Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-24004 — Fleet: Unauthenticated Android device disenrollment vulnerability via Pub/Sub endpoint

Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fleet’s Android MDM Pub/Sub handling could allow unauthenticated requests to trigger device unenrollme…

fleet | Remote | Authentication
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
5.5 MEDIUM
CVE-2026-23999 — Fleet: Device lock PIN can be predicted if lock time is known

Fleet is open source device management software. In versions prior to 4.80.1, Fleet generated device lock and wipe PINs using a predictable algorithm based solely on the current Unix timestamp. Becau…

fleet | Cryptography
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
8.1 HIGH
CVE-2026-1779 — User Registration & Membership <= 5.1.2 - Authentication Bypass

The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.2. This is due to incorrect authentication in the 'register_member…

Remote | Authentication
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
6.1 MEDIUM
CVE-2026-2506 — EM Cost Calculator <= 2.3.1 - Unauthenticated Stored Cross-Site Scripting via 'customer_n…

The EM Cost Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.1. This is due to the plugin storing attacker-controlled 'customer_name'…

cost_calculator | Remote | Cross-Site Scripting
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
4.4 MEDIUM
CVE-2026-2499 — Custom Logo <= 2.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via Logo …

The Custom Logo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2 due to insufficient input sanitization and output escapi…

Remote | Cross-Site Scripting
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
4.4 MEDIUM
CVE-2026-2498 — WP Social Meta <= 1.0.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via …

The WP Social Meta plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output e…

Remote | Cross-Site Scripting
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
4.4 MEDIUM
CVE-2026-2489 — TP2WP Importer <= 1.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'W…

The TP2WP Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Watched domains' textarea on the attachment importer settings page in all versions up to, and including, …

Remote | Cross-Site Scripting
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
6.4 MEDIUM
CVE-2026-2029 — Livemesh Addons for Beaver Builder <= 3.9.2 - Authenticated (Contributor+) Stored Cross-S…

The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[labb_pricing_item]` shortcode's `title` and `value` attributes in all versions up to…

beaver_builder_addons | Remote | Cross-Site Scripting
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
4.0 MEDIUM
CVE-2026-27973 — Audiobookshelf has Stored XSS in ItemSearchCard.vue via Audiobook Metadata (Search Result…

Audiobookshelf is a self-hosted audiobook and podcast server. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 0.12.0-beta of the Audiobookshelf mobile application that a…

audiobookshelf | Remote | Cross-Site Scripting
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
7.6 HIGH
CVE-2026-27970 — Angular i18n vulnerable to Cross-Site Scripting (XSS)

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Versions prior to 21.2.0, 21.1.16, 20.3.17, and 19.2.19 have a cros…

angular | Remote | Cross-Site Scripting
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
9.3 CRITICAL
CVE-2026-27969 — Vitess users with backup storage access can write to arbitrary file paths on restore

Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage location (e.g. an S3 bucket) can manip…

vitess | Remote | Path Traversal
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
4.3 MEDIUM
CVE-2026-27968 — Packistry accepts expired access tokens

Packistry is a self-hosted Composer repository designed to handle PHP package distribution. Prior to version 0.13.0, RepositoryAwareController::authorize() verified token presence and ability, but di…

packistry | Remote | Authentication
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
9.8 CRITICAL
CVE-2026-27966 — Langflow has Remote Code Execution in CSV Agent

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent node in Langflow hardcodes `allow_dangerous_code=True`, which automatically expose…

langflow | Remote | Injection
Feb 26, 2026 Feb 28, 2026
Feb 26, 2026
Feb 28, 2026
9.9 CRITICAL
CVE-2026-27965 — Vitess users with backup storage access can gain unauthorized access to production deploy…

Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage location (e.g. an S3 bucket) can manip…

vitess | Remote | Misconfiguration
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
8.8 HIGH
CVE-2026-27961 — Agenta's Server-Side Template Injection (SSTI) via custom evaluator Jinja2 templates allo…

Agenta is an open-source LLMOps platform. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior to 0.86.8 in Agenta's API server evaluator template rendering. Although the vu…

agenta | Remote | Injection
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
7.5 HIGH
CVE-2026-27959 — Koa has Host Header Injection via `ctx.hostname`

Koa is middleware for Node.js using ES2017 async functions. Prior to versions 3.1.2 and 2.16.4, Koa's `ctx.hostname` API performs naive parsing of the HTTP Host header, extracting everything before t…

koa | Remote | Information Disclosure
Feb 26, 2026 Feb 28, 2026
Feb 26, 2026
Feb 28, 2026
6.5 MEDIUM
CVE-2026-27954 — LiveHelperChat has department-level authorization bypass in holdaction, blockuser, and tr…

Live Helper Chat is an open-source application that enables live support websites. In versions up to and including 4.52, three chat action endpoints (holdaction.php, blockuser.php, and transferchat.…

live_helper_chat livehelperchat | Remote | Authorization
Feb 26, 2026 Feb 28, 2026
Feb 26, 2026
Feb 28, 2026
9.9 CRITICAL
CVE-2026-27952 — Agenta has Python Sandbox Escape, Leading to Remote Code Execution (RCE)

Agenta is an open-source LLMOps platform. In Agenta-API prior to version 0.48.1, a Python sandbox escape vulnerability existed in Agenta's custom code evaluator. Agenta used RestrictedPython as a san…

agenta | Remote | Injection
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
6.1 MEDIUM
CVE-2026-27948 — Copyparty vulnerable to eflected cross-site scripting via setck parameter

Copyparty is a portable file server. In versions prior to 1.20.9, an XSS allows for reflected cross-site scripting via URL-parameter `?setck=...`. Version 1.20.9 fixes the issue.

copyparty | Remote | Cross-Site Scripting
Feb 26, 2026 Feb 28, 2026
Feb 26, 2026
Feb 28, 2026
6.5 MEDIUM
CVE-2026-27943 — OpenEMR's Eye Exam View Trusts form_id Without Verifying Patient/Encounter Ownership

OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, the eye exam (eye_mag) view loads data by `form_id` (or…

openemr | Remote | Authorization
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
Showing 20 of 5066 Results