Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.5 HIGH
CVE-2026-26224 — Intego Log Reporter TOCTOU Local Privilege Escalation

Intego Log Reporter, a macOS diagnostic utility bundled with Intego security products that collects system and application logs for support analysis, contains a local privilege escalation vulnerabili…

| Race Condition
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
5.3 MEDIUM
CVE-2026-26185 — Directus Affected by User Enumeration via Password Reset Timing Attack

Directus is a real-time API and App dashboard for managing SQL database content. Before 11.14.1, a timing-based user enumeration vulnerability exists in the password reset functionality. When an inva…

directus | Remote | Authentication
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
7.5 HIGH
CVE-2026-26076 — ntpd-rs affected by excessive CPU load from malformed packets

ntpd-rs is a full-featured implementation of the Network Time Protocol. Prior to 1.7.1, an attacker can remotely induce moderate increases (2-4 times above normal) in cpu usage. When having NTS enabl…

ntpd-rs | Remote | Denial of Service
Feb 12, 2026 Feb 23, 2026
Feb 12, 2026
Feb 23, 2026
6.9 MEDIUM
CVE-2026-26075 — Cross-Site Request Forgery (CSRF) in FastGPT

FastGPT is an AI Agent building platform. Due to the fact that FastGPT's web page acquisition nodes, HTTP nodes, etc. need to initiate data acquisition requests from the server, there are certain sec…

fastgpt | Remote | Server-Side Request Forgery
Feb 12, 2026 Feb 23, 2026
Feb 12, 2026
Feb 23, 2026
9.1 CRITICAL
CVE-2026-26069 — Scraparr Readarr Integration exposes sensitive values as metric labels.

Scraparr is a Prometheus Exporter for various components of the *arr Suite. From 3.0.0-beta to before 3.0.2, when the Readarr integration was enabled, the exporter exposed the configured Readarr API …

scraparr | Remote | Information Disclosure
Feb 12, 2026 Feb 23, 2026
Feb 12, 2026
Feb 23, 2026
9.9 CRITICAL
CVE-2026-26068 — emp3r0r Agent-Controlled Metadata to Operator RCE (tmux Command Injection)

emp3r0r is a stealth-focused C2 designed by Linux users for Linux environments. Prior to 3.21.1, untrusted agent metadata (Transport, Hostname) is accepted during check-in and later interpolated into…

emp3r0r | Remote | Injection
Feb 12, 2026 Feb 25, 2026
Feb 12, 2026
Feb 25, 2026
8.8 HIGH
CVE-2026-26056 — Arbitrary WASM Code Execution via AnnotationOverrideFlight Injection in Yoke ATC

Yoke is a Helm-inspired infrastructure-as-code (IaC) package deployer. In 0.19.0 and earlier, a vulnerability exists in the Air Traffic Controller (ATC) component of Yoke. It allows users with CR cre…

Remote | Injection
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
7.5 HIGH
CVE-2026-26055 — Unauthenticated Admission Webhook Endpoints in Yoke ATC

Yoke is a Helm-inspired infrastructure-as-code (IaC) package deployer. In 0.19.0 and earlier, a vulnerability exists in the Air Traffic Controller (ATC) component of Yoke. The ATC webhook endpoints l…

Remote | Authentication
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
5.4 MEDIUM
CVE-2026-25828 — Grub-Btrfs Command Injection Vulnerability

grub-btrfs through 2026-01-31 (on Arch Linux and derivative distributions) allows initramfs OS command injection because it does not sanitize the $root parameter to resolve_device(). NOTE: a third pa…

Remote | Injection
Feb 12, 2026 Mar 04, 2026
Feb 12, 2026
Mar 04, 2026
9.8 CRITICAL
CVE-2026-1358 — Airleader Master Unrestricted Upload of File with Dangerous Type

Airleader Master versions 6.381 and prior allow for file uploads without restriction to multiple webpages running maximum privileges. This could allow an unauthenticated user to potentially obtain …

Remote | Authentication
Feb 12, 2026 Mar 03, 2026
Feb 12, 2026
Mar 03, 2026
6.1 MEDIUM
CVE-2025-70845 — "Lty628 Aidigu XSS"

lty628 aidigu v1.9.1 is vulnerable to Cross Site Scripting (XSS) exists in the /setting/ page where the "intro" field is not properly sanitized or escaped.

Remote | Cross-Site Scripting
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
5.4 MEDIUM
CVE-2025-14282 — Dropbear: privilege escalation via unix domain socket forwardings

A flaw was found in Dropbear. When running in multi-user mode and authenticating users, the dropbear ssh server does the socket forwardings requested by the remote client as root, only switching to t…

Remote | Authorization
Feb 12, 2026 Feb 18, 2026
Feb 12, 2026
Feb 18, 2026
9.4 CRITICAL
CVE-2026-26020 — AutoGPT Affected by Remote Code Execution via Dynamic Module Import in Block Loading (__i…

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to 0.6.48, an authenticated user could achieve R…

autogpt_platform | Remote | Authentication
Feb 12, 2026 Feb 17, 2026
Feb 12, 2026
Feb 17, 2026
9.8 CRITICAL
CVE-2026-26011 — Critical Heap Out-of-bounds Access in `pf_cluster_stats()` via Malicious /initialpose Cov…

navigation2 is a ROS 2 Navigation Framework and System. In 1.3.11 and earlier, a critical heap out-of-bounds write vulnerability exists in Nav2 AMCL's particle filter clustering logic. By publishing …

nav2 | Remote | Memory Corruption
Feb 12, 2026 Feb 23, 2026
Feb 12, 2026
Feb 23, 2026
5.0 MEDIUM
CVE-2026-26005 — ClipBucket v5 enables internal network scans via an SSRF vulnerability

ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #45, in Clip Bucket V5, The Remote Play allows creating video entries that reference external video URLs without uploading the…

clipbucket | Remote | Server-Side Request Forgery
Feb 12, 2026 Feb 18, 2026
Feb 12, 2026
Feb 18, 2026
6.1 MEDIUM
CVE-2026-26000 — XWiki Platform affected by click-jacking through CSS injection in comments

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.9.0, 17.4.6, and 16.10.13, it's possible using comments to inject CSS that would t…

xwiki | Remote | Cross-Site Scripting
Feb 12, 2026 Feb 19, 2026
Feb 12, 2026
Feb 19, 2026
9.8 CRITICAL
CVE-2026-25996 — Inspektor Gadget uses unsanitized ANSI Escape Sequences In `columns` Output Mode

Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. String fields from eBPF events in columns output mode are…

inspektor_gadget | Remote | Information Disclosure
Feb 12, 2026 Feb 23, 2026
Feb 12, 2026
Feb 23, 2026
6.0 MEDIUM
CVE-2026-0619 — Integer Wraparound DoS in Silicon Labs Matter Implementation

A reachable infinite loop via an integer wraparound is present in Silicon Labs' Matter SDK which allows an attacker to trigger a denial of service. A hard reset is required to recover the device.

Remote | Denial of Service
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
7.5 HIGH
CVE-2026-25949 — Traefik: TCP readTimeout bypass via STARTTLS on Postgres

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.8, there is a potential vulnerability in Traefik managing STARTTLS requests. An unauthenticated client can bypass Traefik entrypoint r…

traefik | Remote | Denial of Service
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
6.8 MEDIUM
CVE-2026-25933 — Arduino App Lab has Improper Data Validation in Internal Terminal Interface

Arduino App Lab is a cross-platform IDE for developing Arduino Apps. Prior to 0.4.0, a vulnerability was identified in the Terminal component of the arduino-app-lab application. The issue stems from …

app_lab | Injection
Feb 12, 2026 Feb 19, 2026
Feb 12, 2026
Feb 19, 2026
Showing 20 of 5064 Results