Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.7 HIGH
CVE-2026-25758 — Spree allows unauthenticated users can access all guest addresses

Spree is an open source e-commerce solution built with Ruby on Rails. A critical IDOR vulnerability exists in Spree Commerce's guest checkout flow that allows any guest user to bind arbitrary guest a…

spree | Remote | Authorization
Feb 06, 2026 Feb 19, 2026
Feb 06, 2026
Feb 19, 2026
7.5 HIGH
CVE-2026-25732 — NiceGUI's Path Traversal via Unsanitized FileUpload.name Enables Arbitrary File Write

NiceGUI is a Python-based UI framework. Prior to 3.7.0, NiceGUI's FileUpload.name property exposes client-supplied filename metadata without sanitization, enabling path traversal when developers use …

nicegui | Remote | Path Traversal
Feb 06, 2026 Feb 20, 2026
Feb 06, 2026
Feb 20, 2026
5.4 MEDIUM
CVE-2026-25574 — Payload Affected by Cross-Collection IDOR in payload-preferences Access Control (Multi-Au…

Payload is a free and open source headless content management system. Prior to 3.74.0, a cross-collection Insecure Direct Object Reference (IDOR) vulnerability exists in the payload-preferences inter…

payload | Remote | Authorization
Feb 06, 2026 Feb 20, 2026
Feb 06, 2026
Feb 20, 2026
9.8 CRITICAL
CVE-2026-25544 — Payload has an SQL Injection in JSON/RichText Queries on PostgreSQL/SQLite Adapters

Payload is a free and open source headless content management system. Prior to 3.73.0, when querying JSON or richText fields, user input was directly embedded into SQL without escaping, enabling blin…

payload | Remote | Injection
Feb 06, 2026 Feb 20, 2026
Feb 06, 2026
Feb 20, 2026
8.8 HIGH
CVE-2026-25533 — Enclave has a sandbox escape via infinite recursion and error objects

Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.10.1, the existing layers of security in enclave-vm are insufficient: The AST sanitization can be bypassed…

enclave | Misconfiguration
Feb 06, 2026 Feb 20, 2026
Feb 06, 2026
Feb 20, 2026
6.1 MEDIUM
CVE-2026-25516 — NiceGUI's XSS vulnerability in ui.markdown() allows arbitrary JavaScript execution throug…

NiceGUI is a Python-based UI framework. The ui.markdown() component uses the markdown2 library to convert markdown content to HTML, which is then rendered via innerHTML. By default, markdown2 allows …

nicegui | Remote | Cross-Site Scripting
Feb 06, 2026 Feb 20, 2026
Feb 06, 2026
Feb 20, 2026
5.3 MEDIUM
CVE-2026-25123 — Homarr affected by Unauthenticated SSRF / Port-Scan Primitive via widget.app.ping

Homarr is an open-source dashboard. Prior to 1.52.0, a public (unauthenticated) tRPC endpoint widget.app.ping accepts an arbitrary url and performs a server-side request to that URL. This allows an u…

homarr | Remote | Server-Side Request Forgery
Feb 06, 2026 Feb 18, 2026
Feb 06, 2026
Feb 18, 2026
9.9 CRITICAL
CVE-2026-1731 — BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection V…

BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted re…

remote_support privileged_remote_access | CISA KEV Remote | Injection
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
9.1 CRITICAL
CVE-2026-1727 — Information Disclosure via Bucket Squatting in Google Cloud Agentspace.

The Agentspace service was affected by a vulnerability that exposed sensitive information due to the use of predictable Google Cloud Storage bucket names. These names were utilized for error logs and…

Remote | Information Disclosure
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
7.4 HIGH
CVE-2025-68621 — Trilium Notes has a Timing Attack Vulnerability in /api/login/sync

Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large personal knowledge bases. Prior to 0.101.0, a critical timing attack vulnerability i…

trilium | Remote | Authentication
Feb 06, 2026 Feb 24, 2026
Feb 06, 2026
Feb 24, 2026
9.0 HIGH
CVE-2026-2067 — UTT 进取 520W formTimeGroupConfig strcpy buffer overflow

A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /goform/formTimeGroupConfig. The manipulation of the argument year1 …

520w_firmware 520w | Remote | Memory Corruption
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
9.0 HIGH
CVE-2026-2066 — UTT 进取 520W formIpGroupConfig strcpy buffer overflow

A weakness has been identified in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/formIpGroupConfig. Executing a manipulation of the argument groupName can lead to buff…

520w_firmware 520w | Remote | Memory Corruption
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
7.8 HIGH
CVE-2026-25731 — Calibre Affected by Arbitrary Code Execution via Server-Side Template Injection in Calibr…

calibre is an e-book manager. Prior to 9.2.0, a Server-Side Template Injection (SSTI) vulnerability in Calibre's Templite templating engine allows arbitrary code execution when a user converts an ebo…

calibre | Injection
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
6.5 MEDIUM
CVE-2026-25729 — DeepAudit Affected by User Enumeration via Broken Access Control

DeepAudit is a multi-agent system for code vulnerability discovery. In 3.0.4 and earlier, there is an improper access control vulnerability in the /api/v1/users/ endpoint allows any authenticated use…

deepaudit | Remote | Authorization
Feb 06, 2026 Feb 28, 2026
Feb 06, 2026
Feb 28, 2026
8.2 HIGH
CVE-2026-25636 — calibre has a Path Traversal Leading to Arbitrary File Corruption and Code Execution

calibre is an e-book manager. In 9.1.0 and earlier, a path traversal vulnerability in Calibre's EPUB conversion allows a malicious EPUB file to corrupt arbitrary existing files writable by the Calibr…

calibre | Path Traversal
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
8.6 HIGH
CVE-2026-25635 — calibre has a Path Traversal Leading to Arbitrary File Write and Potential Code Execution

calibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains a path traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions. On Windows (haven…

calibre | Path Traversal
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
7.8 HIGH
CVE-2026-25634 — iccDEV memcpy-param-overlap in CIccTagMultiProcessElement::Apply()

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to 2.3.1.4, SrcPixel and DestPixel stack buffers ove…

iccdev | Memory Corruption
Feb 06, 2026 Feb 19, 2026
Feb 06, 2026
Feb 19, 2026
10.0 CRITICAL
CVE-2026-25632 — EPyT-Flow has unsafe JSON deserialization (__type__)

EPyT-Flow is a Python package designed for the easy generation of hydraulic and water quality scenario data of water distribution networks. Prior to 0.16.1, EPyT-Flow’s REST API parses attacker-contr…

Remote | Injection
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
6.5 MEDIUM
CVE-2026-25631 — Domain allowlist bypass enables credential exfiltration

n8n is an open source workflow automation platform. Prior to 1.121.0, there is a vulnerability in the HTTP Request node's credential domain validation allowed an authenticated attacker to send reques…

n8n | Remote | Server-Side Request Forgery
Feb 06, 2026 Feb 19, 2026
Feb 06, 2026
Feb 19, 2026
8.8 HIGH
CVE-2026-25628 — Qdrant affected by arbitrary file write via `/logger` endpoint

Qdrant is a vector similarity search engine and vector database. From 1.9.3 to before 1.16.0, it is possible to append to arbitrary files via /logger endpoint using an attacker-controlled on_disk.log…

qdrant | Remote | Path Traversal
Feb 06, 2026 Feb 19, 2026
Feb 06, 2026
Feb 19, 2026
Showing 20 of 5090 Results