Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.1 MEDIUM
CVE-2020-37079 — Wing FTP Server < 6.2.7 - Cross-site Request Forgery

Wing FTP Server versions prior to 6.2.7 contain a cross-site request forgery (CSRF) vulnerability in the web administration interface that allows attackers to delete admin users. Attackers can craft …

wing_ftp_server | Remote | Cross-Site Request Forgery
Feb 07, 2026 Feb 18, 2026
Feb 07, 2026
Feb 18, 2026
9.0 HIGH
CVE-2026-2070 — UTT 进取 520W formPolicyRouteConf strcpy buffer overflow

A vulnerability has been found in UTT 进取 520W 1.7.7-180627. The affected element is the function strcpy of the file /goform/formPolicyRouteConf. Such manipulation of the argument GroupName leads to b…

520w_firmware 520w | Remote | Memory Corruption
Feb 06, 2026 Feb 13, 2026
Feb 06, 2026
Feb 13, 2026
9.1 CRITICAL
CVE-2026-25804 — Antrea has invalid enforcement order for network policy rules caused by integer overflow

Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to versions 2.3.2 and 2.4.3, Antrea's network policy priority assignment system has a uint16 arithmetic overflow bug…

antrea | Remote | Misconfiguration
Feb 06, 2026 Feb 28, 2026
Feb 06, 2026
Feb 28, 2026
9.8 CRITICAL
CVE-2026-25803 — 3DP-MANAGER Uses Hard-coded Credentials

3DP-MANAGER is an inbound generator for 3x-ui. In version 2.0.1 and prior, the application automatically creates an administrative account with known default credentials (admin/admin) upon the first …

Remote | Authentication
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
8.1 HIGH
CVE-2026-25793 — Nebula Has Possible Blocklist Bypass via ECDSA Signature Malleability

Nebula is a scalable overlay networking tool. In versions from 1.7.0 to 1.10.2, when using P256 certificates (which is not the default configuration), it is possible to evade a blocklist entry create…

nebula | Remote | Cryptography
Feb 06, 2026 Feb 18, 2026
Feb 06, 2026
Feb 18, 2026
7.5 HIGH
CVE-2026-25762 — AdonisJS vulnerable to Denial of Service (DoS) via Unrestricted Memory Buffering in PartH…

AdonisJS is a TypeScript-first web framework. Prior to versions 10.1.3 and 11.0.0-next.9, a denial of service (DoS) vulnerability exists in the multipart file handling logic of @adonisjs/bodyparser. …

Remote | Denial of Service
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
7.7 HIGH
CVE-2026-25757 — Unauthenticated Spree Commerce users can view completed guest orders by Order ID

Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 5.0.8, 5.1.10, 5.2.7, and 5.3.2, unauthenticated users can view completed guest orders by Order ID. This issue …

spree | Remote | Information Disclosure
Feb 06, 2026 Feb 23, 2026
Feb 06, 2026
Feb 23, 2026
7.2 HIGH
CVE-2026-25754 — AdonisJS multipart body parsing has Prototype Pollution issue

AdonisJS is a TypeScript-first web framework. Prior to versions 10.1.3 and 11.0.0-next.9, a prototype pollution vulnerability in AdonisJS multipart form-data parsing may allow a remote attacker to ma…

Remote | Misconfiguration
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
6.6 MEDIUM
CVE-2026-25749 — Heap Overflow in Vim

Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists in Vim's tag file resolution logic when processing the 'helpfile' option. The v…

vim | Memory Corruption
Feb 06, 2026 Feb 20, 2026
Feb 06, 2026
Feb 20, 2026
7.5 HIGH
CVE-2026-25644 — DataHub's LDAP Ingestion Source vulnerable to MITM attack through TLS downgrade

DataHub is an open-source metadata platform. Prior to version 1.3.1.8, the LDAP ingestion source is vulnerable to MITM attack through TLS downgrade. This issue has been patched in version 1.3.1.8.

datahub datahub | Remote | Misconfiguration
Feb 06, 2026 Feb 20, 2026
Feb 06, 2026
Feb 20, 2026
4.8 MEDIUM
CVE-2026-2069 — ggml-org llama.cpp GBNF Grammar llama-grammar.cpp llama_grammar_advance_stack stack-based…

A flaw has been found in ggml-org llama.cpp up to 55abc39. Impacted is the function llama_grammar_advance_stack of the file llama.cpp/src/llama-grammar.cpp of the component GBNF Grammar Handler. This…

llama.cpp | Memory Corruption
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
9.0 HIGH
CVE-2026-2068 — UTT 进取 520W formSyslogConf strcpy buffer overflow

A vulnerability was detected in UTT 进取 520W 1.7.7-180627. This issue affects the function strcpy of the file /goform/formSyslogConf. The manipulation of the argument ServerIp results in buffer overfl…

520w_firmware 520w | Remote | Memory Corruption
Feb 06, 2026 Feb 13, 2026
Feb 06, 2026
Feb 13, 2026
3.5 LOW
CVE-2026-25764 — OpenProject vulnerable to Stored HTML injection

OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an HTML injection vulnerability occurs in the time tracking function of OpenProject. The app…

openproject | Remote | Injection
Feb 06, 2026 Feb 13, 2026
Feb 06, 2026
Feb 13, 2026
9.9 CRITICAL
CVE-2026-25763 — Command Injection on OpenProject repositories leads to Remote Code Execution

OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an arbitrary file write vulnerability exists in OpenProject’s repository changes endpoint (/…

openproject | Remote | Path Traversal
Feb 06, 2026 Feb 13, 2026
Feb 06, 2026
Feb 13, 2026
6.5 MEDIUM
CVE-2026-25760 — Website Path Traversal / Arbitrary File Read (Authenticated) in Sliver

Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.6.11, a path traversal in the website content subsystem lets an authenticated operator read arbitrary files…

sliver | Remote | Path Traversal
Feb 06, 2026 Feb 19, 2026
Feb 06, 2026
Feb 19, 2026
7.7 HIGH
CVE-2026-25758 — Spree allows unauthenticated users can access all guest addresses

Spree is an open source e-commerce solution built with Ruby on Rails. A critical IDOR vulnerability exists in Spree Commerce's guest checkout flow that allows any guest user to bind arbitrary guest a…

spree | Remote | Authorization
Feb 06, 2026 Feb 19, 2026
Feb 06, 2026
Feb 19, 2026
7.5 HIGH
CVE-2026-25732 — NiceGUI's Path Traversal via Unsanitized FileUpload.name Enables Arbitrary File Write

NiceGUI is a Python-based UI framework. Prior to 3.7.0, NiceGUI's FileUpload.name property exposes client-supplied filename metadata without sanitization, enabling path traversal when developers use …

nicegui | Remote | Path Traversal
Feb 06, 2026 Feb 20, 2026
Feb 06, 2026
Feb 20, 2026
5.4 MEDIUM
CVE-2026-25574 — Payload Affected by Cross-Collection IDOR in payload-preferences Access Control (Multi-Au…

Payload is a free and open source headless content management system. Prior to 3.74.0, a cross-collection Insecure Direct Object Reference (IDOR) vulnerability exists in the payload-preferences inter…

payload | Remote | Authorization
Feb 06, 2026 Feb 20, 2026
Feb 06, 2026
Feb 20, 2026
9.8 CRITICAL
CVE-2026-25544 — Payload has an SQL Injection in JSON/RichText Queries on PostgreSQL/SQLite Adapters

Payload is a free and open source headless content management system. Prior to 3.73.0, when querying JSON or richText fields, user input was directly embedded into SQL without escaping, enabling blin…

payload | Remote | Injection
Feb 06, 2026 Feb 20, 2026
Feb 06, 2026
Feb 20, 2026
8.8 HIGH
CVE-2026-25533 — Enclave has a sandbox escape via infinite recursion and error objects

Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.10.1, the existing layers of security in enclave-vm are insufficient: The AST sanitization can be bypassed…

enclave | Misconfiguration
Feb 06, 2026 Feb 20, 2026
Feb 06, 2026
Feb 20, 2026
Showing 20 of 5141 Results