CVE ID : CVE-2026-27198 Published : Feb. 21, 2026, 6:17 a.m. | 27 minutes ago Description : Formwork is a flat file-based Content Management System (CMS). In versions 2.0.0 through 2.3.3, the application…
CVE-2026-27197 – Sentry: Improper Authentication on SAML SSO process allows user identity linking
CVE ID : CVE-2026-27197 Published : Feb. 21, 2026, 5:17 a.m. | 1 hour, 27 minutes ago Description : Sentry is a developer-first error tracking and performance monitoring tool. Versions 21.12.0 through 26.1.0 have…
CVE-2026-27196 – Statamic affected by privilege escalation via stored Cross-site Scripting
CVE ID : CVE-2026-27196 Published : Feb. 21, 2026, 5:17 a.m. | 1 hour, 27 minutes ago Description : Statmatic is a Laravel and Git powered content management system (CMS). Versions 5.73.8 and below…
CVE-2026-27203 – eBay API MCP Server Affected by Environment Variable Injection
CVE ID : CVE-2026-27203 Published : Feb. 21, 2026, 12:16 a.m. | 1 hour, 46 minutes ago Description : eBay API MCP Server is an open source local MCP server providing AI assistants with…
CVE-2026-27202 – GetSimple CMS: Uploaded Files (feature) Arbitrary File Read Vulnerability
CVE ID : CVE-2026-27202 Published : Feb. 21, 2026, 12:16 a.m. | 1 hour, 46 minutes ago Description : GetSimple CMS is a content management system. All versions of GetSimple CMS have a flaw…
CVE-2026-27169 – OpenSift: Persistent XSS Chat Tool Rendering
CVE ID : CVE-2026-27169 Published : Feb. 21, 2026, 12:16 a.m. | 1 hour, 46 minutes ago Description : OpenSift is an AI study tool that sifts through large datasets using semantic search and…
CVE-2026-27168 – SAIL: Heap-based Buffer Overflow in Sail-codecs-xwd
CVE ID : CVE-2026-27168 Published : Feb. 21, 2026, 12:16 a.m. | 1 hour, 46 minutes ago Description : SAIL is a cross-platform library for loading and saving images with support for animation, metadata,…
CVE-2026-27161 – Unauthenticated Information Disclosure via .htaccess Reliance in Sensitive Directories
CVE ID : CVE-2026-27161 Published : Feb. 21, 2026, 12:16 a.m. | 1 hour, 46 minutes ago Description : GetSimple CMS is a content management system. All versions of GetSimple CMS rely on .htaccess…
CVE-2026-2635 – MLflow Use of Default Password Authentication Bypass Vulnerability
CVE ID : CVE-2026-2635 Published : Feb. 20, 2026, 11:16 p.m. | 46 minutes ago Description : MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication…
CVE-2026-2037 – GFI Archiver MArc.Core Deserialization of Untrusted Data Remote Code Execution Vulnerability
CVE ID : CVE-2026-2037 Published : Feb. 20, 2026, 11:16 p.m. | 46 minutes ago Description : GFI Archiver MArc.Core Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers…