CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2025-15563

    Last Modified: 26 Feb 2026

    Any unauthenticated user can reset the WorkTime on-prem database configuration by sending a specific HTTP request to the WorkTime server. No authorization check is applied here.

    Published: 19 Feb 2026
    7.3
    High

    CVE-2025-9062

    Last Modified: 5 Jun 2026

    Authorization Bypass Through User-Controlled Key vulnerability in MeCODE Informatics and Engineering Services Ltd. Envanty allows Parameter Injection. This issue affects Envanty: before 1.0.6.   NOTE: The vendor was contacted early about this disclosure but did not respond in any way. The vulnerability was learned to be remediated through reporter information and testing.

    Published: 19 Feb 2026
    6.1
    Medium

    CVE-2025-15562

    Last Modified: 26 Feb 2026

    The server API endpoint /report/internet/urls reflects received data into the HTML response without applying proper encoding or filtering. This allows an attacker to execute arbitrary JavaScript in the victim's browser if the victim opens a URL prepared by the attacker.

    Published: 19 Feb 2026
    7.8
    High

    CVE-2025-15561

    Last Modified: 26 Feb 2026

    An attacker can exploit the update behavior of the WorkTime monitoring daemon to elevate privileges on the local system to NT Authority\SYSTEM. A malicious executable must be named  WTWatch.exe and dropped in the C:\ProgramData\wta\ClientExe directory, which is writable by "Everyone". The executable will then be run by the WorkTime monitoring daemon.

    Published: 19 Feb 2026
    8.8
    High

    CVE-2025-15560

    Last Modified: 26 Feb 2026

    An authenticated attacker with minimal permissions can exploit a SQL injection in the WorkTime server "widget" API endpoint to inject SQL queries. If the Firebird backend is used, attackers are able to retrieve all data from the database backend. If the MSSQL backend is used the attacker can execute arbitrary SQL statements on the database backend and gain access to sensitive data.

    Published: 19 Feb 2026
    9.8
    Critical

    CVE-2025-15559

    Last Modified: 3 Mar 2026

    An unauthenticated attacker can inject OS commands when calling a server API endpoint in NesterSoft WorkTime. The server API call to generate and download the WorkTime client from the WorkTime server is vulnerable in the “guid” parameter. This allows an attacker to execute arbitrary commands on the WorkTime server as NT Authority\SYSTEM with the highest privileges. Attackers are able to access or manipulate sensitive data and take over the whole server.

    Published: 19 Feb 2026
    9.1
    Critical

    CVE-2025-13590

    Last Modified: 6 Mar 2026

    A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST API. Successful uploads may lead to remote code execution. By leveraging the vulnerability, a malicious actor may perform Remote Code Execution by uploading a specially crafted payload.

    Published: 19 Feb 2026
    8.4
    High

    CVE-2025-12107

    Last Modified: 3 Sept 2026

    The Velocity template engine, utilized by the affected product, accepts and processes template syntax without sufficient sanitization or validation of user-controlled input. This allows an authenticated administrator to inject arbitrary template syntax. Successful exploitation enables an attacker with administrative privileges to execute arbitrary template code on the server. This can lead to significant security consequences, including remote code execution, manipulation of data, and unauthorized access to sensitive information.

    Published: 19 Feb 2026
    5.3
    Medium

    CVE-2026-1219

    Last Modified: 17 Apr 2026

    The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 4.0 to 5.10 via the 'load_track_note_ajax' due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view the contents of private posts.

    Published: 19 Feb 2026
    6.4
    Medium

    CVE-2026-2718

    Last Modified: 15 Apr 2026

    The Dealia – Request a Quote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Gutenberg block attributes in all versions up to, and including, 1.0.8. This is due to the use of `wp_kses()` for output escaping within HTML attribute contexts where `esc_attr()` is required. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 19 Feb 2026
    4.4
    Medium

    CVE-2026-2716

    Last Modified: 15 Apr 2026

    The Client Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Testimonial Heading' setting in all versions up to, and including, 2.0. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 19 Feb 2026
    6.5
    Medium

    CVE-2026-1461

    Last Modified: 15 Apr 2026

    The Simple Membership plugin for WordPress is vulnerable to Improper Handling of Missing Values in all versions up to, and including, 4.7.0 via the Stripe webhook handler. This is due to the plugin only validating webhook signatures when the stripe-webhook-signing-secret setting is configured, which is empty by default. This makes it possible for unauthenticated attackers to forge Stripe webhook events to manipulate membership subscriptions, including reactivating expired memberships without payment or canceling legitimate subscriptions, potentially leading to unauthorized access and service disruption.

    Published: 19 Feb 2026
    8.1
    High

    CVE-2026-22267

    Last Modified: 17 Apr 2026

    Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

    Published: 19 Feb 2026
    6.3
    Medium

    CVE-2026-22268

    Last Modified: 17 Apr 2026

    Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to denial of service of a Dell Enterprise Support connection.

    Published: 19 Feb 2026
    4.7
    Medium

    CVE-2026-22266

    Last Modified: 18 Apr 2026

    Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Improper Verification of Source of a Communication Channel vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.

    Published: 19 Feb 2026
    Unknown

    CVE-2026-27323

    Last Modified: 20 Feb 2026

    Not used

    Published: 19 Feb 2026
    Unknown

    CVE-2026-27324

    Last Modified: 20 Feb 2026

    Not used

    Published: 19 Feb 2026
    Unknown

    CVE-2026-27325

    Last Modified: 20 Feb 2026

    Not used

    Published: 19 Feb 2026
    Unknown

    CVE-2026-27317

    Last Modified: 20 Feb 2026

    Not used

    Published: 19 Feb 2026
    Unknown

    CVE-2026-27318

    Last Modified: 20 Feb 2026

    Not used

    Published: 19 Feb 2026
    Unknown

    CVE-2026-27319

    Last Modified: 20 Feb 2026

    Not used

    Published: 19 Feb 2026
    Unknown

    CVE-2026-27320

    Last Modified: 20 Feb 2026

    Not used

    Published: 19 Feb 2026
    Unknown

    CVE-2026-27321

    Last Modified: 20 Feb 2026

    Not used

    Published: 19 Feb 2026
    Unknown

    CVE-2026-27322

    Last Modified: 20 Feb 2026

    Not used

    Published: 19 Feb 2026
    4.7
    Medium

    CVE-2026-22269

    Last Modified: 18 Apr 2026

    Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Improper Verification of Source of a Communication Channel vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.

    Published: 19 Feb 2026
    6.9
    Medium

    CVE-2025-41023

    Last Modified: 15 Apr 2026

    An authentication bypass vulnerability has been found in Thesamur's AutoGPT. This vulnerability allows an attacker to bypass authentication mechanisms. Once inside the web application, the attacker can use any of its features regardless of the authorisation method used.

    Published: 19 Feb 2026
    8.8
    High

    CVE-2026-26358

    Last Modified: 18 Apr 2026

    Dell Unisphere for PowerMax, version(s) 10.2, contain(s) a Missing Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

    Published: 19 Feb 2026
    5.1
    Medium

    CVE-2025-40697

    Last Modified: 15 Apr 2026

    Reflected Cross-Site Scripting (XSS) vulnerability in '/index.php' in Lewe WebMeasure, which allows remote attackers to execute arbitrary code through the 'page' parameter. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.

    Published: 19 Feb 2026
    8.1
    High

    CVE-2026-26360

    Last Modified: 18 Apr 2026

    Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability to delete arbitrary files.

    Published: 19 Feb 2026
    5.1
    Medium

    CVE-2026-2736

    Last Modified: 17 Apr 2026

    Reflected Cross-site Scripting (XSS) in Alkacon's OpenCms v18.0, which allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL containing the ‘q’ parameter in ‘/search/index.html’. This vulnerability can be exploited to steal sensitive user information such as session cookies, or to perform actions while impersonating the user.

    Published: 19 Feb 2026
    5.1
    Medium

    CVE-2026-2735

    Last Modified: 18 Apr 2026

    Stored Cross-Site Scripting (XSS) in Alkacon's OpenCms v18.0, which occurs when user input is not properly validated when sending a POST request to ‘/blog/new-article/org.opencms.ugc.CmsUgcEditService.gwt’ using the ‘text’ parameter.

    Published: 19 Feb 2026
    8.8
    High

    CVE-2026-26359

    Last Modified: 17 Apr 2026

    Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the ability to overwrite arbitrary files.

    Published: 19 Feb 2026
    6.5
    Medium

    CVE-2026-27094

    Last Modified: 16 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GoDaddy CoBlocks coblocks allows Stored XSS.This issue affects CoBlocks: from n/a through <= 3.1.16.

    Published: 19 Feb 2026
    6.5
    Medium

    CVE-2026-27092

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in Greg Winiarski WPAdverts wpadverts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPAdverts: from n/a through <= 2.3.0.

    Published: 19 Feb 2026
    4.3
    Medium

    CVE-2026-27090

    Last Modified: 16 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WP Moose Kenta Companion kenta-companion allows Cross Site Request Forgery.This issue affects Kenta Companion: from n/a through <= 1.3.3.

    Published: 19 Feb 2026
    6.5
    Medium

    CVE-2026-27074

    Last Modified: 16 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vaakash Shortcoder shortcoder allows Stored XSS.This issue affects Shortcoder: from n/a through <= 6.5.1.

    Published: 19 Feb 2026
    6.5
    Medium

    CVE-2026-27069

    Last Modified: 16 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Soledad soledad allows DOM-Based XSS.This issue affects Soledad: from n/a through <= 8.7.2.

    Published: 19 Feb 2026
    Unknown

    CVE-2026-27066

    Last Modified: 11 Jun 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 19 Feb 2026
    6.5
    Medium

    CVE-2026-27059

    Last Modified: 16 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci Recipe penci-recipe allows DOM-Based XSS.This issue affects Penci Recipe: from n/a through <= 4.1.

    Published: 19 Feb 2026
    6.5
    Medium

    CVE-2026-27058

    Last Modified: 16 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci Podcast penci-podcast allows DOM-Based XSS.This issue affects Penci Podcast: from n/a through <= 1.7.

    Published: 19 Feb 2026
    6.5
    Medium

    CVE-2026-27057

    Last Modified: 16 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci Filter Everything penci-filter-everything allows Stored XSS.This issue affects Penci Filter Everything: from n/a through <= 1.7.

    Published: 19 Feb 2026
    4.3
    Medium

    CVE-2026-27055

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in PenciDesign Penci AI SmartContent Creator penci-ai allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Penci AI SmartContent Creator: from n/a through <= 2.0.

    Published: 19 Feb 2026
    7.5
    High

    CVE-2026-27052

    Last Modified: 16 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in villatheme Sales Countdown Timer for WooCommerce and WordPress sctv-sales-countdown-timer allows PHP Local File Inclusion.This issue affects Sales Countdown Timer for WooCommerce and WordPress: from n/a through < 1.1.9.

    Published: 19 Feb 2026
    5.4
    Medium

    CVE-2026-27050

    Last Modified: 16 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ThimPress RealPress realpress allows Cross Site Request Forgery.This issue affects RealPress: from n/a through <= 1.1.0.

    Published: 19 Feb 2026
    5.3
    Medium

    CVE-2026-27042

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in WPDeveloper NotificationX notificationx allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NotificationX: from n/a through <= 3.2.1.

    Published: 19 Feb 2026
    5.4
    Medium

    CVE-2026-25473

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in AA-Team WZone woozone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WZone: from n/a through <= 14.0.31.

    Published: 19 Feb 2026
    6.5
    Medium

    CVE-2026-25472

    Last Modified: 16 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeFusion Fusion Builder fusion-builder allows Stored XSS.This issue affects Fusion Builder: from n/a through <= 3.14.1.

    Published: 19 Feb 2026
    6.5
    Medium

    CVE-2026-25463

    Last Modified: 16 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WpEstate Wpresidence Core wpresidence-core allows Stored XSS.This issue affects Wpresidence Core: from n/a through <= 5.4.0.

    Published: 19 Feb 2026
    4.3
    Medium

    CVE-2026-25459

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in uixthemes Sober sober allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sober: from n/a through <= 3.5.12.

    Published: 19 Feb 2026
    6.5
    Medium

    CVE-2026-25453

    Last Modified: 16 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mdempfle Advanced iFrame advanced-iframe allows DOM-Based XSS.This issue affects Advanced iFrame: from n/a through <= 2025.10.

    Published: 19 Feb 2026