Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-28414 — Gradio has Absolute Path Traversal on Windows with Python 3.13+

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Window with Python 3.13+ are vulnerable to an absolute path traversal issue that e…

gradio | Remote | Path Traversal
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2026-28411 — WeGIA Vulnerable to Authentication Bypass via `extract($_REQUEST)`

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, an unsafe use of the `extract()` function on the `$_REQUEST` superglobal allows an unauthenticated attacker to overwrite lo…

wegia | Remote | Authentication
Feb 27, 2026 Mar 03, 2026
Feb 27, 2026
Mar 03, 2026
10.0 CRITICAL
CVE-2026-28409 — WeGIA Vulnerable to Remote Code Execution (RCE) via OS Command Injection

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulnerability exists in the WeGIA application's database restoration functionality. …

wegia | Remote | Injection
Feb 27, 2026 Mar 03, 2026
Feb 27, 2026
Mar 03, 2026
9.8 CRITICAL
CVE-2026-28408 — WeGIA lacks authentication verification in adicionar_tipo_docs_atendido.php

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, the script in adicionar_tipo_docs_atendido.php does not go through the project's central controller and does not have its o…

wegia | Remote | Authorization
Feb 27, 2026 Mar 03, 2026
Feb 27, 2026
Mar 03, 2026
6.9 MEDIUM
CVE-2026-28407 — malcontent's nested archive extraction failure can drop content from scan inputs

malcontent is software for discovering supply-chain compromises through context, differential analysis, and YARA. Prior to version 1.21.0, malcontent would remove nested archives which failed to extr…

malcontent | Remote | Supply Chain
Feb 27, 2026 Mar 03, 2026
Feb 27, 2026
Mar 03, 2026
8.2 HIGH
CVE-2026-28406 — kaniko has tar archive path traversal in build context extraction allows writing files ou…

kaniko is a tool to build container images from a Dockerfile, inside a container or Kubernetes cluster. Starting in version 1.25.4 and prior to version 1.25.10, kaniko unpacks build context archives …

kaniko | Remote | Path Traversal
Feb 27, 2026 Mar 06, 2026
Feb 27, 2026
Mar 06, 2026
7.1 HIGH
CVE-2026-28402 — nimiq/core-rs-albatross's nimiq-blockchain missing proposal body root verification

nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.2.2, a malicious or compromised validator that is …

Remote | Misconfiguration
Feb 27, 2026 Mar 02, 2026
Feb 27, 2026
Mar 02, 2026
7.5 HIGH
CVE-2026-28400 — Docker Model Runner Unauthenticated Runtime Flag Injection via _configure Endpoint

Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Versions prior to 1.0.16 expose a POST `/engines/_configure` endpoint that accepts arbitrary runtime fl…

| Misconfiguration
Feb 27, 2026 Mar 02, 2026
Feb 27, 2026
Mar 02, 2026
8.8 HIGH
CVE-2026-27939 — Statamic allows Authenticated Control Panel users to escalate privileges via elevated ses…

Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6.4.0, Authenticated Control Panel users may under certain conditions obtain ele…

statamic | Remote | Authentication
Feb 27, 2026 Mar 10, 2026
Feb 27, 2026
Mar 10, 2026
5.9 MEDIUM
CVE-2026-27167 — Gradio: Mocked OAuth Login Exposes Server Credentials and Uses Hardcoded Session Secret

Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version 6.6.0, Gradio applications running outside of Hugging Face Spaces automatically…

gradio | Remote | Misconfiguration
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
1.3 LOW
CVE-2026-28355 — "PWA" Canarytoken Vulnerable to Stored Self Cross-Site Scripting

Canarytokens help track activity and actions on a network. Versions prior to `sha-7ff0e12` have a Self Cross-Site Scripting vulnerability in the "PWA" Canarytoken, whereby the Canarytoken's creator c…

canarytokens | Remote | Cross-Site Scripting
Feb 27, 2026 Mar 02, 2026
Feb 27, 2026
Mar 02, 2026
6.5 MEDIUM
CVE-2026-28352 — Indico missing access check in event series management API

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In versions prior to 3.3.11, the API endpoint used to manage event series is missing a…

indico | Remote | Authentication
Feb 27, 2026 Mar 03, 2026
Feb 27, 2026
Mar 03, 2026
6.9 MEDIUM
CVE-2026-28351 — Manipulated RunLengthDecode streams can exhaust RAM

pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.4, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing the c…

pypdf | Remote | Denial of Service
Feb 27, 2026 Mar 03, 2026
Feb 27, 2026
Mar 03, 2026
6.8 MEDIUM
CVE-2026-28338 — PMD Designer has Stored XSS in VBHTMLRenderer and YAHTMLRenderer via unescaped violation …

PMD is an extensible multilanguage static code analyzer. Prior to version 7.22.0, PMD's `vbhtml` and `yahtml` report formats insert rule violation messages into HTML output without escaping. When PMD…

pmd | Remote | Cross-Site Scripting
Feb 27, 2026 Mar 03, 2026
Feb 27, 2026
Mar 03, 2026
5.5 MEDIUM
CVE-2026-28288 — Dify has a user enumeration issue

Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-existent accounts differ, allowing an attacker to enumerate email addresses regist…

dify | Remote | Information Disclosure
Feb 27, 2026 Mar 09, 2026
Feb 27, 2026
Mar 09, 2026
8.1 HIGH
CVE-2026-28272 — Kiteworks Email Protection Gateway has a Cross-site Scripting vulnerability

Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks Email Protection Gateway allows authenticated administrators to inject malicious scripts through a conf…

kiteworks | Remote | Cross-Site Scripting
Feb 27, 2026 Mar 04, 2026
Feb 27, 2026
Mar 04, 2026
6.5 MEDIUM
CVE-2026-28271 — Kiteworks Core is vulnerable to Server-Side Request Forgery (SSRF)

Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration functionality allows bypassing of SSRF protections through DNS rebinding attacks. Malicio…

kiteworks | Remote | Server-Side Request Forgery
Feb 27, 2026 Mar 04, 2026
Feb 27, 2026
Mar 04, 2026
7.2 HIGH
CVE-2026-28270 — Kiteworks Core has an Unrestricted Upload of File with Dangerous Type

Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration allows uploading of arbitrary files without proper validation. Malicious administrators c…

kiteworks | Remote | Misconfiguration
Feb 27, 2026 Mar 04, 2026
Feb 27, 2026
Mar 04, 2026
9.8 CRITICAL
CVE-2026-28268 — Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse

Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerability exists in the password reset mechanism of vikunja/api that allows password …

vikunja | Remote | Authentication
Feb 27, 2026 Mar 06, 2026
Feb 27, 2026
Mar 06, 2026
6.5 MEDIUM
CVE-2018-25160 — HTTP::Session2 versions through 1.09 for Perl does not validate the format of user provid…

HTTP::Session2 versions through 1.09 for Perl does not validate the format of user provided session ids, enabling code injection or other impact depending on session backend. For example, if an appl…

http\ | Remote | Injection
Feb 27, 2026 Mar 03, 2026
Feb 27, 2026
Mar 03, 2026
Showing 20 of 5272 Results