Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-2979 — FastApiAdmin Scheduled Task API controller.py user_avatar_upload_controller unrestricted …

A flaw has been found in FastApiAdmin up to 2.2.0. This issue affects the function user_avatar_upload_controller of the file /backend/app/api/v1/module_system/user/controller.py of the component Sche…

fastapi-admin fastapiadmin | Remote | Misconfiguration
Feb 23, 2026 Mar 05, 2026
Feb 23, 2026
Mar 05, 2026
4.0 MEDIUM
CVE-2026-26365 — Akamai CDN HTTP Request Smuggling Vulnerability

Akamai Ghost on Akamai CDN edge servers before 2026-02-06 mishandles processing of custom hop-by-hop HTTP headers, where an incoming request containing the header "Connection: Transfer-Encoding" coul…

Remote | Injection
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
8.8 HIGH
CVE-2026-25747 — Apache Camel: Deserialization of Untrusted Data in Camel LevelDB

Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes data read from the LevelDB aggregation repository usi…

camel | Remote | Authentication
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
9.1 CRITICAL
CVE-2026-23552 — Apache Camel: Camel-Keycloak: Cross-Realm Token Acceptance Bypass in KeycloakSecurityPoli…

Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component.  The Camel-Keycloak KeycloakSecurityPolicy does not validate the iss (issuer) claim of JWT tokens again…

camel | Remote | Authentication
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
8.8 HIGH
CVE-2026-2978 — FastApiAdmin Scheduled Task API controller.py upload_file_controller unrestricted upload

A vulnerability was detected in FastApiAdmin up to 2.2.0. This vulnerability affects the function upload_file_controller of the file /backend/app/api/v1/module_system/params/controller.py of the comp…

fastapi-admin fastapiadmin | Remote | Misconfiguration
Feb 23, 2026 Mar 05, 2026
Feb 23, 2026
Mar 05, 2026
8.8 HIGH
CVE-2026-2977 — FastApiAdmin Scheduled Task API controller.py upload_controller unrestricted upload

A security vulnerability has been detected in FastApiAdmin up to 2.2.0. This affects the function upload_controller of the file /backend/app/api/v1/module_common/file/controller.py of the component S…

fastapi-admin fastapiadmin | Remote | Misconfiguration
Feb 23, 2026 Mar 05, 2026
Feb 23, 2026
Mar 05, 2026
8.3 HIGH
CVE-2026-1367 — SQL Injection

Zohocorp ManageEngine ADSelfService Plus versions 6522 and below are vulnerable to authenticated SQL Injection in the search report option.

manageengine_adselfservice_plus | Remote | Injection
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
Showing 20 of 5587 Results