Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-27590 — Caddy: Unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NA…

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's FastCGI path splitting logic computes the split index on a lowercased copy of the request path and th…

caddy | Remote | Path Traversal
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
6.9 MEDIUM
CVE-2026-27589 — Caddy vulnerable to cross-origin config application via local admin API /load (caddy)

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the local caddy admin API (default listen `127.0.0.1:2019`) exposes a state-changing `POST /load` endpoint th…

caddy | Remote | Misconfiguration
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
9.1 CRITICAL
CVE-2026-27588 — Caddy: MatchHost becomes case-sensitive for large host lists (>100), enabling host-based …

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `host` request matcher is documented as case-insensitive, but when configured with a large host …

caddy | Remote | Misconfiguration
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
9.1 CRITICAL
CVE-2026-27587 — Caddy: MatchPath %xx (escaped-path) branch skips case normalization, enabling path-based …

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `path` request matcher is intended to be case-insensitive, but when the match pattern contains p…

caddy | Remote | Misconfiguration
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
9.1 CRITICAL
CVE-2026-27586 — Caddy's mTLS client authentication silently fails open when CA certificate file is missin…

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, two swallowed errors in `ClientAuthentication.provision()` cause mTLS client certificate authentication to si…

caddy | Remote | Authentication
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
6.9 MEDIUM
CVE-2026-27585 — Caddy's improper sanitization of glob characters in file matcher may lead to bypassing se…

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path sanitization routine in file matcher doesn't sanitize backslashes which can lead to bypassing path r…

caddy | Remote | Path Traversal
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
7.5 HIGH
CVE-2026-27571 — nats-server websockets are vulnerable to pre-auth memory DoS

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The WebSockets handling of NATS messages handles compressed messages via the WebSockets negotiated comp…

nats-server | Remote | Denial of Service
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
8.6 HIGH
CVE-2025-13776 — Hard-coded database credentials in Finka software

Multiple Finka programs use hard-coded Firebird database credentials (shared across all instances of this software). A malicious attacker in local network who knows default credentials is able to rea…

Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
7.5 HIGH
CVE-2024-48928 — Piwigo's secret key can be brute forced

Piwigo is an open source photo gallery application for the web. In versions on the 14.x branch, when installing, the secret_key configuration parameter is set to MD5(RAND()) in MySQL. However, RAND()…

piwigo | Remote | Cross-Site Request Forgery
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
7.5 HIGH
CVE-2026-27521 — Binardat 10G08-0800GSM Network Switch Missing Login Rate Limiting

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior do not implement rate limiting or account lockout on failed login attempts, enabling brute-force attacks against user c…

10g08-0800gsm_firmware 10g08-0800gsm | Remote | Authentication
Feb 24, 2026 Mar 02, 2026
Feb 24, 2026
Mar 02, 2026
8.7 HIGH
CVE-2026-27520 — Binardat 10G08-0800GSM Network Switch Base64-encoded Password Stored in Cookie

Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 store a user password in a client-side cookie as a Base64-encoded value accessible via the web interface. Because Base6…

10g08-0800gsm_firmware 10g08-0800gsm | Remote | Information Disclosure
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
8.7 HIGH
CVE-2026-27519 — Binardat 10G08-0800GSM Network Switch Hard-coded RC4 Encryption Key

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior use RC4 with a hard-coded key embedded in client-side JavaScript. Because the key is static and exposed, an attacker ca…

10g08-0800gsm_firmware 10g08-0800gsm | Remote | Cryptography
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
5.1 MEDIUM
CVE-2026-27518 — Binardat 10G08-0800GSM Network Switch CSRF

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior lack CSRF protections for state-changing actions in the administrative interface. An attacker can trick an authenticate…

10g08-0800gsm_firmware 10g08-0800gsm | Remote | Cross-Site Request Forgery
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
6.1 MEDIUM
CVE-2026-27517 — Binardat 10G08-0800GSM Network Switch XSS

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior reflect unsanitized user input in the web interface, allowing an attacker to inject and execute arbitrary JavaScript in…

10g08-0800gsm_firmware 10g08-0800gsm | Remote | Cross-Site Scripting
Feb 24, 2026 Mar 02, 2026
Feb 24, 2026
Mar 02, 2026
8.6 HIGH
CVE-2026-27516 — Binardat 10G08-0800GSM Network Switch Plaintext Password Exposure

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior expose user passwords in plaintext within the administrative interface and HTTP responses, allowing recovery of valid c…

10g08-0800gsm_firmware 10g08-0800gsm | Remote | Information Disclosure
Feb 24, 2026 Mar 02, 2026
Feb 24, 2026
Mar 02, 2026
9.3 CRITICAL
CVE-2026-27515 — Binardat 10G08-0800GSM Network Switch Predictable Session Identifiers

Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 generate predictable numeric session identifiers in the web management interface. An attacker can guess valid session I…

10g08-0800gsm_firmware 10g08-0800gsm | Remote | Authentication
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
9.8 CRITICAL
CVE-2026-27507 — Binardat 10G08-0800GSM Network Switch Hard-coded Credentials

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain hard-coded administrative credentials that cannot be changed by users. Knowledge of these credentials allows fu…

10g08-0800gsm_firmware 10g08-0800gsm | Remote | Authentication
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
8.8 HIGH
CVE-2026-23678 — Binardat 10G08-0800GSM Network Switch Traceroute CLI Command Injection

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain a command injection vulnerability in the traceroute diagnostic function of the affected device web management i…

10g08-0800gsm_firmware 10g08-0800gsm | Remote | Injection
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
9.8 CRITICAL
CVE-2025-69985 — FUXA JWT Referer Header Bypass RCE

FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, which improperly trus…

fuxa | Remote | Authentication
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
8.8 HIGH
CVE-2025-63409 — GCOM EPON 1GE C00R371V00B01 Privilege Escalation and Improper Access Control Vulnerability

Privilege escalation and improper access control in GCOM EPON 1GE C00R371V00B01 allows remote authenticated users to modify administrator only settings and extract administrator credentials.

gcom_epon_1ge_firmware gcom_epon_1ge | Remote | Authorization
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
Showing 20 of 5379 Results