Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.8 HIGH
CVE-2026-25880 — Untrusted Search Path in SumatraPDF Reader (explorer.exe on Windows)

SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, the PDF reader allows execution of a malicious binary (explorer.exe) located in the same directory as the opened PDF when the us…

sumatrapdf | Authentication
Feb 09, 2026 Feb 23, 2026
Feb 09, 2026
Feb 23, 2026
9.8 CRITICAL
CVE-2026-25875 — PlaciPy Admin Privilege Escalation via Trusted JWT Claims

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, The admin authorization middleware trusts client-controlled JWT claims (role and scope) without enfor…

placipy | Remote | Authorization
Feb 09, 2026 Feb 11, 2026
Feb 09, 2026
Feb 11, 2026
9.8 CRITICAL
CVE-2026-25814 — NoSQL Injection Risk via Unsanitized Query Parameters

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, User-controlled query parameters are passed directly into DynamoDB query/filter construction without …

placipy | Remote | Injection
Feb 09, 2026 Feb 18, 2026
Feb 09, 2026
Feb 18, 2026
8.7 HIGH
CVE-2026-25813 — PlaciPy Exposes Sensitive Data via Application Logs

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, The application logs highly sensitive data directly to console output without masking or redaction.

placipy | Remote | Information Disclosure
Feb 09, 2026 Feb 18, 2026
Feb 09, 2026
Feb 18, 2026
9.3 CRITICAL
CVE-2026-25812 — PlaciPy is Missing CSRF Protection on State-Changing Endpoints

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application enables credentialed CORS requests but does not implement any CSRF protection mechani…

placipy | Remote | Cross-Site Request Forgery
Feb 09, 2026 Feb 18, 2026
Feb 09, 2026
Feb 18, 2026
9.1 CRITICAL
CVE-2026-25811 — PlaciPy Email Domain Trust Enables Cross-Tenant Data Access (Multi-Tenant Isolation Failu…

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application derives the tenant identifier directly from the email domain provided by the user, wi…

placipy | Remote | Authentication
Feb 09, 2026 Feb 18, 2026
Feb 09, 2026
Feb 18, 2026
7.5 HIGH
CVE-2026-25808 — Hollo DMs get leaked and can be seen on Webfinger Browser

Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Prior to 0.6.20 and 0.7.2, there is a security vulnerability where DMs and followers-only posts w…

hollo | Remote | Authorization
Feb 09, 2026 Feb 28, 2026
Feb 09, 2026
Feb 28, 2026
8.8 HIGH
CVE-2026-25807 — Unauthenticated Remote Code Execution via P2P Sharing in ZAI-Shell

ZAI Shell is an autonomous SysOps agent designed to navigate, repair, and secure complex environments. Prior to 9.0.3, the P2P terminal sharing feature (share start) opens a TCP socket on port 5757 w…

zai_shell | Remote | Authentication
Feb 09, 2026 Feb 24, 2026
Feb 09, 2026
Feb 24, 2026
6.5 MEDIUM
CVE-2025-15317 — Tanium addressed an uncontrolled resource consumption vulnerability in Tanium Server.

Tanium addressed an uncontrolled resource consumption vulnerability in Tanium Server.

server | Remote | Denial of Service
Feb 09, 2026 Feb 10, 2026
Feb 09, 2026
Feb 10, 2026
6.7 MEDIUM
CVE-2025-15316 — Tanium addressed a local privilege escalation vulnerability in Tanium Server.

Tanium addressed a local privilege escalation vulnerability in Tanium Server.

server | Authorization
Feb 09, 2026 Feb 10, 2026
Feb 09, 2026
Feb 10, 2026
6.7 MEDIUM
CVE-2025-15315 — Tanium addressed a local privilege escalation vulnerability in Tanium Module Server.

Tanium addressed a local privilege escalation vulnerability in Tanium Module Server.

moduleserver | Authentication
Feb 09, 2026 Feb 10, 2026
Feb 09, 2026
Feb 10, 2026
6.9 MEDIUM
CVE-2026-25878 — FroshAdminer Adminer UI is accessible without admin session

FroshAdminer is the Adminer plugin for Shopware Platform. Prior to 2.2.1, the Adminer route (/admin/adminer) was accessible without Shopware admin authentication. The route was configured with auth_r…

froshadminer | Remote | Authentication
Feb 09, 2026 Feb 28, 2026
Feb 09, 2026
Feb 28, 2026
9.1 CRITICAL
CVE-2026-25876 — PlaciPy is Missing Authorization on Assessment Results Endpoint

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes/results.routes.ts verify authentication but fails to enforce object-level auth…

placipy | Remote | Authorization
Feb 09, 2026 Feb 11, 2026
Feb 09, 2026
Feb 11, 2026
9.1 CRITICAL
CVE-2026-25810 — PlaciPy is Missing Object-Level Authorization in student.submission.routes.ts

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes/student.submission.routes.ts verify authentication but fails to enforce object…

placipy | Remote | Authorization
Feb 09, 2026 Feb 11, 2026
Feb 09, 2026
Feb 11, 2026
9.8 CRITICAL
CVE-2026-25809 — PlaciPy Code Execution Allowed Without Assessment Active State Validation

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the code evaluation endpoint does not validate the assessment lifecycle state before allowing executi…

placipy | Remote | Authorization
Feb 09, 2026 Feb 11, 2026
Feb 09, 2026
Feb 11, 2026
6.5 MEDIUM
CVE-2026-25806 — PlaciPy has Missing Authorization Checks on Student Management Endpoints (IDOR)

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the GET /api/students/:email PUT /api/students/:email/status, and DELETE /api/students/:email routes …

placipy | Remote | Authorization
Feb 09, 2026 Feb 11, 2026
Feb 09, 2026
Feb 11, 2026
7.5 HIGH
CVE-2026-25791 — Sliver has a DNS C2 OTP Bypass Allows Unauthenticated Session Flooding and Denial of Serv…

Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.7.0, the DNS C2 listener accepts unauthenticated TOTP bootstrap messages and allocates server-side DNS sess…

sliver | Remote | Authentication
Feb 09, 2026 Feb 23, 2026
Feb 09, 2026
Feb 23, 2026
5.8 MEDIUM
CVE-2026-25765 — Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url

Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Prior to 2.14.1, Faraday's build_exclusive_url method (in lib/faraday/connection.rb) uses Ruby…

faraday | Remote | Server-Side Request Forgery
Feb 09, 2026 Feb 20, 2026
Feb 09, 2026
Feb 20, 2026
8.8 HIGH
CVE-2026-25761 — Command injection via crafted filenames in Super-linter Action

Super-linter is a combination of multiple linters to run as a GitHub Action or standalone. From 6.0.0 to 8.3.0, the Super-linter GitHub Action is vulnerable to command injection via crafted filenames…

super-linter | Remote | Injection
Feb 09, 2026 Feb 28, 2026
Feb 09, 2026
Feb 28, 2026
5.8 MEDIUM
CVE-2026-25740 — Privilege escalation to the `CAP_NET_RAW` capability via the `programs.captive-browser` N…

captive browser, a dedicated Chrome instance to log into captive portals without messing with DNS settings. In 25.05 and earlier, when programs.captive-browser is enabled, any user of the system can …

| Misconfiguration
Feb 09, 2026 Feb 09, 2026
Feb 09, 2026
Feb 09, 2026
Showing 20 of 5087 Results