Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.0 HIGH
CVE-2026-2872 — Tenda A21 MAC Filtering Configuration Endpoint setBlackRule set_device_name stack-based o…

A security vulnerability has been detected in Tenda A21 1.0.0.0. This vulnerability affects the function set_device_name of the file /goform/setBlackRule of the component MAC Filtering Configuration …

a21_firmware a21 | Remote | Memory Corruption
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
9.0 HIGH
CVE-2026-2871 — Tenda A21 SetIpMacBind fromSetIpMacBind stack-based overflow

A weakness has been identified in Tenda A21 1.0.0.0. This affects the function fromSetIpMacBind of the file /goform/SetIpMacBind. This manipulation of the argument list causes stack-based buffer over…

a21_firmware a21 | Remote | Memory Corruption
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
9.0 HIGH
CVE-2026-2870 — Tenda A21 formSetQosBand set_qosMib_list stack-based overflow

A security flaw has been discovered in Tenda A21 1.0.0.0. Affected by this issue is the function set_qosMib_list of the file /goform/formSetQosBand. The manipulation of the argument list results in s…

a21_firmware a21 | Remote | Memory Corruption
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
5.5 MEDIUM
CVE-2026-2869 — janet-lang janet handleattr specials.c janetc_varset out-of-bounds

A vulnerability was identified in janet-lang janet up to 1.40.1. Affected by this vulnerability is the function janetc_varset of the file src/core/specials.c of the component handleattr Handler. The …

janet | Memory Corruption
Feb 21, 2026 Feb 26, 2026
Feb 21, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-2867 — itsourcecode Vehicle Management System billaction.php sql injection

A vulnerability was determined in itsourcecode Vehicle Management System 1.0. Affected is an unknown function of the file /billaction.php. Executing a manipulation of the argument ID can lead to sql …

vehicle_management_system | Remote | Injection
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
7.4 HIGH
CVE-2026-27579 — CollabPlatform : CORS Misconfiguration Allows Arbitrary Origin With Credentials Leading t…

CollabPlatform is a full-stack, real-time doc collaboration platform. In all versions of CollabPlatform, the Appwrite project used by the application is misconfigured to allow arbitrary origins in CO…

Remote | Misconfiguration
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
9.9 CRITICAL
CVE-2026-27574 — OneUptime: node:vm sandbox escape in probe allows any project member to achieve RCE

OneUptime is a solution for monitoring and managing online services. In versions 9.5.13 and below, custom JavaScript monitor feature uses Node.js's node:vm module (explicitly documented as not a secu…

oneuptime | Remote | Injection
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
4.7 MEDIUM
CVE-2026-27492 — Lettermint Node.js SDK leaks email properties to unintended recipients when client instan…

Lettermint Node.js SDK is the official Node.js SDK for Lettermint. In versions 1.5.0 and below, email properties (such as to, subject, html, text, and attachments) are not reset between sends when a …

lettermint | Information Disclosure
Feb 21, 2026 Feb 24, 2026
Feb 21, 2026
Feb 24, 2026
4.8 MEDIUM
CVE-2026-1787 — LearnPress Export Import <= 4.1.0 - Missing Authentication to Unauthenticated Migrated Co…

The LearnPress Export Import – WordPress extension for LearnPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'delete_migrated_data' funct…

Remote | Authorization
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
4.8 MEDIUM
CVE-2026-27576 — OpenClaw: ACP prompt-size checks missing in local stdio bridge could reduce responsivenes…

OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, the ACP bridge accepts very large prompt text blocks and can assemble oversized prompt payloads before forwarding them to chat.se…

openclaw | Denial of Service
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
7.3 HIGH
CVE-2026-27488 — OpenClaw hardened cron webhook delivery against SSRF

OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, Cron webhook delivery in src/gateway/server-cron.ts uses fetch() directly, so webhook targets can reach private/metadata/internal…

openclaw | Remote | Server-Side Request Forgery
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
8.0 HIGH
CVE-2026-27487 — OpenClaw: Prevent shell injection in macOS keychain credential write

OpenClaw is a personal AI assistant. In versions 2026.2.13 and below, when using macOS, the Claude CLI keychain credential refresh path constructed a shell command to write the updated JSON blob into…

macos openclaw | Remote | Injection
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
5.3 MEDIUM
CVE-2026-27486 — OpenClaw: Process Safety - Unvalidated PID Kill via SIGKILL in Process Cleanup

OpenClaw is a personal AI assistant. In versions 2026.2.13 and below of the OpenClaw CLI, the process cleanup uses system-wide process enumeration and pattern matching to terminate processes without …

openclaw | Remote | Misconfiguration
Feb 21, 2026 Feb 24, 2026
Feb 21, 2026
Feb 24, 2026
4.6 MEDIUM
CVE-2026-27485 — OpenClaw affected by Stored XSS in Control UI via unsanitized assistant name/avatar in in…

OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, skills/skill-creator/scripts/package_skill.py (a local helper script used when authors package skills) previously followed symlin…

openclaw | Information Disclosure
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
4.3 MEDIUM
CVE-2026-27484 — OpenClaw Discord moderation authorization used untrusted sender identity in tool-driven f…

OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, the Discord moderation action handling (timeout, kick, ban) uses sender identity from request parameters in tool-driven flows, in…

openclaw | Remote | Authorization
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
8.2 HIGH
CVE-2026-27482 — Ray: Dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdo…

Ray is an AI compute engine. In versions 2.53.0 and below, thedashboard HTTP server blocks browser-origin POST/PUT but does not cover DELETE, and key DELETE endpoints are unauthenticated by default. …

ray | Remote | Authentication
Feb 21, 2026 Mar 04, 2026
Feb 21, 2026
Mar 04, 2026
5.3 MEDIUM
CVE-2026-27480 — Static Web Server: Timing-Based Username Enumeration in Basic Authentication

Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. In versions 2.1.0 through 2.40.1, a timing-based username enumeration vulnerability in Basic Authenti…

static_web_server | Remote | Authentication
Feb 21, 2026 Feb 24, 2026
Feb 21, 2026
Feb 24, 2026
6.5 MEDIUM
CVE-2025-14339 — weMail <= 2.0.7 - Missing Authorization to Unauthenticated Form Deletion

The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for WordPress is vulnerable to unauthorized form deletion in all versions up to, and …

Remote | Authorization
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
7.7 HIGH
CVE-2026-27479 — Wallos: SSRF via Redirect Bypass in Logo/Icon URL Fetch

Wallos is an open-source, self-hostable personal subscription tracker. Versions 4.6.0 and below contain a Server-Side Request Forgery (SSRF) vulnerability in the subscription and payment logo/icon up…

wallos | Remote | Server-Side Request Forgery
Feb 21, 2026 Feb 24, 2026
Feb 21, 2026
Feb 24, 2026
9.8 CRITICAL
CVE-2026-2865 — itsourcecode Agri-Trading Online Shopping System HTTP POST Request productcontroller.php …

A vulnerability was found in itsourcecode Agri-Trading Online Shopping System 1.0. This impacts an unknown function of the file admin/productcontroller.php of the component HTTP POST Request Handler.…

Feb 21, 2026 Feb 26, 2026
Feb 21, 2026
Feb 26, 2026
Showing 20 of 5337 Results