Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-20139 — Client-Side Denial of Service (DoS) through ''/splunkd/__raw/services/authentication/user…

In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.8, 9.3.9, and 9.2.12, and Splunk Cloud Platform versions below 10.2.2510.3, 10.1.2507.8, 10.0.2503.9, and 9.3.2411.121, a low-privileged user t…

splunk splunk_cloud_platform | Denial of Service
Feb 18, 2026 Feb 20, 2026
Feb 18, 2026
Feb 20, 2026
6.8 MEDIUM
CVE-2026-20138 — Sensitive Information Disclosure in "_internal" index in Splunk Enterprise

In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.9, and 9.2.11, a user of a Splunk Search Head Cluster (SHC) deployment who holds a role with access to the Splunk `_internal` index coul…

splunk | Information Disclosure
Feb 18, 2026 Feb 20, 2026
Feb 18, 2026
Feb 20, 2026
5.7 MEDIUM
CVE-2026-20137 — Risky Commands Safeguards Bypass through preloaded Data Models due to Path Traversal vuln…

In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.5, 9.3.7, and 9.2.9, and Splunk Cloud Platform versions below 10.1.2507.0, 10.0.2503.9, 9.3.2411.112, and 9.3.2408.122, a low-privileged user w…

splunk splunk_cloud_platform | Remote | Injection
Feb 18, 2026 Feb 20, 2026
Feb 18, 2026
Feb 20, 2026
9.8 CRITICAL
CVE-2025-70152 — Code-Projects Community Project Scholars Tracking System SQL Injection Vulnerability

code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php. These endpoints lac…

scholars_tracking_system | Remote | Injection
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
8.8 HIGH
CVE-2025-70151 — Code-Projects Scholars Tracking System Remote Code Execution Vulnerability

code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload. The endpoints update_profile_picture.php and upload_picture.…

scholars_tracking_system | Remote | Authentication
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
9.8 CRITICAL
CVE-2025-70150 — CodeAstro Membership Management System Unauthenticated Delete Member Vulnerability

CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id pa…

membership_management_system | Remote | Authentication
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
7.5 HIGH
CVE-2025-70148 — CodeAstro Membership Management System IDOR

Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users …

membership_management_system | Remote | Authentication
Feb 18, 2026 Feb 20, 2026
Feb 18, 2026
Feb 20, 2026
10.0 CRITICAL
CVE-2025-14009 — Zip Slip Vulnerability in nltk/nltk Leading to Remote Code Execution

A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py uses zipfile.extractall() without performing path…

nltk | Remote | Path Traversal
Feb 18, 2026 Mar 06, 2026
Feb 18, 2026
Mar 06, 2026
Showing 20 of 5708 Results