CVE Feed

    Dashboard / CVE

    7.4
    High

    CVE-2025-70058

    Last Modified: 26 Feb 2026

    An issue pertaining to CWE-295: Improper Certificate Validation was discovered in YMFE yapi v1.12.0. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in the HTTPS agent configuration for Axios requests

    Published: 23 Feb 2026
    5.5
    Medium

    CVE-2025-61143

    Last Modified: 25 Feb 2026

    libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c.

    Published: 23 Feb 2026
    9.1
    Critical

    CVE-2026-3061

    Last Modified: 17 Apr 2026

    Out of bounds read in Media in Google Chrome prior to 145.0.7632.116 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

    Published: 23 Feb 2026
    6.5
    Medium

    CVE-2025-70044

    Last Modified: 26 Feb 2026

    An issue pertaining to CWE-295: Improper Certificate Validation was discovered in fofolee uTools-quickcommand 5.0.3.

    Published: 23 Feb 2026
    7.4
    High

    CVE-2025-63945

    Last Modified: 26 Feb 2026

    A privilege escalation (PE) vulnerability in the Tencent iOA app thru 210.9.28693.621001 on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition.

    Published: 23 Feb 2026
    6.2
    Medium

    CVE-2025-61147

    Last Modified: 24 Mar 2026

    strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table().

    Published: 23 Feb 2026
    8.8
    High

    CVE-2025-70328

    Last Modified: 26 Feb 2026

    TOTOLINK X6000R v9.4.0cu.1498_B20250826 contains an OS command injection vulnerability in the NTPSyncWithHost handler of the /usr/sbin/shttpd executable. The host_time parameter is retrieved via sub_40C404 and passed to a date -s shell command through CsteSystem. While the first two tokens of the input are validated, the remainder of the string is not sanitized, allowing authenticated attackers to execute arbitrary shell commands via shell metacharacters.

    Published: 23 Feb 2026
    8
    High

    CVE-2025-70329

    Last Modified: 24 Feb 2026

    TOTOLink X5000R v9.1.0cu_2415_B20250515 contains an OS command injection vulnerability in the setIptvCfg handler of the /usr/sbin/lighttpd executable. The vlanVidLan1 (and other vlanVidLanX) parameters are retrieved via Uci_Get_Str and passed to the CsteSystem function without adequate validation or filtering. This allows an authenticated attacker to execute arbitrary shell commands with root privileges by injecting shell metacharacters into the affected parameters.

    Published: 23 Feb 2026
    7.5
    High

    CVE-2025-69700

    Last Modified: 24 Feb 2026

    Tenda FH1203 V2.0.1.6 contains a stack-based buffer overflow vulnerability in the modify_add_client_prio function, which is reachable via the formSetClientPrio CGI handler.

    Published: 23 Feb 2026
    9.8
    Critical

    CVE-2025-70327

    Last Modified: 26 Feb 2026

    TOTOLINK X5000R v9.1.0cu_2415_B20250515 contains an argument injection vulnerability in the setDiagnosisCfg handler of the /usr/sbin/lighttpd executable. The ip parameter is retrieved via websGetVar and passed to a ping command through CsteSystem without validating if the input starts with a hyphen (-). This allows remote authenticated attackers to inject arbitrary command-line options into the ping utility, potentially leading to a Denial of Service (DoS) by causing excessive resource consumption or prolonged execution.

    Published: 23 Feb 2026
    4
    Medium

    CVE-2026-26365

    Last Modified: 17 Apr 2026

    Akamai Ghost on Akamai CDN edge servers before 2026-02-06 mishandles processing of custom hop-by-hop HTTP headers, where an incoming request containing the header "Connection: Transfer-Encoding" could result in a forward request with invalid message framing, depending on the Akamai processing path. This could result in the origin server parsing the request body incorrectly, leading to HTTP request smuggling.

    Published: 23 Feb 2026
    7.3
    High

    CVE-2025-61144

    Last Modified: 25 Feb 2026

    libtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function.

    Published: 23 Feb 2026
    9.8
    Critical

    CVE-2026-3062

    Last Modified: 17 Apr 2026

    Out of bounds read and write in Tint in Google Chrome on Mac prior to 145.0.7632.116 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

    Published: 23 Feb 2026
    6.1
    Medium

    CVE-2026-26464

    Last Modified: 18 Apr 2026

    Stored Cross-Site Scripting (XSS) was found in the /admin/edit_user.php page of Society Management System Portal V1.0, which allows remote attackers to inject and store arbitrary JavaScript code that is executed in users' browsers. This vulnerability can be exploited via the name parameter in a POST HTTP request, leading to execution of malicious scripts when the affected content is viewed by other users, including administrators.

    Published: 23 Feb 2026
    5.4
    Medium

    CVE-2026-3063

    Last Modified: 17 Apr 2026

    Inappropriate implementation in DevTools in Google Chrome prior to 145.0.7632.116 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via DevTools. (Chromium security severity: High)

    Published: 23 Feb 2026
    5
    Medium

    CVE-2025-61145

    Last Modified: 25 Feb 2026

    libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c.

    Published: 23 Feb 2026
    7.4
    High

    CVE-2025-63946

    Last Modified: 26 Feb 2026

    A privilege escalation (PE) vulnerability in the Tencent PC Manager app thru 17.10.28554.205 on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition.

    Published: 23 Feb 2026
    4
    Medium

    CVE-2025-61146

    Last Modified: 23 Apr 2026

    saitoha libsixel until v1.8.7 was discovered to contain a memory leak via the component malloc_stub.c.

    Published: 23 Feb 2026
    9.1
    Critical

    CVE-2025-70043

    Last Modified: 15 Apr 2026

    An issue pertaining to CWE-295: Improper Certificate Validation was discovered in Ayms node-To master. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in TLS socket options

    Published: 23 Feb 2026
    7.4
    High

    CVE-2026-2959

    Last Modified: 17 Apr 2026

    A vulnerability was detected in D-Link DWR-M960 1.01.07. Affected by this vulnerability is the function sub_44E0F8 of the file /boafrm/formNewSchedule. Performing a manipulation of the argument url results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used.

    Published: 22 Feb 2026
    7.4
    High

    CVE-2026-2958

    Last Modified: 17 Apr 2026

    A security vulnerability has been detected in D-Link DWR-M960 1.01.07. Affected is the function sub_457C5C of the file /boafrm/formWsc. Such manipulation of the argument save_apply leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.

    Published: 22 Feb 2026
    9.1
    Critical

    CVE-2026-2588

    Last Modified: 17 Apr 2026

    Crypt::NaCl::Sodium versions through 2.001 for Perl has an integer overflow flaw on 32-bit systems. Sodium.xs casts a STRLEN (size_t) to unsigned long long when passing a length pointer to libsodium functions. On 32-bit systems size_t is typically 32-bits while an unsigned long long is at least 64-bits.

    Published: 22 Feb 2026
    2.1
    Low

    CVE-2026-2957

    Last Modified: 17 Apr 2026

    A weakness has been identified in qinming99 dst-admin up to 1.5.0. This impacts the function deleteBackup of the file src/main/java/com/tugos/dst/admin/controller/BackupController.java of the component File Handler. This manipulation causes denial of service. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 22 Feb 2026
    2.1
    Low

    CVE-2026-2956

    Last Modified: 18 Apr 2026

    A security flaw has been discovered in qinming99 dst-admin up to 1.5.0. This affects the function revertBackup of the file /home/restore. The manipulation of the argument Name results in command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 22 Feb 2026
    2.1
    Low

    CVE-2026-2954

    Last Modified: 18 Apr 2026

    A vulnerability was found in Dromara UJCMS 10.0.2. Impacted is the function importChanel of the file /api/backend/ext/import-data/import-channel of the component ImportDataController. Performing a manipulation of the argument driverClassName/url results in injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 22 Feb 2026
    8.8
    High

    CVE-2019-25462

    Last Modified: 15 Apr 2026

    Web Ofisi Rent a Car v3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'klima' parameter. Attackers can send GET requests to with malicious 'klima' values to extract sensitive database information or cause denial of service.

    Published: 22 Feb 2026
    8.8
    High

    CVE-2019-25461

    Last Modified: 7 Apr 2026

    Web Ofisi Platinum E-Ticaret v5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'q' parameter. Attackers can send POST requests to the ajax/productsFilterSearch endpoint with malicious 'q' values using time-based blind SQL injection techniques to extract sensitive database information.

    Published: 22 Feb 2026
    8.8
    High

    CVE-2019-25460

    Last Modified: 7 Apr 2026

    Web Ofisi Platinum E-Ticaret v5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'q' GET parameter. Attackers can send requests to the arama endpoint with malicious 'q' values using time-based SQL injection techniques to extract sensitive database information.

    Published: 22 Feb 2026
    8.8
    High

    CVE-2019-25459

    Last Modified: 7 Apr 2026

    Web Ofisi Emlak V2 contains multiple SQL injection vulnerabilities in the endpoint that allow unauthenticated attackers to manipulate database queries through GET parameters. Attackers can inject SQL code into parameters like emlak_durumu, emlak_tipi, il, ilce, kelime, and semt to extract sensitive database information or perform time-based blind SQL injection attacks.

    Published: 22 Feb 2026
    8.8
    High

    CVE-2019-25458

    Last Modified: 7 Apr 2026

    Web Ofisi Firma Rehberi v1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through GET parameters. Attackers can send requests to with malicious payloads in the 'il', 'kat', or 'kelime' parameters to extract sensitive database information or perform time-based blind SQL injection attacks.

    Published: 22 Feb 2026
    8.8
    High

    CVE-2019-25457

    Last Modified: 7 Apr 2026

    Web Ofisi Firma v13 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'oz' array parameter. Attackers can send GET requests to category pages with malicious 'oz[]' values using time-based blind SQL injection payloads to extract sensitive database information.

    Published: 22 Feb 2026
    8.8
    High

    CVE-2019-25456

    Last Modified: 7 Apr 2026

    Web Ofisi Emlak v2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'ara' GET parameter. Attackers can send requests to with time-based SQL injection payloads to extract sensitive database information or cause denial of service.

    Published: 22 Feb 2026
    8.8
    High

    CVE-2019-25455

    Last Modified: 7 Apr 2026

    Web Ofisi E-Ticaret v3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'a' parameter. Attackers can send GET requests to with malicious 'a' parameter values to extract sensitive database information.

    Published: 22 Feb 2026
    2.1
    Low

    CVE-2026-2953

    Last Modified: 18 Apr 2026

    A vulnerability has been found in Dromara UJCMS 101.2. This issue affects the function deleteDirectory of the file WebFileTemplateController.delete of the component Template Handler. Such manipulation leads to path traversal. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 22 Feb 2026
    5.5
    Medium

    CVE-2026-2952

    Last Modified: 17 Apr 2026

    A flaw has been found in Vaelsys 4.1.0. This vulnerability affects unknown code of the file /tree/tree_server.php of the component HTTP POST Request Handler. This manipulation of the argument xajaxargs causes os command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 22 Feb 2026
    8.8
    High

    CVE-2019-25391

    Last Modified: 15 Apr 2026

    Ashop Shopping Cart Software contains a time-based blind SQL injection vulnerability that allows attackers to manipulate database queries through the blacklistitemid parameter. Attackers can send POST requests to the admin/bannedcustomers.php endpoint with crafted SQL payloads using SLEEP functions to extract sensitive database information.

    Published: 22 Feb 2026
    8.8
    High

    CVE-2019-25366

    Last Modified: 15 Apr 2026

    microASP Portal+ CMS contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the explode_tree parameter. Attackers can send crafted requests to pagina.phtml with SQL injection payloads using extractvalue and concat functions to extract sensitive database information like the current database name.

    Published: 22 Feb 2026
    8.8
    High

    CVE-2019-25440

    Last Modified: 15 Apr 2026

    WebIncorp ERP contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the prod_id parameter. Attackers can send GET requests to product_detail.php with malicious prod_id values to extract sensitive database information.

    Published: 22 Feb 2026
    8.8
    High

    CVE-2019-25439

    Last Modified: 15 Apr 2026

    NoviSmart CMS contains an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the Referer HTTP header field. Attackers can craft requests with time-based SQL injection payloads in the Referer header to extract sensitive database information or cause denial of service.

    Published: 22 Feb 2026
    8.8
    High

    CVE-2019-25433

    Last Modified: 15 Apr 2026

    XOOPS CMS 2.5.9 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cid parameter. Attackers can send GET requests to the gerar_pdf.php endpoint with malicious cid values to extract sensitive database information.

    Published: 22 Feb 2026
    2
    Low

    CVE-2026-2947

    Last Modified: 17 Apr 2026

    A vulnerability was detected in rymcu forest up to 0.0.5. This affects the function updateUserInfo of the file - src/main/java/com/rymcu/forest/web/api/user/UserInfoController.java of the component User Profile Handler. The manipulation results in cross site scripting. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 22 Feb 2026
    8.8
    High

    CVE-2019-25452

    Last Modified: 7 Apr 2026

    Dolibarr ERP/CRM 10.0.1 contains an SQL injection vulnerability in the elemid POST parameter of the viewcat.php endpoint that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can submit crafted POST requests with malicious SQL payloads in the elemid parameter to extract sensitive database information using error-based or time-based blind SQL injection techniques.

    Published: 22 Feb 2026
    7.1
    High

    CVE-2019-25450

    Last Modified: 7 Apr 2026

    Dolibarr ERP/CRM 10.0.1 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injecting SQL code through POST parameters. Attackers can inject malicious SQL through parameters like actioncode, demand_reason_id, and availability_id in card.php endpoints to extract sensitive database information using boolean-based blind, error-based, and time-based blind techniques.

    Published: 22 Feb 2026
    8.8
    High

    CVE-2019-25446

    Last Modified: 15 Apr 2026

    DIGIT CENTRIS ERP contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the datum1, datum2, KID, and PID parameters. Attackers can send POST requests to /korisnikinfo.php with malicious SQL syntax in these parameters to extract or modify sensitive database information.

    Published: 22 Feb 2026
    8.8
    High

    CVE-2019-25443

    Last Modified: 15 Apr 2026

    Inventory Webapp contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through GET parameters. Attackers can supply malicious SQL payloads in the name, description, quantity, or cat_id parameters to add-item.php to execute arbitrary database commands.

    Published: 22 Feb 2026
    8.8
    High

    CVE-2019-25442

    Last Modified: 7 Apr 2026

    Web Wiz Forums 12.01 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the PF parameter. Attackers can send GET requests to member_profile.asp with malicious PF values to extract sensitive database information.

    Published: 22 Feb 2026
    2
    Low

    CVE-2026-2946

    Last Modified: 17 Apr 2026

    A security vulnerability has been detected in rymcu forest up to 0.0.5. Affected by this issue is the function XssUtils.replaceHtmlCode of the file src/main/java/com/rymcu/forest/util/XssUtils.java of the component Article Content/Comments/Portfolio. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 22 Feb 2026
    2.1
    Low

    CVE-2026-2945

    Last Modified: 17 Apr 2026

    A weakness has been identified in JeecgBoot 3.9.0. Affected by this vulnerability is an unknown functionality of the file /sys/common/uploadImgByHttp. Executing a manipulation of the argument fileUrl can lead to server-side request forgery. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 22 Feb 2026
    5.5
    Medium

    CVE-2026-2944

    Last Modified: 17 Apr 2026

    A security flaw has been discovered in Tosei Online Store Management System ネット店舗管理システム 1.01. Affected is the function system of the file /cgi-bin/monitor.php of the component HTTP POST Request Handler. Performing a manipulation of the argument DevId results in os command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 22 Feb 2026
    2.1
    Low

    CVE-2026-2943

    Last Modified: 15 Apr 2026

    A vulnerability was identified in SapneshNaik Student Management System up to f4b4f0928f0b5551a28ee81ae7e7fe47d9345318. This impacts an unknown function of the file index.php. Such manipulation of the argument Error leads to cross site scripting. The attack can be launched remotely. The exploit is publicly available and might be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 22 Feb 2026