Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.1 HIGH
CVE-2026-27206 — Zumba Json Serializer has a potential PHP Object Injection via Unrestricted @type in unse…

Zumba Json Serializer is a library to serialize PHP variables in JSON format. In versions 3.2.2 and below, the library allows deserialization of PHP objects from JSON using a special @type field. The…

Remote | Information Disclosure
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
5.5 MEDIUM
CVE-2026-2863 — feng_ha_ha/megagao ssm-erp/production_ssm FileServiceImpl.java deleteFile path traversal

A flaw has been found in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07bdd097. The impacted element is the function deleteFile of the file FileServiceImpl.java…

Remote | Path Traversal
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
5.5 MEDIUM
CVE-2026-2861 — Foswiki Changes/Viewfile/Oops information disclosure

A vulnerability was detected in Foswiki up to 2.1.10. The affected element is an unknown function of the component Changes/Viewfile/Oops. The manipulation results in information disclosure. It is pos…

foswiki | Remote | Information Disclosure
Feb 21, 2026 Feb 26, 2026
Feb 21, 2026
Feb 26, 2026
9.4 CRITICAL
CVE-2026-27212 — Swiper has a Prototype Pollution Vulnerability

Swiper is a free and mobile touch slider with hardware accelerated transitions and native behavior. Versions 6.5.1 through 12.1.1 have a Prototype pollution vulnerability. The vulnerability resides i…

swiper | Misconfiguration
Feb 21, 2026 Feb 24, 2026
Feb 21, 2026
Feb 24, 2026
10.0 CRITICAL
CVE-2026-27211 — Cloud Hypervisor: Host File Exfiltration via QCOW Backing File Abuse

Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. Versions 34.0 through 50.0 arevulnerable to arbitrary host file exfiltration (constrained by process privileges) when using virtio-b…

cloud_hypervisor | Remote | Path Traversal
Feb 21, 2026 Feb 24, 2026
Feb 21, 2026
Feb 24, 2026
6.1 MEDIUM
CVE-2026-27210 — Pannellum has a XSS vulnerability in hot spot attributes

Pannellum is a lightweight, free, and open source panorama viewer for the web. In versions 3.5.0 through 2.5.6, the hot spot attributes configuration property allowed any attribute to be set, includi…

pannellum | Remote | Cross-Site Scripting
Feb 21, 2026 Mar 02, 2026
Feb 21, 2026
Mar 02, 2026
4.3 MEDIUM
CVE-2026-27205 — Flask session does not add `Vary: Cookie` header when accessed in some ways

Flask is a web server gateway interface (WSGI) web application framework. In versions 3.1.2 and below, when the session object is accessed, Flask should set the Vary: Cookie header., resulting in a U…

flask | Remote | Misconfiguration
Feb 21, 2026 Feb 24, 2026
Feb 21, 2026
Feb 24, 2026
6.3 MEDIUM
CVE-2026-27199 — Werkzeug safe_join() allows Windows special device names

Werkzeug is a comprehensive WSGI web application library. Versions 3.1.5 and below, the safe_join function allows Windows device names as filenames if preceded by other path segments. This was previo…

werkzeug | Remote | Path Traversal
Feb 21, 2026 Mar 03, 2026
Feb 21, 2026
Mar 03, 2026
8.8 HIGH
CVE-2026-27198 — Formwork Improperly Manages Privileges During User Creation

Formwork is a flat file-based Content Management System (CMS). In versions 2.0.0 through 2.3.3, the application fails to properly enforce role-based authorization during account creation. Although th…

formwork | Remote | Authorization
Feb 21, 2026 Mar 03, 2026
Feb 21, 2026
Mar 03, 2026
6.5 MEDIUM
CVE-2026-26047 — Moodle: moodle: uncontrolled resource consumption in tex formula editor leading to denial…

A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimetex, insufficient execution time limits could allow specially crafted formulas to…

moodle | Remote | Denial of Service
Feb 21, 2026 Feb 26, 2026
Feb 21, 2026
Feb 26, 2026
7.2 HIGH
CVE-2026-26046 — Moodle: moodle: improper input sanitization in tex filter administration setting

A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled …

moodle | Remote | Injection
Feb 21, 2026 Feb 26, 2026
Feb 21, 2026
Feb 26, 2026
7.2 HIGH
CVE-2026-26045 — Moodle: moodle: improper validation in file restore functionality leading to remote code …

A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lea…

moodle | Remote | Injection
Feb 21, 2026 Feb 26, 2026
Feb 21, 2026
Feb 26, 2026
6.5 MEDIUM
CVE-2026-2860 — feng_ha_ha/megagao ssm-erp/production_ssm EmployeeController.java improper authorization

A security vulnerability has been detected in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07bdd097. Impacted is an unknown function of the file EmployeeControl…

Remote | Authorization
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
9.1 CRITICAL
CVE-2026-27197 — Sentry: Improper Authentication on SAML SSO process allows user identity linking

Sentry is a developer-first error tracking and performance monitoring tool. Versions 21.12.0 through 26.1.0 have a critical vulnerability in its SAML SSO implementation which allows an attacker to t…

sentry | Remote | Authentication
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
8.1 HIGH
CVE-2026-27196 — Statamic affected by privilege escalation via stored Cross-site Scripting

Statmatic is a Laravel and Git powered content management system (CMS). Versions 5.73.8 and below in addition to 6.0.0-alpha.1 through 6.3.1 have a Stored XSS vulnerability in html fieldtypes which a…

statamic | Remote | Cross-Site Scripting
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
9.8 CRITICAL
CVE-2026-27194 — D-Tale affected by Remote Code Execution through the /save-column-filter endpoint

D-Tale is a visualizer for pandas data structures. Versions prior to 3.20.0 are vulnerable to Remote Code Execution through the /save-column-filter endpoint. Users hosting D-Tale publicly can be vuln…

d-tale | Remote | Injection
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
8.2 HIGH
CVE-2026-27193 — Feathers exposes internal headers via unencrypted session cookie

Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In versions 5.0.39 and below, all HTTP request headers are stored in the session cookie, whic…

feathers | Remote | Information Disclosure
Feb 21, 2026 Feb 25, 2026
Feb 21, 2026
Feb 25, 2026
8.1 HIGH
CVE-2026-27192 — Feathers has an origin validation bypass via prefix matching

Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In versions 5.0.39 and below, origin validation uses startsWith() for comparison, allowing at…

feathers | Remote | Misconfiguration
Feb 21, 2026 Feb 25, 2026
Feb 21, 2026
Feb 25, 2026
7.4 HIGH
CVE-2026-27191 — Feathers: Open Redirect in OAuth callback enables account takeover

Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. Versions 5.0.39 and below the redirect query parameter is appended to the base origin without…

feathers | Remote | Authentication
Feb 21, 2026 Feb 25, 2026
Feb 21, 2026
Feb 25, 2026
6.5 MEDIUM
CVE-2025-65995 — Apache Airflow: Disclosure of secrets to UI via kwargs

When a DAG failed during parsing, Airflow’s error-reporting in the UI could include the full kwargs passed to the operators. If those kwargs contained sensitive values (such as secrets), they might b…

airflow | Remote | Information Disclosure
Feb 21, 2026 Feb 25, 2026
Feb 21, 2026
Feb 25, 2026
Showing 20 of 5388 Results