Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.5 MEDIUM
CVE-2026-28288 — Dify has a user enumeration issue

Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-existent accounts differ, allowing an attacker to enumerate email addresses regist…

dify | Remote | Information Disclosure
Feb 27, 2026 Mar 09, 2026
Feb 27, 2026
Mar 09, 2026
8.1 HIGH
CVE-2026-28272 — Kiteworks Email Protection Gateway has a Cross-site Scripting vulnerability

Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks Email Protection Gateway allows authenticated administrators to inject malicious scripts through a conf…

kiteworks | Remote | Cross-Site Scripting
Feb 27, 2026 Mar 04, 2026
Feb 27, 2026
Mar 04, 2026
6.5 MEDIUM
CVE-2026-28271 — Kiteworks Core is vulnerable to Server-Side Request Forgery (SSRF)

Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration functionality allows bypassing of SSRF protections through DNS rebinding attacks. Malicio…

kiteworks | Remote | Server-Side Request Forgery
Feb 27, 2026 Mar 04, 2026
Feb 27, 2026
Mar 04, 2026
7.2 HIGH
CVE-2026-28270 — Kiteworks Core has an Unrestricted Upload of File with Dangerous Type

Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration allows uploading of arbitrary files without proper validation. Malicious administrators c…

kiteworks | Remote | Misconfiguration
Feb 27, 2026 Mar 04, 2026
Feb 27, 2026
Mar 04, 2026
9.8 CRITICAL
CVE-2026-28268 — Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse

Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerability exists in the password reset mechanism of vikunja/api that allows password …

vikunja | Remote | Authentication
Feb 27, 2026 Mar 06, 2026
Feb 27, 2026
Mar 06, 2026
6.5 MEDIUM
CVE-2018-25160 — HTTP::Session2 versions through 1.09 for Perl does not validate the format of user provid…

HTTP::Session2 versions through 1.09 for Perl does not validate the format of user provided session ids, enabling code injection or other impact depending on session backend. For example, if an appl…

http\ | Remote | Injection
Feb 27, 2026 Mar 18, 2026
Feb 27, 2026
Mar 18, 2026
Showing 20 of 5886 Results