Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
2.7 LOW
CVE-2026-22866 — ENS DNSSEC Oracle Vulnerable to RSA Signature Forgery via Missing PKCS#1 v1.5 Padding Val…

Ethereum Name Service (ENS) is a distributed, open, and extensible naming system based on the Ethereum blockchain. In versions 1.6.2 and prior, the `RSASHA256Algorithm` and `RSASHA1Algorithm` contrac…

ethereum_name_service | Remote | Cryptography
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
9.6 CRITICAL
CVE-2025-69771 — Asbplayer File Upload Code Execution Vulnerability

An arbitrary file upload vulnerability in the subtitle loading function of asbplayer v1.13.0 allows attackers to execute arbitrary code via uploading a crafted subtitle file.

asbplayer | Remote | Misconfiguration
Feb 25, 2026 Mar 02, 2026
Feb 25, 2026
Mar 02, 2026
8.7 HIGH
CVE-2025-50180 — esm.sh is vulnerable to full-response SSRF

esm.sh is a no-build content delivery network (CDN) for web development. In version 136, esm.sh is vulnerable to a full-response SSRF, allowing an attacker to retrieve information from internal websi…

esm.sh | Remote | Server-Side Request Forgery
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
9.3 CRITICAL
CVE-2025-1242 — Administrative Credentials Can Be Extracted Through Gardyn API Responses

The administrative credentials can be extracted through application API responses, mobile application reverse engineering, and device firmware reverse engineering. The exposure may result in an attac…

Remote | Information Disclosure
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
7.5 HIGH
CVE-2026-3203 — Buffer Over-read in Wireshark

RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service

wireshark | Remote | Denial of Service
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
7.5 HIGH
CVE-2026-3202 — NULL Pointer Dereference in Wireshark

NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service

wireshark | Remote | Denial of Service
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
7.5 HIGH
CVE-2026-3201 — Improperly Controlled Sequential Memory Allocation in Wireshark

USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service

wireshark | Remote | Denial of Service
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-3187 — feiyuchuixue sz-boot-parent API Endpoint upload unrestricted upload

A vulnerability was identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this issue is some unknown functionality of the file /api/admin/sys-file/upload of the component API Endpoi…

sz-boot-parent | Remote | Misconfiguration
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
5.9 MEDIUM
CVE-2026-2878 — Insufficient Entropy Vulnerability in Telerik UI for ASP.NET AJAX

In Progress® Telerik® UI for AJAX, versions prior to 2026.1.225, an insufficient entropy vulnerability exists in RadAsyncUpload, where a predictable temporary identifier, based on timestamp and filen…

telerik_ui_for_asp.net_ajax | Remote | Cryptography
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-27699 — Basic FTP has Path Traversal Vulnerability in its downloadToDir() method

The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()` method. A malicious FTP server can send directory l…

basic-ftp | Remote | Path Traversal
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
5.3 MEDIUM
CVE-2026-27695 — zae-limiter: DynamoDB hot partition throttling enables per-entity Denial of Service

zae-limiter is a rate limiting library using the token bucket algorithm. Prior to version 0.10.1, all rate limit buckets for a single entity share the same DynamoDB partition key (`namespace/ENTITY#{…

zae-limiter | Remote | Denial of Service
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
7.1 HIGH
CVE-2026-27692 — iccDEV has HBO in CIccTagTextDescription::Release()

iccDEV provides a set of libraries and tools for working with ICC color management profiles. In versions up to and including 2.3.1.4, heap-buffer-overflow read occurs during CIccTagTextDescription::R…

iccdev | Memory Corruption
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
6.2 MEDIUM
CVE-2026-27691 — iccDEV has SIO in parse3DTable() at iccFromCube.cpp Line 218

iccDEV provides a set of libraries and tools for working with ICC color management profiles. In versions up to and including 2.3.1.4, signed integer overflow in iccFromCube.cpp during multiplication …

iccdev | Memory Corruption
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
6.5 MEDIUM
CVE-2026-3186 — feiyuchuixue sz-boot-parent Password Reset password default password

A vulnerability was determined in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this vulnerability is an unknown functionality of the file /api/admin/sys-user/reset/password/ of the compo…

sz-boot-parent | Remote | Authorization
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
5.5 MEDIUM
CVE-2026-3185 — feiyuchuixue sz-boot-parent API Endpoint sys-message authorization

A vulnerability was found in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected is an unknown function of the file /api/admin/sys-message/ of the component API Endpoint. The manipulation of the a…

sz-boot-parent | Remote | Authorization
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
2.3 LOW
CVE-2026-28196 — JetBrains TeamCity Unsecured Credentials Disclosure

In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk

teamcity | Information Disclosure
Feb 25, 2026 Feb 25, 2026
Feb 25, 2026
Feb 25, 2026
4.3 MEDIUM
CVE-2026-28195 — JetBrains TeamCity Unauthenticated Build Configuration Parameter Injection

In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations

teamcity | Remote | Authorization
Feb 25, 2026 Feb 25, 2026
Feb 25, 2026
Feb 25, 2026
6.1 MEDIUM
CVE-2026-28194 — JetBrains TeamCity Open Redirect Vulnerability

In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow

teamcity | Remote | Misconfiguration
Feb 25, 2026 Feb 25, 2026
Feb 25, 2026
Feb 25, 2026
8.8 HIGH
CVE-2026-28193 — JetBrains YouTrack Unvalidated Request Vulnerability

In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint

youtrack | Remote | Server-Side Request Forgery
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-2624 — Authentication Bypass in ePati's Antikor NGFW

Missing Authentication for Critical Function vulnerability in ePati Cyber ​​Security Technologies Inc. Antikor Next Generation Firewall (NGFW) allows Authentication Bypass.This issue affects Antikor …

antikor_next_generation_firewall | Remote | Authentication
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
Showing 20 of 5385 Results