Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.1 HIGH
CVE-2026-2460 — REB500 Directory Access Control Protocol Privilege Escalation Vulnerability

A vulnerability exists in REB500 for an authenticated user with low-level privileges to access and alter the content of directories by using the DAC protocol that the user is not authorized to do so.

reb500_firmware reb500 | Remote | Authorization
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
8.1 HIGH
CVE-2026-2459 — "REB500 Directory Traversal Vulnerability"

A vulnerability exists in REB500 for an authenticated user with Installer role to access and alter the contents of directories that the role is not authorized to do so.

reb500_firmware reb500 | Remote | Authorization
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
7.1 HIGH
CVE-2026-23984 — Apache Superset: SQLLab Read-Only Bypass on PostgreSQL

An Improper Input Validation vulnerability exists in Apache Superset that allows an authenticated user with SQLLab access to bypass the read-only verification check when using a PostgreSQL database c…

superset | Remote | Injection
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
6.5 MEDIUM
CVE-2026-23983 — Apache Superset: Sensitive Data Exposure via REST API (disabled by default)

A Sensitive Data Exposure vulnerability exists in Apache Superset allowing authenticated users to retrieve sensitive user information. The Tag endpoint (disabled by default) allows users to retrieve …

superset | Remote | Information Disclosure
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
7.1 HIGH
CVE-2026-23982 — Apache Superset: Improper Authorization in Dataset Creation Allows Access Control Bypass

An Improper Authorization vulnerability exists in Apache Superset that allows a low-privileged user to bypass data access controls. When creating a dataset, Superset enforces permission checks to pre…

superset | Remote | Authorization
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
6.5 MEDIUM
CVE-2026-23980 — Apache Superset: Improper Neutralization of Special Elements used in a SQL Command

Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user with read access to conduct error-based SQL injection…

superset | Remote | Injection
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
6.5 MEDIUM
CVE-2026-23969 — Apache Superset: Exposure of Sensitive Information via Incomplete ClickHouse Function Fil…

Apache Superset utilizes a configurable dictionary, DISALLOWED_SQL_FUNCTIONS, to restrict the execution of potentially sensitive SQL functions within SQL Lab and charts. While this feature included r…

superset | Remote | Injection
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
8.7 HIGH
CVE-2026-1773 — IEC 60870-5-104 Denial of Service

IEC 60870-5-104: Potential Denial of Service impact on reception of invalid U-format frame. Product is only affected if IEC 60870-5-104 bi-directional functionality is configured. Enabling secure com…

Feb 24, 2026 Feb 27, 2026
Feb 24, 2026
Feb 27, 2026
5.3 MEDIUM
CVE-2026-1772 — RTU500 Web Interface Information Disclosure

RTU500 web interface: An unprivileged user can read user management information. The information cannot be accessed via the RTU500 web user interface but requires further tools like browser developme…

rtu520_firmware rtu530_firmware rtu540_firmware rtu560_firmware rtu520 rtu530 +2 more | Remote | Information Disclosure
Feb 24, 2026 Feb 27, 2026
Feb 24, 2026
Feb 27, 2026
9.8 CRITICAL
CVE-2025-14577 — PHP Function Injection in Slican NPC/IPL/IPM/IPU

Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to execute arbitrary PHP commands by sending specially crafted requests to /webcti/…

Feb 24, 2026 Mar 02, 2026
Feb 24, 2026
Mar 02, 2026
7.8 HIGH
CVE-2026-2664 — Out of bounds read vulnerability in grpcfuse kernel module

An out of bounds read vulnerability in the grpcfuse kernel module present in the Linux VM in Docker Desktop for Windows, Linux and macOS up to version 4.61.0 could allow a local attacker to cause an …

desktop | Memory Corruption
Feb 24, 2026 Feb 27, 2026
Feb 24, 2026
Feb 27, 2026
6.5 MEDIUM
CVE-2025-27555 — Apache Airflow: Connection Secrets not masked in UI when Connection are added via Airflow…

Airflow versions before 2.11.1 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which they should not see. When sensitive connection pa…

airflow | Remote | Information Disclosure
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
8.4 HIGH
CVE-2024-56373 — Apache Airflow: SSTI to Code Execution in Airflow through Shared DB Information

DAG Author (who already has quite a lot of permissions) could manipulate database of Airflow 2 in the way to execute arbitrary code in the web-server context, which they should normally not be able t…

airflow | Remote | Authorization
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
9.9 CRITICAL
CVE-2025-11165 — DotCMS Velocity Sandbox Escape Vulnerability

A sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users with scripting privileges to bypass class and package restrictions enforced by Sec…

dotcms | Remote | Injection
Feb 24, 2026 Mar 03, 2026
Feb 24, 2026
Mar 03, 2026
8.1 HIGH
CVE-2024-1524 — A local user can be impersonated when using federated authentication with Silent JIT Prov…

When the "Silent Just-In-Time Provisioning" feature is enabled for a federated identity provider (IDP) there is a risk that a local user store user's information may be replaced during the account p…

Feb 24, 2026 Mar 03, 2026
Feb 24, 2026
Mar 03, 2026
9.8 CRITICAL
CVE-2026-1229 — Incorrect calculation in CIRCL secp384r1 CombinedMult

The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas. ECDH and ECDSA signi…

circl | Remote | Cryptography
Feb 24, 2026 Mar 03, 2026
Feb 24, 2026
Mar 03, 2026
9.1 CRITICAL
CVE-2025-40541 — SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Remote Code Execution Vulnerabi…

An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor the ability to execute native code as a privileged account. This issue requir…

serv-u | Remote | Authorization
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
9.1 CRITICAL
CVE-2025-40540 — SolarWinds Serv-U Type Confusion Remote Code Execution Vulnerability

A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative p…

serv-u | Remote | Memory Corruption
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
9.1 CRITICAL
CVE-2025-40539 — SolarWinds Serv-U Type Confusion Remote Code Execution Vulnerability

A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative p…

serv-u | Remote | Memory Corruption
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
9.1 CRITICAL
CVE-2025-40538 — SolarWinds Serv-U Broken Access Control Remote Code Execution Vulnerability

A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to create a system admin user and execute arbitrary code as a privileged account via d…

serv-u | Remote | Authorization
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
Showing 20 of 5272 Results