Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-2694 — The Events Calendar <= 6.15.16 - Improper Authorization to Authenticated (Contributor+) E…

The The Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to an improper capability check on the 'can_edit' and 'can_delete' function in all…

Remote | Authorization
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
7.5 HIGH
CVE-2026-27951 — FreeRDP has possible Integer overflow in Stream_EnsureCapacity

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, the function `Stream_EnsureCapacity` can create an endless blocking loop. This may affect all client and serv…

freerdp | Remote | Denial of Service
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
7.5 HIGH
CVE-2026-27950 — FreeRDP heap-use-after-free in update_pointer_new(SDL): Fix Applied in the Wrong File

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, the fix for the heap-use-after-free described in CVE-2026-24680 is incomplete. While the vulnerable execution…

freerdp | Remote | Memory Corruption
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
7.2 HIGH
CVE-2026-27819 — Vikunja has Path Traversal in CLI Restore

Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the restoreConfig function in vikunja/pkg/modules/dump/restore.go of the go-vikunja/vikunja repository fails to…

vikunja | Remote | Path Traversal
Feb 25, 2026 Mar 05, 2026
Feb 25, 2026
Mar 05, 2026
7.3 HIGH
CVE-2026-27616 — Vikunja Vulnerable to Stored Cross-Site Scripting (XSS) via Unsanitized SVG Attachment Up…

Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to upload SVG files as task attachments. SVG is an XML-based format that supports …

vikunja | Remote | Cross-Site Scripting
Feb 25, 2026 Mar 05, 2026
Feb 25, 2026
Mar 05, 2026
9.1 CRITICAL
CVE-2026-27575 — Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change

Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to set weak passwords (e.g., 1234, password) without enforcing minimum strength re…

vikunja | Remote | Authentication
Feb 25, 2026 Mar 05, 2026
Feb 25, 2026
Mar 05, 2026
9.6 CRITICAL
CVE-2026-27148 — Storybook Dev Server Vulnerable to WebSocket Hijacking

Storybook is a frontend workshop for building user interface components and pages in isolation. Prior to versions 7.6.23, 8.6.17, 9.1.19, and 10.2.10, the WebSocket functionality in Storybook's dev s…

storybook | Remote | Cross-Site Scripting
Feb 25, 2026 Mar 10, 2026
Feb 25, 2026
Mar 10, 2026
6.1 MEDIUM
CVE-2026-27116 — Vikunja has Reflected HTML Injection via filter Parameter in Projects Module

Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, a reflected HTML injection vulnerability exists in the Projects module where the `filter` URL parameter is rend…

vikunja | Remote | Cross-Site Scripting
Feb 25, 2026 Mar 05, 2026
Feb 25, 2026
Mar 05, 2026
7.5 HIGH
CVE-2026-26986 — FreeRDP has heap-use-after-free in rail_window_free

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `rail_window_free` dereferences a freed `xfAppWindow` pointer during `HashTable_Free` cleanup because `xf_rai…

freerdp | Remote | Memory Corruption
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
8.1 HIGH
CVE-2026-26985 — LORIS vulnerable to path traversal in electrophysiology_browser

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Starting in version 24.0.0 and prior to …

loris | Remote | Path Traversal
Feb 25, 2026 Mar 05, 2026
Feb 25, 2026
Mar 05, 2026
8.8 HIGH
CVE-2026-26984 — LORIS media module vulnerable to remote code execution

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Prior to versions 26.0.5, 27.0.2, and 28…

loris | Remote | Path Traversal
Feb 25, 2026 Mar 05, 2026
Feb 25, 2026
Mar 05, 2026
Showing 20 of 6111 Results