Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.2 HIGH
CVE-2026-27627 — Karakeep's Reddit plugin content bypasses DOMPurify sanitization, enabling stored XSS

Karakeep is a elf-hostable bookmark-everything app. In version 0.30.0, when the Reddit metascraper plugin returns `readableContentHtml`, the HTML parsing subprocess uses it directly without running i…

karakeep | Remote | Cross-Site Scripting
Feb 25, 2026 Mar 10, 2026
Feb 25, 2026
Mar 10, 2026
10.0 CRITICAL
CVE-2026-27597 — @enclave-vm/core is vulnerable to Sandbox Escape

Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to version 2.11.1, it is possible to escape the security boundraries set by `@enclave-vm/core`, which can be us…

enclave | Remote | Misconfiguration
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
5.5 MEDIUM
CVE-2026-3146 — libvips matrixload.c vips_foreign_load_matrix_header null pointer dereference

A vulnerability has been found in libvips up to 8.18.0. The impacted element is the function vips_foreign_load_matrix_header of the file libvips/foreign/matrixload.c. The manipulation leads to null p…

libvips | Memory Corruption
Feb 25, 2026 Feb 25, 2026
Feb 25, 2026
Feb 25, 2026
7.8 HIGH
CVE-2026-3145 — libvips matrixload.c vips_foreign_load_matrix_header memory corruption

A flaw has been found in libvips up to 8.18.0. The affected element is the function vips_foreign_load_matrix_file_is_a/vips_foreign_load_matrix_header of the file libvips/foreign/matrixload.c. Execut…

libvips | Memory Corruption
Feb 25, 2026 Feb 25, 2026
Feb 25, 2026
Feb 25, 2026
9.0 CRITICAL
CVE-2026-27822 — Rust has Critical Stored XSS in Preview Modal, leading to Administrative Account Takeover

RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.83, a Stored Cross-Site Scripting (XSS) vulnerability in the RustFS Console allows an attacker to execute arb…

rustfs | Remote | Cross-Site Scripting
Feb 25, 2026 Feb 25, 2026
Feb 25, 2026
Feb 25, 2026
3.1 LOW
CVE-2026-27632 — Talishar Vulnerable to Cross-Site Request Forgery (CSRF)

Talishar is a fan-made Flesh and Blood project. Prior to commit 6be3871a14c192d1fb8146cdbc76f29f27c1cf48, the Talishar application lacks Cross-Site Request Forgery (CSRF) protections on critical stat…

talishar | Remote | Cross-Site Request Forgery
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
8.8 HIGH
CVE-2026-27629 — InvenTree Vulnerable to Server Side Template Injection (SSTI)

InvenTree is an Open Source Inventory Management System. Prior to version 1.2.3, insecure server-side templates can be hijacked to expose secure information to the client. When generating custom batc…

inventree | Remote | Information Disclosure
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
7.5 HIGH
CVE-2026-27628 — pypdf has a possible infinite loop when loading circular /Prev entries in cross-reference…

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.2, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires reading the file. This …

pypdf | Remote | Denial of Service
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
9.9 CRITICAL
CVE-2026-27626 — OliveTin vulnerable to OS Command Injection via `password` argument type and webhook JSON…

OliveTin gives access to predefined shell commands from a web interface. In versions up to and including 3000.10.0, OliveTin's shell mode safety check (`checkShellArgumentSafety`) blocks several dang…

olivetin | Remote | Injection
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
6.8 MEDIUM
CVE-2026-27621 — TypiCMS Core has Stored Cross-Site Scripting (XSS) via SVG File Upload

TypiCMS is a multilingual content management system based on the Laravel framework. A Stored Cross-Site Scripting (XSS) vulnerability exists in the file upload module of TypiCMS prior to version 16.1…

typicms | Remote | Cross-Site Scripting
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
8.8 HIGH
CVE-2026-27615 — ADB-Explorer: UNC Path Support in ManualAdbPath Leads to Remote Code Execution (RCE)

ADB Explorer is a fluent UI for ADB on Windows. In versions prior to Beta 0.9.26022, ADB-Explorer allows the `ManualAdbPath` settings variable, which determines the path of the ADB binary to be execu…

adb_explorer | Misconfiguration
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
9.3 CRITICAL
CVE-2026-27614 — Bugsink is vulnerable to Stored XSS via Pygments fallback in stacktrace rendering

Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.13, an unauthenticated attacker who can submit events to a Bugsink project can store arbitrary JavaScript in an event. The paylo…

bugsink | Remote | Cross-Site Scripting
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
6.1 MEDIUM
CVE-2026-27612 — Repostat Vulnerable to Reflected Cross-Site Scripting (XSS) via repo prop in RepoCard

Repostat is a React component to fetch and display GitHub repository info. Prior to version 1.0.1, the `RepoCard` component is vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability oc…

repostat | Remote | Cross-Site Scripting
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
7.1 HIGH
CVE-2026-27611 — FileBrowser Quantum: Password Protection Not Enforced on Shared File Links

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to versions 1.1.3-stable and 1.2.6-beta, when users share password-protected files, the recipient can completely bypass the p…

filebrowser_quantum | Remote | Authentication
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
7.0 HIGH
CVE-2026-27610 — Parse Dashboard Has a Cache Key Collision that Leaks Master Key to Read-Only Sessions

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the `ConfigKeyCache` uses the same cache key for both master key and read-o…

parse_dashboard | Remote | Misconfiguration
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
8.3 HIGH
CVE-2026-27609 — Parse Dashboard Missing CSRF Protection on Agent Endpoint

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint (`POST /apps/:appId/agent`) lacks CSRF protection…

parse_dashboard | Remote | Cross-Site Request Forgery
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
9.3 CRITICAL
CVE-2026-27608 — Parse Dashboard Missing Authorization on Agent Endpoint

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint (`POST /apps/:appId/agent`) does not enforce auth…

parse_dashboard | Remote | Authorization
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
9.1 CRITICAL
CVE-2026-27607 — RustFS's Missing Post Policy Validation leads to Arbitrary Object Write

RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.56 through 1.0.0-alpha.82, RustFS does not validate policy conditions in presigned POST uploads (PostObject), allo…

rustfs | Remote | Misconfiguration
Feb 25, 2026 Feb 25, 2026
Feb 25, 2026
Feb 25, 2026
9.8 CRITICAL
CVE-2026-27606 — Rollup 4 has Arbitrary File Write via Path Traversal

Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present in current source) is vulnerable to an Arbitrary Fi…

rollup | Remote | Path Traversal
Feb 25, 2026 Feb 25, 2026
Feb 25, 2026
Feb 25, 2026
9.9 CRITICAL
CVE-2026-27595 — Parse Dashboard has incomplete authentication on AI Agent endpoint

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint (POST `/apps/:appId/agent`) has multiple security…

parse_dashboard | Remote | Authentication
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
Showing 20 of 5328 Results