Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.0 MEDIUM
CVE-2026-27900 — Terraform Provider Debug Logs Vulnerable to Sensitive Information Exposure

The Terraform Provider for Linode versions prior to v3.9.0 logged sensitive information including some passwords, StackScript content, and object storage data in debug logs without redaction. Provide…

Remote | Information Disclosure
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
8.8 HIGH
CVE-2026-27899 — WireGuard Portal Vulnerable to Privilege Escalation to Admin via User Self-Update

WireGuard Portal (or wg-portal) is a web-based configuration portal for WireGuard server management. Prior to version 2.1.3, any authenticated non-admin user can become a full administrator by sendin…

wireguard_portal | Remote | Authorization
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
6.9 MEDIUM
CVE-2026-27887 — Spin has memory leaks in various WIT interfaces

Spin is an open source developer tool for building and running serverless applications powered by WebAssembly. When Spin is configured to allow connections to a database or web server which could ret…

Remote | Denial of Service
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
4.9 MEDIUM
CVE-2026-22728 — sealed-secrets /v1/rotate can widen sealing scope to cluster-wide via attacker-controlled…

Bitnami Sealed Secrets is vulnerable to a scope-widening attack during the secret rotation (/v1/rotate) flow. The rotation handler derives the sealing scope for the newly encrypted output from untrus…

Remote | Authorization
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
7.5 HIGH
CVE-2026-1557 — WP Responsive Images <= 1.0 - Unauthenticated Path Traversal to Arbitrary File Read via s…

The WP Responsive Images plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0 via the 'src' parameter. This makes it possible for unauthenticated attackers t…

Remote | Path Traversal
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
8.2 HIGH
CVE-2026-27946 — ZITADEL Users Can Self-Verify Email/Phone via UpdateHumanUser API

ZITADEL is an open source identity management platform. Prior to versions 4.11.1 and 3.4.7, a vulnerability in Zitadel's self-management capability allowed users to mark their email and phone as veri…

zitadel | Remote | Authentication
Feb 26, 2026 Mar 05, 2026
Feb 26, 2026
Mar 05, 2026
6.5 MEDIUM
CVE-2026-27945 — ZITADEL has potential SSRF via Actions

ZITADEL is an open source identity management platform. Zitadel Action V2 (introduced as early preview in 2.59.0, beta in 3.0.0 and GA in 4.0.0) is a webhook based approach to allow developers act on…

zitadel | Remote | Server-Side Request Forgery
Feb 26, 2026 Mar 05, 2026
Feb 26, 2026
Mar 05, 2026
7.0 HIGH
CVE-2026-27896 — MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity

The Go MCP SDK used Go's standard encoding/json.Unmarshal for JSON-RPC and MCP protocol message parsing in versions prior to 1.3.1. Go's standard library performs case-insensitive matching of JSON ke…

Remote | Injection
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
7.5 HIGH
CVE-2026-27888 — pypdf: Manipulated FlateDecode XFA streams can exhaust RAM

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.3, an attacker who uses this vulnerability can craft a PDF which leads to the RAM being exhausted. This requires accessing the `x…

pypdf | Remote | Denial of Service
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
5.3 MEDIUM
CVE-2026-27884 — NetExec vulnerable to arbitrary file write via path traversal in spider_plus module

NetExec is a network execution tool. Prior to version 1.5.1, the module spider_plus improperly creates the output file and folder path when saving files from SMB shares. It does not take into account…

Remote | Path Traversal
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
4.3 MEDIUM
CVE-2026-27840 — ZITADEL's truncated opaque tokens are still valid

ZITADEL is an open source identity management platform. Starting in version 2.31.0 and prior to versions 3.4.7 and 4.11.0, opaque OIDC access tokens in the v2 format truncated to 80 characters are st…

zitadel | Remote | Cryptography
Feb 26, 2026 Mar 05, 2026
Feb 26, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2026-27837 — Dottie vulnerable to prototype pollution bypass via non-first path segments in set() and …

Dottie provides nested object access and manipulation in JavaScript. Versions 2.0.4 through 2.0.6 contain an incomplete fix for CVE-2023-26132. The prototype pollution guard introduced in commit `7d3…

dottie | Remote | Misconfiguration
Feb 26, 2026 Feb 28, 2026
Feb 26, 2026
Feb 28, 2026
7.5 HIGH
CVE-2026-27831 — rldns Vulnerable to Heap-based Out-of-Bounds Read

rldns is an open source DNS server. Version 1.3 has a heap-based out-of-bounds read that leads to denial of service. Version 1.4 contains a patch for the issue.

Remote | Memory Corruption
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
8.9 HIGH
CVE-2026-27830 — c3p0 vulnerable to Remote Code Execution via unsafe deserialization of userOverridesAsStr…

c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances. Several c3p0 `ConnectionPoolDataSource` implem…

| Injection
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
7.2 HIGH
CVE-2026-27829 — Astro is vulnerable to SSRF due to missing allowlist enforcement in remote image inferSize

Astro is a web framework. In versions 9.0.0 through 9.5.3, a bug in Astro's image pipeline allows bypassing `image.domains` / `image.remotePatterns` restrictions, enabling the server to fetch content…

\@astrojs\/node | Remote | Server-Side Request Forgery
Feb 26, 2026 Mar 09, 2026
Feb 26, 2026
Mar 09, 2026
8.8 HIGH
CVE-2026-27976 — Zed Extension Sandbox Escape via Tar Symlink Following

Zed, a code editor, has an extension installer allows tar/gzip downloads. Prior to version 0.224.4, the tar extractor (`async_tar::Archive::unpack`) creates symlinks from the archive without validati…

zed | Remote | Path Traversal
Feb 26, 2026 Mar 05, 2026
Feb 26, 2026
Mar 05, 2026
7.1 HIGH
CVE-2026-27967 — Symlink Escape in Agent File Tools

Zed, a code editor, has a symlink escape vulnerability in versions prior to 0.225.9 in Agent file tools (`read_file`, `edit_file`). It allows reading and writing files **outside the project directory…

zed | Path Traversal
Feb 26, 2026 Mar 05, 2026
Feb 26, 2026
Mar 05, 2026
6.8 MEDIUM
CVE-2026-27933 — Manyfold vulnerable to session hijack via cookie leakage in proxy caches

Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. Versions prior to 0.133.0 are vulnerable to session hijack via coo…

manyfold | Remote | Misconfiguration
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
7.7 HIGH
CVE-2026-27821 — GPAC NHML Demuxer (dmx_nhml.c) Vulnerable to Stack Buffer Overflow

GPAC is an open-source multimedia framework. In versions up to and including 26.02.0, a stack buffer overflow occurs during NHML file parsing in `src/filters/dmx_nhml.c`. The value of the xmlHeaderEn…

gpac | Remote | Memory Corruption
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
8.7 HIGH
CVE-2026-27818 — TerriaJS-Server has a domain validation bypass vulnerability in its proxy allowlist

TerriaJS-Server is a NodeJS Express server for TerriaJS, a library for building web-based geospatial data explorers. A validation bug in versions prior to 4.0.3 allows an attacker to proxy domains no…

terriajs-server | Remote | Misconfiguration
Feb 26, 2026 Mar 04, 2026
Feb 26, 2026
Mar 04, 2026
Showing 20 of 5237 Results