Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-27759 — Featured Image from Content < 1.7 Authenticated SSRF via save_post

Featured Image from Content (featured-image-from-content) WordPress plugin versions prior to 1.7 contain an authenticated server-side request forgery vulnerability that allows Author-level users to f…

Remote | Server-Side Request Forgery
Feb 27, 2026 Feb 27, 2026
Feb 27, 2026
Feb 27, 2026
2.2 LOW
CVE-2026-28422 — Vim has stack-buffer-overflow in build_stl_str_hl()

Vim is an open source, command line text editor. Prior to version 9.2.0078, a stack-buffer-overflow occurs in `build_stl_str_hl()` when rendering a statusline with a multi-byte fill character on a ve…

vim | Memory Corruption
Feb 27, 2026 Feb 28, 2026
Feb 27, 2026
Feb 28, 2026
5.3 MEDIUM
CVE-2026-28421 — Vim has a heap-buffer-overflow and a segmentation fault

Vim is an open source, command line text editor. Versions prior to 9.2.0077 have a heap-buffer-overflow and a segmentation fault (SEGV) exist in Vim's swap file recovery logic. Both are caused by unv…

vim | Memory Corruption
Feb 27, 2026 Feb 28, 2026
Feb 27, 2026
Feb 28, 2026
4.4 MEDIUM
CVE-2026-28420 — Vim has Heap-based Buffer Overflow and OOB Read in :terminal

Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an out-of-bounds READ exist in Vim's terminal emulator when processing maximum combi…

vim | Memory Corruption
Feb 27, 2026 Feb 28, 2026
Feb 27, 2026
Feb 28, 2026
5.3 MEDIUM
CVE-2026-28419 — Vim has Heap-based Buffer Underflow in Emacs tags parsing

Vim is an open source, command line text editor. Prior to version 9.2.0075, a heap-based buffer underflow exists in Vim's Emacs-style tags file parsing logic. When processing a malformed tags file wh…

vim | Memory Corruption
Feb 27, 2026 Feb 28, 2026
Feb 27, 2026
Feb 28, 2026
4.4 MEDIUM
CVE-2026-28418 — Vim has Heap-based Buffer Overflow in Emacs tags parsing

Vim is an open source, command line text editor. Prior to version 9.2.0074, a heap-based buffer overflow out-of-bounds read exists in Vim's Emacs-style tags file parsing logic. When processing a malf…

vim | Memory Corruption
Feb 27, 2026 Feb 28, 2026
Feb 27, 2026
Feb 28, 2026
4.4 MEDIUM
CVE-2026-28417 — Vim has OS Command Injection in netrw

Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a …

vim | Injection
Feb 27, 2026 Feb 28, 2026
Feb 27, 2026
Feb 28, 2026
8.2 HIGH
CVE-2026-28416 — Gradio has SSRF via Malicious `proxy_url` Injection in `gr.load()` Config Processing

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Server-Side Request Forgery (SSRF) vulnerability in Gradio allows an attacker to make arbitrary HTTP …

gradio | Remote | Server-Side Request Forgery
Feb 27, 2026 Feb 27, 2026
Feb 27, 2026
Feb 27, 2026
4.3 MEDIUM
CVE-2026-28415 — Gradio has Open Redirect in OAuth Flow

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, the _redirect_to_target() function in Gradio's OAuth flow accepts an unvalidated _target_url query para…

gradio | Remote | Misconfiguration
Feb 27, 2026 Feb 27, 2026
Feb 27, 2026
Feb 27, 2026
7.5 HIGH
CVE-2026-28414 — Gradio has Absolute Path Traversal on Windows with Python 3.13+

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Window with Python 3.13+ are vulnerable to an absolute path traversal issue that e…

gradio | Remote | Path Traversal
Feb 27, 2026 Feb 27, 2026
Feb 27, 2026
Feb 27, 2026
9.8 CRITICAL
CVE-2026-28411 — WeGIA Vulnerable to Authentication Bypass via `extract($_REQUEST)`

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, an unsafe use of the `extract()` function on the `$_REQUEST` superglobal allows an unauthenticated attacker to overwrite lo…

wegia | Remote | Authentication
Feb 27, 2026 Feb 27, 2026
Feb 27, 2026
Feb 27, 2026
10.0 CRITICAL
CVE-2026-28409 — WeGIA Vulnerable to Remote Code Execution (RCE) via OS Command Injection

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulnerability exists in the WeGIA application's database restoration functionality. …

wegia | Remote | Injection
Feb 27, 2026 Feb 27, 2026
Feb 27, 2026
Feb 27, 2026
9.8 CRITICAL
CVE-2026-28408 — WeGIA lacks authentication verification in adicionar_tipo_docs_atendido.php

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, the script in adicionar_tipo_docs_atendido.php does not go through the project's central controller and does not have its o…

wegia | Remote | Authorization
Feb 27, 2026 Feb 27, 2026
Feb 27, 2026
Feb 27, 2026
6.9 MEDIUM
CVE-2026-28407 — malcontent's nested archive extraction failure can drop content from scan inputs

malcontent is software for discovering supply-chain compromises through context, differential analysis, and YARA. Prior to version 1.21.0, malcontent would remove nested archives which failed to extr…

malcontent | Remote | Supply Chain
Feb 27, 2026 Feb 27, 2026
Feb 27, 2026
Feb 27, 2026
8.2 HIGH
CVE-2026-28406 — kaniko has tar archive path traversal in build context extraction allows writing files ou…

kaniko is a tool to build container images from a Dockerfile, inside a container or Kubernetes cluster. Starting in version 1.25.4 and prior to version 1.25.10, kaniko unpacks build context archives …

Remote | Path Traversal
Feb 27, 2026 Feb 27, 2026
Feb 27, 2026
Feb 27, 2026
7.1 HIGH
CVE-2026-28402 — nimiq/core-rs-albatross's nimiq-blockchain missing proposal body root verification

nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.2.2, a malicious or compromised validator that is …

Remote | Misconfiguration
Feb 27, 2026 Feb 27, 2026
Feb 27, 2026
Feb 27, 2026
7.5 HIGH
CVE-2026-28400 — Docker Model Runner Unauthenticated Runtime Flag Injection via _configure Endpoint

Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Versions prior to 1.0.16 expose a POST `/engines/_configure` endpoint that accepts arbitrary runtime fl…

| Misconfiguration
Feb 27, 2026 Feb 27, 2026
Feb 27, 2026
Feb 27, 2026
8.8 HIGH
CVE-2026-27939 — Statamic allows Authenticated Control Panel users to escalate privileges via elevated ses…

Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6.4.0, Authenticated Control Panel users may under certain conditions obtain ele…

statamic | Remote | Authentication
Feb 27, 2026 Feb 27, 2026
Feb 27, 2026
Feb 27, 2026
0.0 NONE
CVE-2026-27167 — Gradio: Mocked OAuth Login Exposes Server Credentials and Uses Hardcoded Session Secret

Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version 6.6.0, Gradio applications running outside of Hugging Face Spaces automatically…

gradio | Remote | Misconfiguration
Feb 27, 2026 Feb 27, 2026
Feb 27, 2026
Feb 27, 2026
1.3 LOW
CVE-2026-28355 — "PWA" Canarytoken Vulnerable to Stored Self Cross-Site Scripting

Canarytokens help track activity and actions on a network. Versions prior to `sha-7ff0e12` have a Self Cross-Site Scripting vulnerability in the "PWA" Canarytoken, whereby the Canarytoken's creator c…

canarytokens | Remote | Cross-Site Scripting
Feb 27, 2026 Feb 27, 2026
Feb 27, 2026
Feb 27, 2026
Showing 20 of 4764 Results