Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-1229 — Incorrect calculation in CIRCL secp384r1 CombinedMult

The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas. ECDH and ECDSA signi…

circl | Remote | Cryptography
Feb 24, 2026 Mar 03, 2026
Feb 24, 2026
Mar 03, 2026
9.1 CRITICAL
CVE-2025-40541 — SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Remote Code Execution Vulnerabi…

An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor the ability to execute native code as a privileged account. This issue requir…

serv-u | Remote | Authorization
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
9.1 CRITICAL
CVE-2025-40540 — SolarWinds Serv-U Type Confusion Remote Code Execution Vulnerability

A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative p…

serv-u | Remote | Memory Corruption
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
9.1 CRITICAL
CVE-2025-40539 — SolarWinds Serv-U Type Confusion Remote Code Execution Vulnerability

A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative p…

serv-u | Remote | Memory Corruption
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
9.1 CRITICAL
CVE-2025-40538 — SolarWinds Serv-U Broken Access Control Remote Code Execution Vulnerability

A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to create a system admin user and execute arbitrary code as a privileged account via d…

serv-u | Remote | Authorization
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
4.3 MEDIUM
CVE-2026-24314 — Information Disclosure vulnerability in S/4HANA (Manage Payment Media)

Under certain conditions SAP S/4HANA (Manage Payment Media) allows an authenticated attacker to access information which would otherwise be restricted. This could cause low impact on confidentiality …

s\/4hana_uiapfi70 s\/4hana_uis4h | Remote | Authorization
Feb 24, 2026 Mar 03, 2026
Feb 24, 2026
Mar 03, 2026
7.2 HIGH
CVE-2025-15589 — MuYuCMS Template Management Template.php delete_dir_file path traversal

A vulnerability was determined in MuYuCMS 2.7. Affected is the function delete_dir_file of the file application/admin/controller/Template.php of the component Template Management Page. This manipulat…

muyucms | Remote | Path Traversal
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
8.8 HIGH
CVE-2025-15386 — Responsive Lightbox & Gallery < 2.6.1 - Unauthenticated Stored XSS

The Responsive Lightbox & Gallery WordPress plugin before 2.6.1 is vulnerable to an Unauthenticated Stored-XSS attack due to flawed regex replacement rules that can be abused by posting a comment wit…

responsive_lightbox | Remote | Cross-Site Scripting
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
6.1 MEDIUM
CVE-2026-3070 — SourceCodester Modern Image Gallery App upload.php cross site scripting

A vulnerability was detected in SourceCodester Modern Image Gallery App 1.0. Affected by this vulnerability is an unknown functionality of the file upload.php. The manipulation of the argument filena…

modern_image_gallery_app | Remote | Cross-Site Scripting
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
9.8 CRITICAL
CVE-2026-3069 — itsourcecode Document Management System edtlbls.php sql injection

A security vulnerability has been detected in itsourcecode Document Management System 1.0. Affected is an unknown function of the file /edtlbls.php. The manipulation of the argument field1 leads to s…

Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
9.8 CRITICAL
CVE-2026-3068 — itsourcecode Document Management System deluser.php sql injection

A weakness has been identified in itsourcecode Document Management System 1.0. This impacts an unknown function of the file /deluser.php. Executing a manipulation of the argument user2del can lead to…

Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
8.8 HIGH
CVE-2026-3067 — HummerRisk Archive Extraction CommandUtils.java extractZip path traversal

A vulnerability has been found in HummerRisk up to 1.5.0. This issue affects the function extractTarGZ/extractZip of the file hummer-common/hummer-common-core/src/main/java/com/hummer/common/core/uti…

hummerrisk | Remote | Path Traversal
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
8.8 HIGH
CVE-2026-3066 — HummerRisk Cloud Compliance Scanning PlatformUtils.java fixedCommand command injection

A flaw has been found in HummerRisk up to 1.5.0. This vulnerability affects the function fixedCommand of the file hummer-common/hummer-common-core/src/main/java/com/hummer/common/core/utils/PlatformU…

hummerrisk | Remote | Injection
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
6.9 MEDIUM
CVE-2026-27461 — Pimcore vulnerable to SQL injection via unsanitized filter value in Dependency Dao RLIKE …

Pimcore is an Open Source Data & Experience Management Platform. In versions up to and including 11.5.14.1 and 12.3.2, the filter query parameter in the dependency listing endpoints is JSON-decoded a…

pimcore | Remote | Injection
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
7.1 HIGH
CVE-2026-3091 — Synology Presto Client DLL Injection Vulnerability

An uncontrolled search path element vulnerability in Synology Presto Client before 2.1.3-0672 allows local users to read or write arbitrary files during installation by placing a malicious DLL in adv…

presto_client | Path Traversal
Feb 24, 2026 Mar 04, 2026
Feb 24, 2026
Mar 04, 2026
8.8 HIGH
CVE-2026-3065 — HummerRisk Cloud Task Dry-run CloudTaskService.java CommandUtils.commonExecCmdWithResult …

A vulnerability was detected in HummerRisk up to 1.5.0. This affects the function CommandUtils.commonExecCmdWithResult of the file CloudTaskService.java of the component Cloud Task Dry-run. Performin…

hummerrisk | Remote | Injection
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
8.8 HIGH
CVE-2026-3064 — HummerRisk Cloud Task Scheduler ResourceCreateService.java command injection

A security vulnerability has been detected in HummerRisk up to 1.5.0. Affected by this issue is some unknown functionality of the file ResourceCreateService.java of the component Cloud Task Scheduler…

hummerrisk | Remote | Injection
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
9.8 CRITICAL
CVE-2026-3057 — a54552239 pearProjectApi Backend Task.php dateTotalForProject sql injection

A security flaw has been discovered in a54552239 pearProjectApi up to 2.8.10. Affected is the function dateTotalForProject of the file application/common/Model/Task.php of the component Backend Inter…

pearprojectapi | Remote | Injection
Feb 24, 2026 Mar 03, 2026
Feb 24, 2026
Mar 03, 2026
6.1 MEDIUM
CVE-2026-3054 — Alinto SOGo cross site scripting

A vulnerability was identified in Alinto SOGo 5.12.3/5.12.4. This impacts an unknown function. The manipulation of the argument hint leads to cross site scripting. The attack can be initiated remotel…

sogo | Remote | Cross-Site Scripting
Feb 24, 2026 Feb 28, 2026
Feb 24, 2026
Feb 28, 2026
6.5 MEDIUM
CVE-2026-27129 — Cloud Metadata SSRF Protection Bypass via IPv6 Resolution

Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF validation in Craft CMS’s GraphQL Asset mutation uses `gethostbyname()`, which…

craft_cms | Remote | Server-Side Request Forgery
Feb 24, 2026 Mar 02, 2026
Feb 24, 2026
Mar 02, 2026
Showing 20 of 5383 Results