of Service
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
6.6 MEDIUM
CVE-2026-27709 — NanaZip .NET Single-File Manifest Parser Vulnerable to Out-of-Bounds Read via Unchecked R…

NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, NanaZip’s `.NET Single File Application` parser has an out-of-bounds read vulne…

nanazip | Memory Corruption
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
8.8 HIGH
CVE-2026-27635 — Manyfold vulnerable to OS command injection via ZIP filename in f3d render

Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. Prior to version 0.133.0, when model render generation is enabled,…

manyfold | Remote | Injection
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
8.7 HIGH
CVE-2026-27633 — TinyWeb has Unbounded Content-Length Memory Exhaustion (DoS)

TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Versions prior to version 2.02 have a Denial of Service (DoS) vulnerability via memory exhaustion. Unauthenticated remote attackers …

tinyweb | Remote | Denial of Service
Feb 26, 2026 Feb 28, 2026
Feb 26, 2026
Feb 28, 2026
Showing 20 of 5066 Results