Latest CVE Feed
-
1.3
LOWCVE-2026-27465
Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fleet’s configuration API could expose Google Calendar service account credentials to authenticated users with low-privilege roles. This may allow unauthorize... Read more
Affected Products :- Published: Feb. 26, 2026
- Modified: Feb. 26, 2026
- Vuln Type: Information Disclosure
-
1.2
LOWCVE-2026-25963
Fleet is open source device management software. In versions prior to 4.80.1, a broken authorization check in Fleet’s certificate template deletion API could allow a team administrator to delete certificate templates belonging to other teams within the sa... Read more
Affected Products :- Published: Feb. 26, 2026
- Modified: Feb. 26, 2026
- Vuln Type: Authorization
-
1.7
LOWCVE-2026-24004
Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fleet’s Android MDM Pub/Sub handling could allow unauthenticated requests to trigger device unenrollment events. This may result in unauthorized removal of in... Read more
Affected Products :- Published: Feb. 26, 2026
- Modified: Feb. 26, 2026
- Vuln Type: Authentication
-
0.6
LOWCVE-2026-23999
Fleet is open source device management software. In versions prior to 4.80.1, Fleet generated device lock and wipe PINs using a predictable algorithm based solely on the current Unix timestamp. Because no secret key or additional entropy was used, the res... Read more
Affected Products :- Published: Feb. 26, 2026
- Modified: Feb. 26, 2026
- Vuln Type: Cryptography
-
8.1
HIGHCVE-2026-1779
The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.2. This is due to incorrect authentication in the 'register_member' function. This makes it possible for unauthenticated a... Read more
Affected Products :- Published: Feb. 26, 2026
- Modified: Feb. 26, 2026
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2026-2506
The EM Cost Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.1. This is due to the plugin storing attacker-controlled 'customer_name' data and rendering it in the admin customer list withou... Read more
Affected Products :- Published: Feb. 26, 2026
- Modified: Feb. 26, 2026
- Vuln Type: Cross-Site Scripting
-
4.4
MEDIUMCVE-2026-2499
The Custom Logo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, ... Read more
Affected Products :- Published: Feb. 26, 2026
- Modified: Feb. 26, 2026
- Vuln Type: Cross-Site Scripting
-
4.4
MEDIUMCVE-2026-2498
The WP Social Meta plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack... Read more
Affected Products :- Published: Feb. 26, 2026
- Modified: Feb. 26, 2026
- Vuln Type: Cross-Site Scripting
-
4.4
MEDIUMCVE-2026-2489
The TP2WP Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Watched domains' textarea on the attachment importer settings page in all versions up to, and including, 1.1. This is due to insufficient input sanitization and ... Read more
Affected Products :- Published: Feb. 26, 2026
- Modified: Feb. 26, 2026
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2026-2029
The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[labb_pricing_item]` shortcode's `title` and `value` attributes in all versions up to, and including, 3.9.2 due to insufficient input sanitiz... Read more
Affected Products :- Published: Feb. 26, 2026
- Modified: Feb. 26, 2026
- Vuln Type: Cross-Site Scripting
-
4.0
MEDIUMCVE-2026-27973
Audiobookshelf is a self-hosted audiobook and podcast server. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 0.12.0-beta of the Audiobookshelf mobile application that allows arbitrary JavaScript execution through malicious l... Read more
Affected Products :- Published: Feb. 26, 2026
- Modified: Feb. 26, 2026
- Vuln Type: Cross-Site Scripting
-
7.6
HIGHCVE-2026-27970
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Versions prior to 21.2.0, 21.1.16, 20.3.17, and 19.2.19 have a cross-Site scripting vulnerability in the Angular internatio... Read more
Affected Products :- Published: Feb. 26, 2026
- Modified: Feb. 26, 2026
- Vuln Type: Cross-Site Scripting
-
9.3
CRITICALCVE-2026-27969
Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage location (e.g. an S3 bucket) can manipulate backup manifest files so that files in the manifes... Read more
Affected Products :- Published: Feb. 26, 2026
- Modified: Feb. 26, 2026
- Vuln Type: Path Traversal
-
4.3
MEDIUMCVE-2026-27968
Packistry is a self-hosted Composer repository designed to handle PHP package distribution. Prior to version 0.13.0, RepositoryAwareController::authorize() verified token presence and ability, but did not enforce token expiration. As a result, an expired ... Read more
Affected Products :- Published: Feb. 26, 2026
- Modified: Feb. 26, 2026
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2026-27966
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent node in Langflow hardcodes `allow_dangerous_code=True`, which automatically exposes LangChain’s Python REPL tool (`python_repl_ast`). As a... Read more
Affected Products :- Published: Feb. 26, 2026
- Modified: Feb. 26, 2026
- Vuln Type: Injection
-
8.4
HIGHCVE-2026-27965
Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage location (e.g. an S3 bucket) can manipulate backup manifest files so that arbitrary code is la... Read more
Affected Products :- Published: Feb. 26, 2026
- Modified: Feb. 26, 2026
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2026-27961
Agenta is an open-source LLMOps platform. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior to 0.86.8 in Agenta's API server evaluator template rendering. Although the vulnerable code lives in the SDK package, it is executed s... Read more
Affected Products :- Published: Feb. 26, 2026
- Modified: Feb. 26, 2026
- Vuln Type: Injection
-
7.5
HIGHCVE-2026-27959
Koa is middleware for Node.js using ES2017 async functions. Prior to versions 3.1.2 and 2.16.4, Koa's `ctx.hostname` API performs naive parsing of the HTTP Host header, extracting everything before the first colon without validating the input conforms to ... Read more
Affected Products :- Published: Feb. 26, 2026
- Modified: Feb. 26, 2026
- Vuln Type: Information Disclosure
-
4.9
MEDIUMCVE-2026-27954
Live Helper Chat is an open-source application that enables live support websites. In versions up to and including 4.52, three chat action endpoints (holdaction.php, blockuser.php, and transferchat.php) load chat objects by ID without calling `erLhcoreCl... Read more
Affected Products :- Published: Feb. 26, 2026
- Modified: Feb. 26, 2026
- Vuln Type: Authorization
-
8.8
HIGHCVE-2026-27952
Agenta is an open-source LLMOps platform. In Agenta-API prior to version 0.48.1, a Python sandbox escape vulnerability existed in Agenta's custom code evaluator. Agenta used RestrictedPython as a sandboxing mechanism for user-supplied evaluator code, but ... Read more
Affected Products :- Published: Feb. 26, 2026
- Modified: Feb. 26, 2026
- Vuln Type: Injection