Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-3289 — Sanluan PublicCMS Template Cache Generation TemplateCacheComponent.java saveMetadata path…

A weakness has been identified in Sanluan PublicCMS 6.202506.d. This impacts the function saveMetadata of the file TemplateCacheComponent.java of the component Template Cache Generation. Executing a …

publiccms | Remote | Path Traversal
Feb 27, 2026 Mar 02, 2026
Feb 27, 2026
Mar 02, 2026
9.8 CRITICAL
CVE-2026-3287 — youlaitech youlai-mall App-side Product Pagination Endpoint SpuController.java listPagedS…

A security flaw has been discovered in youlaitech youlai-mall 2.0.0. This affects the function listPagedSpuForApp of the file mall-pms/pms-boot/src/main/java/com/youlai/mall/pms/controller/app/SpuCon…

youlai-mall | Remote | Injection
Feb 27, 2026 Mar 02, 2026
Feb 27, 2026
Mar 02, 2026
9.1 CRITICAL
CVE-2026-28370 — OpenStack Vitrage Code Execution Vulnerability

In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger code execution on the Vitrage service host as the user the Vit…

vitrage | Remote | Injection
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
5.3 MEDIUM
CVE-2026-1558 — WP Recipe Maker <= 10.3.2 - Insecure Direct Object Reference to Unauthenticated Arbitrary…

The WP Recipe Maker plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) in versions up to, and including, 10.3.2. This is due to the /wp-json/wp-recipe-maker/v1/integrati…

wp_recipe_maker | Remote | Authorization
Feb 27, 2026 Feb 27, 2026
Feb 27, 2026
Feb 27, 2026
7.8 HIGH
CVE-2026-1442 — Unitree UPK files Hard-Coded Key

Since the encryption algorithm used to protect firmware updates is itself encrypted using key material available to an attacker (or anyone paying attention), the firmware updates may be altered by an…

Feb 27, 2026 Mar 11, 2026
Feb 27, 2026
Mar 11, 2026
6.5 MEDIUM
CVE-2026-3286 — itwanger paicoding Image Save Endpoint ImageRestController.java save server-side request …

A vulnerability was identified in itwanger paicoding 1.0.0/1.0.1/1.0.2/1.0.3. The impacted element is the function Save of the file paicoding-web/src/main/java/com/github/paicoding/forum/web/common/i…

paicoding | Remote | Server-Side Request Forgery
Feb 27, 2026 Mar 02, 2026
Feb 27, 2026
Mar 02, 2026
7.5 HIGH
CVE-2026-2428 — Fluent Forms Pro Add On Pack <= 6.1.17 - Missing Authorization to Unauthenticated Payment…

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 6.1.17. This is due to the PayPal IPN (Inst…

Remote | Authentication
Feb 27, 2026 Feb 27, 2026
Feb 27, 2026
Feb 27, 2026
7.9 HIGH
CVE-2026-28364 — OCaml Marshal Deserialization Buffer Over-Read Remote Code Execution

In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems…

ocaml | Memory Corruption
Feb 27, 2026 Mar 06, 2026
Feb 27, 2026
Mar 06, 2026
9.9 CRITICAL
CVE-2026-28363 — OpenClaw Safe Bin Validation Bypass Vulnerability

In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviations (such as --compress-prog) in allowlist mode, leading to approval-free executi…

openclaw | Remote | Authorization
Feb 27, 2026 Feb 27, 2026
Feb 27, 2026
Feb 27, 2026
Showing 20 of 5949 Results