Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.6 HIGH
CVE-2026-27730 — esm.sh has SSRF localhost/private-network bypass in `/http(s)` module route

esm.sh is a no-build content delivery network (CDN) for web development. Versions up to and including 137 have an SSRF vulnerability (CWE-918) in esm.sh’s `/http(s)` fetch route. The service tries to…

esm.sh | Remote | Server-Side Request Forgery
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
6.6 MEDIUM
CVE-2026-27704 — Dart SDK and Flutter SDK have Zip slip in Dart Pub package extraction

The Dart and Flutter SDKs provide software development kits for the Dart programming language. In versions of the Dart SDK prior to 3.11.0 and the Flutter SDK prior to version 3.41.0, when the pub cl…

dart_software_development_kit | Remote | Path Traversal
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
9.9 CRITICAL
CVE-2026-27702 — Budibase Vulnerable to Remote Code Execution via Unsafe eval() in View Filter Map Functio…

Budibase is a low code platform for creating internal tools, workflows, and admin panels. Prior to version 3.30.4, an unsafe `eval()` vulnerability in Budibase's view filtering implementation allows …

budibase | Remote | Injection
Feb 25, 2026 Mar 02, 2026
Feb 25, 2026
Mar 02, 2026
8.8 HIGH
CVE-2026-27701 — LiveCodes vulnerable to JavaScript Injection via untrusted PR title in i18n-update-pull w…

LiveCode is an open-source, client-side code playground. Prior to commit e151c64c2bd80d2d53ac1333f1df9429fe6a1a11, LiveCode's `i18n-update-pull` GitHub Actions workflow is vulnerable to JavaScript in…

Remote | Injection
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
8.2 HIGH
CVE-2026-27700 — Hono is Vulnerable to Authentication Bypass by IP Spoofing in AWS Lambda ALB conninfo

Hono is a Web application framework that provides support for any JavaScript runtime. In versions 4.12.0 and 4.12.1, when using the AWS Lambda adapter (`hono/aws-lambda`) behind an Application Load B…

hono | Remote | Misconfiguration
Feb 25, 2026 Mar 02, 2026
Feb 25, 2026
Mar 02, 2026
2.7 LOW
CVE-2026-22866 — ENS DNSSEC Oracle Vulnerable to RSA Signature Forgery via Missing PKCS#1 v1.5 Padding Val…

Ethereum Name Service (ENS) is a distributed, open, and extensible naming system based on the Ethereum blockchain. In versions 1.6.2 and prior, the `RSASHA256Algorithm` and `RSASHA1Algorithm` contrac…

ethereum_name_service | Remote | Cryptography
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
9.6 CRITICAL
CVE-2025-69771 — Asbplayer File Upload Code Execution Vulnerability

An arbitrary file upload vulnerability in the subtitle loading function of asbplayer v1.13.0 allows attackers to execute arbitrary code via uploading a crafted subtitle file.

asbplayer | Remote | Misconfiguration
Feb 25, 2026 Mar 02, 2026
Feb 25, 2026
Mar 02, 2026
8.7 HIGH
CVE-2025-50180 — esm.sh is vulnerable to full-response SSRF

esm.sh is a no-build content delivery network (CDN) for web development. In version 136, esm.sh is vulnerable to a full-response SSRF, allowing an attacker to retrieve information from internal websi…

esm.sh | Remote | Server-Side Request Forgery
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
9.3 CRITICAL
CVE-2025-1242 — Administrative Credentials Can Be Extracted Through Gardyn API Responses

The administrative credentials can be extracted through application API responses, mobile application reverse engineering, and device firmware reverse engineering. The exposure may result in an attac…

Remote | Information Disclosure
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
7.5 HIGH
CVE-2026-3203 — Buffer Over-read in Wireshark

RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service

wireshark | Remote | Denial of Service
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
7.5 HIGH
CVE-2026-3202 — NULL Pointer Dereference in Wireshark

NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service

wireshark | Remote | Denial of Service
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
7.5 HIGH
CVE-2026-3201 — Improperly Controlled Sequential Memory Allocation in Wireshark

USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service

wireshark | Remote | Denial of Service
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-3187 — feiyuchuixue sz-boot-parent API Endpoint upload unrestricted upload

A vulnerability was identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this issue is some unknown functionality of the file /api/admin/sys-file/upload of the component API Endpoi…

sz-boot-parent | Remote | Misconfiguration
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
5.9 MEDIUM
CVE-2026-2878 — Insufficient Entropy Vulnerability in Telerik UI for ASP.NET AJAX

In Progress® Telerik® UI for AJAX, versions prior to 2026.1.225, an insufficient entropy vulnerability exists in RadAsyncUpload, where a predictable temporary identifier, based on timestamp and filen…

telerik_ui_for_asp.net_ajax | Remote | Cryptography
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-27699 — Basic FTP has Path Traversal Vulnerability in its downloadToDir() method

The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()` method. A malicious FTP server can send directory l…

basic-ftp | Remote | Path Traversal
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
5.3 MEDIUM
CVE-2026-27695 — zae-limiter: DynamoDB hot partition throttling enables per-entity Denial of Service

zae-limiter is a rate limiting library using the token bucket algorithm. Prior to version 0.10.1, all rate limit buckets for a single entity share the same DynamoDB partition key (`namespace/ENTITY#{…

zae-limiter | Remote | Denial of Service
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
7.1 HIGH
CVE-2026-27692 — iccDEV has HBO in CIccTagTextDescription::Release()

iccDEV provides a set of libraries and tools for working with ICC color management profiles. In versions up to and including 2.3.1.4, heap-buffer-overflow read occurs during CIccTagTextDescription::R…

iccdev | Memory Corruption
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
6.2 MEDIUM
CVE-2026-27691 — iccDEV has SIO in parse3DTable() at iccFromCube.cpp Line 218

iccDEV provides a set of libraries and tools for working with ICC color management profiles. In versions up to and including 2.3.1.4, signed integer overflow in iccFromCube.cpp during multiplication …

iccdev | Memory Corruption
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
6.5 MEDIUM
CVE-2026-3186 — feiyuchuixue sz-boot-parent Password Reset password default password

A vulnerability was determined in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this vulnerability is an unknown functionality of the file /api/admin/sys-user/reset/password/ of the compo…

sz-boot-parent | Remote | Authorization
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
5.5 MEDIUM
CVE-2026-3185 — feiyuchuixue sz-boot-parent API Endpoint sys-message authorization

A vulnerability was found in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected is an unknown function of the file /api/admin/sys-message/ of the component API Endpoint. The manipulation of the a…

sz-boot-parent | Remote | Authorization
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
Showing 20 of 5066 Results