Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-3201 — Improperly Controlled Sequential Memory Allocation in Wireshark

USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service

wireshark | Remote | Denial of Service
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-3187 — feiyuchuixue sz-boot-parent API Endpoint upload unrestricted upload

A vulnerability was identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this issue is some unknown functionality of the file /api/admin/sys-file/upload of the component API Endpoi…

sz-boot-parent | Remote | Misconfiguration
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
5.9 MEDIUM
CVE-2026-2878 — Insufficient Entropy Vulnerability in Telerik UI for ASP.NET AJAX

In Progress® Telerik® UI for AJAX, versions prior to 2026.1.225, an insufficient entropy vulnerability exists in RadAsyncUpload, where a predictable temporary identifier, based on timestamp and filen…

telerik_ui_for_asp.net_ajax | Remote | Cryptography
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-27699 — Basic FTP has Path Traversal Vulnerability in its downloadToDir() method

The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()` method. A malicious FTP server can send directory l…

basic-ftp | Remote | Path Traversal
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
5.3 MEDIUM
CVE-2026-27695 — zae-limiter: DynamoDB hot partition throttling enables per-entity Denial of Service

zae-limiter is a rate limiting library using the token bucket algorithm. Prior to version 0.10.1, all rate limit buckets for a single entity share the same DynamoDB partition key (`namespace/ENTITY#{…

zae-limiter | Remote | Denial of Service
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
7.1 HIGH
CVE-2026-27692 — iccDEV has HBO in CIccTagTextDescription::Release()

iccDEV provides a set of libraries and tools for working with ICC color management profiles. In versions up to and including 2.3.1.4, heap-buffer-overflow read occurs during CIccTagTextDescription::R…

iccdev | Memory Corruption
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
6.2 MEDIUM
CVE-2026-27691 — iccDEV has SIO in parse3DTable() at iccFromCube.cpp Line 218

iccDEV provides a set of libraries and tools for working with ICC color management profiles. In versions up to and including 2.3.1.4, signed integer overflow in iccFromCube.cpp during multiplication …

iccdev | Memory Corruption
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
6.5 MEDIUM
CVE-2026-3186 — feiyuchuixue sz-boot-parent Password Reset password default password

A vulnerability was determined in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this vulnerability is an unknown functionality of the file /api/admin/sys-user/reset/password/ of the compo…

sz-boot-parent | Remote | Authorization
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
5.5 MEDIUM
CVE-2026-3185 — feiyuchuixue sz-boot-parent API Endpoint sys-message authorization

A vulnerability was found in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected is an unknown function of the file /api/admin/sys-message/ of the component API Endpoint. The manipulation of the a…

sz-boot-parent | Remote | Authorization
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
2.3 LOW
CVE-2026-28196 — JetBrains TeamCity Unsecured Credentials Disclosure

In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk

teamcity | Information Disclosure
Feb 25, 2026 Feb 25, 2026
Feb 25, 2026
Feb 25, 2026
4.3 MEDIUM
CVE-2026-28195 — JetBrains TeamCity Unauthenticated Build Configuration Parameter Injection

In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations

teamcity | Remote | Authorization
Feb 25, 2026 Feb 25, 2026
Feb 25, 2026
Feb 25, 2026
6.1 MEDIUM
CVE-2026-28194 — JetBrains TeamCity Open Redirect Vulnerability

In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow

teamcity | Remote | Misconfiguration
Feb 25, 2026 Feb 25, 2026
Feb 25, 2026
Feb 25, 2026
8.8 HIGH
CVE-2026-28193 — JetBrains YouTrack Unvalidated Request Vulnerability

In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint

youtrack | Remote | Server-Side Request Forgery
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-2624 — Authentication Bypass in ePati's Antikor NGFW

Missing Authentication for Critical Function vulnerability in ePati Cyber ​​Security Technologies Inc. Antikor Next Generation Firewall (NGFW) allows Authentication Bypass.This issue affects Antikor …

antikor_next_generation_firewall | Remote | Authentication
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
2.6 LOW
CVE-2026-21725 — Authorization Bypass via TOCTOU in Grafana Datasource Deletion by Name

A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so. This requires several very stringent conditions to…

grafana | Remote | Race Condition
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
9.1 CRITICAL
CVE-2026-0704 — Octopus Deploy File Traversal Vulnerability

In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked validation which could potentially result in ways to…

linux_kernel windows octopus_server | Remote | Path Traversal
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
6.5 MEDIUM
CVE-2026-3118 — Rhdh: graphql injection leading to platform-wide denial of service (dos) in rh developer …

A security flaw was identified in the Orchestrator Plugin of Red Hat Developer Hub (Backstage). The issue occurs due to insufficient input validation in GraphQL query handling. An authenticated user …

developer_hub | Remote | Injection
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
7.0 HIGH
CVE-2026-25701 — openSUSE sdbootutil Temporary File Insecure Directory Creation Vulnerability

An Insecure Temporary File vulnerability in openSUSE sdbootutil allows local users to pre-create a directory to achieve various effects like: * gain access to possible private information found in…

| Information Disclosure
Feb 25, 2026 Feb 25, 2026
Feb 25, 2026
Feb 25, 2026
5.5 MEDIUM
CVE-2026-26104 — Udisks: missing authorization check allows unprivileged users to back up luks headers via…

A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue occurs because a privileged D-Bus method re…

enterprise_linux udisks gix-date | Authorization
Feb 25, 2026 Mar 02, 2026
Feb 25, 2026
Mar 02, 2026
7.1 HIGH
CVE-2026-26103 — Udisks: missing authorization check allows unprivileged users to restore luks headers via…

A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue allows a local unpriv…

enterprise_linux udisks gix-date | Authorization
Feb 25, 2026 Mar 02, 2026
Feb 25, 2026
Mar 02, 2026
Showing 20 of 5430 Results