CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2026-2617

    Last Modified: 18 Apr 2026

    A vulnerability was found in Beetel 777VR1 up to 01.00.09. This affects an unknown function of the component Telnet Service/SSH Service. The manipulation results in insecure default initialization of resource. The attack can only be performed from the local network. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 17 Feb 2026
    6.5
    Medium

    CVE-2024-31118

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Smartypants SP Project & Document Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SP Project & Document Manager: from n/a through 4.70.

    Published: 17 Feb 2026
    7.4
    High

    CVE-2026-2616

    Last Modified: 17 Apr 2026

    A vulnerability has been found in Beetel 777VR1 up to 01.00.09. The impacted element is an unknown function of the component Web Management Interface. The manipulation leads to hard-coded credentials. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used. It is advisable to modify the configuration settings. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 17 Feb 2026
    8.2
    High

    CVE-2026-24708

    Last Modified: 11 Sept 2026

    An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend to call qemu-img without a format restriction, resulting in an unsafe image resize operation that could destroy data on the host system. Only compute nodes using the Flat image backend (usually configured with use_cow_images=False) are affected.

    Published: 17 Feb 2026
    6.5
    Medium

    CVE-2022-41650

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Paul Custom Content by Country (by Shield Security) custom-content-by-country.This issue affects Custom Content by Country (by Shield Security): from n/a through 3.1.2.

    Published: 17 Feb 2026
    9.4
    Critical

    CVE-2026-22208

    Last Modified: 26 May 2026

    OpenS100 (the reference implementation S-100 viewer) prior to commit 753cf29 contains a remote code execution vulnerability via an unrestricted Lua interpreter. The Portrayal Engine initializes Lua using luaL_openlibs() without sandboxing or capability restrictions, exposing standard libraries such as 'os' and 'io' to untrusted portrayal catalogues. An attacker can provide a malicious S-100 portrayal catalogue containing Lua scripts that execute arbitrary commands with the privileges of the OpenS100 process when a user imports the catalogue and loads a chart.

    Published: 17 Feb 2026
    5.4
    Medium

    CVE-2026-23861

    Last Modified: 17 Apr 2026

    Dell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the execution of malicious HTML or JavaScript code in a victim user's web browser in the context of the vulnerable web application. Exploitation may lead to information disclosure, session theft, or client-side request forgery.

    Published: 17 Feb 2026
    6.1
    Medium

    CVE-2025-7706

    Last Modified: 5 Jun 2026

    Missing Authentication for Critical Function vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Remote Code Inclusion. This issue affects Liderahenk: from 3.0.0 to 3.3.1 before 3.5.0.

    Published: 17 Feb 2026
    7
    High

    CVE-2026-25087

    Last Modified: 17 Apr 2026

    Use After Free vulnerability in Apache Arrow C++. This issue affects Apache Arrow C++ from 15.0.0 through 23.0.0. It can be triggered when reading an Arrow IPC file (but not an IPC stream) with pre-buffering enabled, if the IPC file contains data with variadic buffers (such as Binary View and String View data). Depending on the number of variadic buffers in a record batch column and on the temporal sequence of multi-threaded IO, a write to a dangling pointer could occur. The value (a `std::shared_ptr<Buffer>` object) that is written to the dangling pointer is not under direct control of the attacker. Pre-buffering is disabled by default but can be enabled using a specific C++ API call (`RecordBatchFileReader::PreBufferMetadata`). The functionality is not exposed in language bindings (Python, Ruby, C GLib), so these bindings are not vulnerable. The most likely consequence of this issue would be random crashes or memory corruption when reading specific kinds of IPC files. If the application allows ingesting IPC files from untrusted sources, this could plausibly be exploited for denial of service. Inducing more targeted kinds of misbehavior (such as confidential data extraction from the running process) depends on memory allocation and multi-threaded IO temporal patterns that are unlikely to be easily controlled by an attacker. Advice for users of Arrow C++: 1. check whether you enable pre-buffering on the IPC file reader (using `RecordBatchFileReader::PreBufferMetadata`) 2. if so, either disable pre-buffering (which may have adverse performance consequences), or switch to Arrow 23.0.1 which is not vulnerable

    Published: 17 Feb 2026
    7.3
    High

    CVE-2026-2615

    Last Modified: 17 Apr 2026

    A flaw has been found in Wavlink WL-NU516U1 up to 20251208. The affected element is the function singlePortForwardDelete of the file /cgi-bin/firewall.cgi. Executing a manipulation of the argument del_flag can lead to command injection. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 17 Feb 2026
    4
    Medium

    CVE-2026-2625

    Last Modified: 1 May 2026

    A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Hat Package Manager (RPM) file. During the RPM signature verification process, this crafted file can trigger an error in the OpenPGP signature parsing code, leading to an unconditional termination of the rpm process. This issue results in an application level denial of service, making the system unable to process RPM files for signature verification.

    Published: 17 Feb 2026
    6.5
    Medium

    CVE-2025-8303

    Last Modified: 5 Jun 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EKA Software Computer Information Advertising Services Ltd. Real Estate Script V5 (With Doping Module – Store Module – New Language System) allows Cross-Site Scripting (XSS). This issue affects Real Estate Script V5 (With Doping Module – Store Module – New Language System): through 17022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 17 Feb 2026
    8.6
    High

    CVE-2025-7631

    Last Modified: 5 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tumeva Internet Technologies Software Information Advertising and Consulting Services Trade Ltd. Co. Tumeva Prime News Software allows SQL Injection. This issue affects Tumeva Prime News Software: from v.1.0.1 before v1.0.2.

    Published: 17 Feb 2026
    8.3
    High

    CVE-2026-2247

    Last Modified: 17 Apr 2026

    SQL injection vulnerability (SQLi) in Clicldeu SaaS, specifically in the generation of reports, which occurs when a previously authenticated remote attacker executes a malicious payload in the URL generated after downloading the student's report card in the ‘Day-to-day’ section from the mobile application. In the URL of the generated PDF, the session token used does not expire, so it remains valid for days after its generation, and unusual characters can be entered after the ‘id_alu’ parameter, resulting in two types of SQLi: boolean-based blind and time-based blind. Exploiting this vulnerability could allow an attacker to access confidential information in the database.

    Published: 17 Feb 2026
    4.3
    Medium

    CVE-2026-2608

    Last Modified: 15 Apr 2026

    The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.5.32. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.

    Published: 17 Feb 2026
    Unknown

    CVE-2026-27036

    Last Modified: 18 Feb 2026

    Not used

    Published: 17 Feb 2026
    Unknown

    CVE-2026-27037

    Last Modified: 18 Feb 2026

    Not used

    Published: 17 Feb 2026
    Unknown

    CVE-2026-27038

    Last Modified: 18 Feb 2026

    Not used

    Published: 17 Feb 2026
    Unknown

    CVE-2026-27031

    Last Modified: 18 Feb 2026

    Not used

    Published: 17 Feb 2026
    Unknown

    CVE-2026-27032

    Last Modified: 18 Feb 2026

    Not used

    Published: 17 Feb 2026
    Unknown

    CVE-2026-27033

    Last Modified: 18 Feb 2026

    Not used

    Published: 17 Feb 2026
    Unknown

    CVE-2026-27034

    Last Modified: 18 Feb 2026

    Not used

    Published: 17 Feb 2026
    Unknown

    CVE-2026-27035

    Last Modified: 18 Feb 2026

    Not used

    Published: 17 Feb 2026
    8.7
    High

    CVE-2026-25903

    Last Modified: 17 Apr 2026

    Apache NiFi 1.1.0 through 2.7.2 are missing authorization when updating configuration properties on extension components that have specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges required to add the annotated component to the flow configuration, but framework authorization did not check restricted status when updating a component previously added. The missing authorization requires a more privileged user to add a restricted component to the flow configuration, but permits a less privileged user to make property configuration changes. Apache NiFi installations that do not implement different levels of authorization for Restricted components are not subject to this vulnerability because the framework enforces write permissions as the security boundary. Upgrading to Apache NiFi 2.8.0 is the recommended mitigation.

    Published: 17 Feb 2026
    7.2
    High

    CVE-2026-1216

    Last Modified: 15 Apr 2026

    The RSS Aggregator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'template' parameter in all versions up to, and including, 5.0.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 17 Feb 2026
    5.8
    Medium

    CVE-2026-0829

    Last Modified: 15 Apr 2026

    The Frontend File Manager Plugin WordPress plugin through 23.5 allows unauthenticated users to send emails through the site without any security checks. This lets attackers use the WordPress site as an open relay for spam or phishing emails to anyone. Attackers can also guess file IDs to access and share uploaded files without permission, exposing sensitive information.

    Published: 17 Feb 2026
    5.3
    Medium

    CVE-2026-1657

    Last Modified: 18 Apr 2026

    The EventPrime plugin for WordPress is vulnerable to unauthorized image file upload in all versions up to, and including, 4.2.8.4. This is due to the plugin registering the upload_file_media AJAX action as publicly accessible (nopriv-enabled) without implementing any authentication, authorization, or nonce verification despite a nonce being created. This makes it possible for unauthenticated attackers to upload image files to the WordPress uploads directory and create Media Library attachments via the ep_upload_file_media endpoint.

    Published: 17 Feb 2026
    7.7
    High

    CVE-2026-2592

    Last Modified: 15 Apr 2026

    The Zarinpal Gateway for WooCommerce plugin for WordPress is vulnerable to Improper Access Control to Payment Status Update in all versions up to and including 5.0.16. This is due to the payment callback handler 'Return_from_ZarinPal_Gateway' failing to validate that the authority token provided in the callback URL belongs to the specific order being marked as paid. This makes it possible for unauthenticated attackers to potentially mark orders as paid without proper payment by reusing a valid authority token from a different transaction of the same amount.

    Published: 17 Feb 2026
    4.4
    Medium

    CVE-2026-2002

    Last Modified: 15 Apr 2026

    The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form_name parameter in all versions up to, and including, 1.50.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The plugin allows admins to give form management permissions to lower level users, which could make this exploitable by users such as subscribers.

    Published: 17 Feb 2026
    9.3
    Critical

    CVE-2026-26220

    Last Modified: 17 Apr 2026

    LightLLM version 1.1.0 and prior contain an unauthenticated remote code execution vulnerability in PD (prefill-decode) disaggregation mode. The PD master node exposes WebSocket endpoints that receive binary frames and pass the data directly to pickle.loads() without authentication or validation. A remote attacker who can reach the PD master can send a crafted payload to achieve arbitrary code execution.

    Published: 17 Feb 2026
    Unknown

    CVE-2026-26995

    Last Modified: 20 Feb 2026

    Further research determined the issue is an external dependency vulnerability.

    Published: 17 Feb 2026
    8.8
    High

    CVE-2026-26732

    Last Modified: 16 Apr 2026

    TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the vpnUser or vpnPassword` parameters in the formFilter function.

    Published: 17 Feb 2026
    7.1
    High

    CVE-2025-70846

    Last Modified: 15 Apr 2026

    lty628 aidigu v1.9.1 is vulnerable to Cross Site Scripting (XSS) on the /tools/Password/add page in the input field password.

    Published: 17 Feb 2026
    7.6
    High

    CVE-2025-67102

    Last Modified: 3 Apr 2026

    A SQL injection vulnerability in the alldayoffs feature in Jorani up to v1.0.4, allows an authenticated attacker to execute arbitrary SQL commands via the entity parameter.

    Published: 17 Feb 2026
    7.2
    High

    CVE-2025-70397

    Last Modified: 19 Feb 2026

    jizhicms 2.5.6 is vulnerable to SQL Injection in Article/deleteAll and Extmolds/deleteAll via the data parameter.

    Published: 17 Feb 2026
    8.8
    High

    CVE-2026-26736

    Last Modified: 17 Apr 2026

    TOTOLINK A3002RU_V3 V3.0.0-B20220304.1804 was discovered to contain a stack-based buffer overflow via the static_ipv6 parameter in the formIpv6Setup function.

    Published: 17 Feb 2026
    7.5
    High

    CVE-2025-65753

    Last Modified: 15 Apr 2026

    An issue in the TLS certification mechanism of Guardian Gryphon v01.06.0006.22 allows attackers to execute commands as root.

    Published: 17 Feb 2026
    7.9
    High

    CVE-2025-32355

    Last Modified: 3 Apr 2026

    Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections. However, the proxy is misconfigured in a way that allows specifying absolute URLs in the HTTP request line, causing the proxy to load the given resource.

    Published: 17 Feb 2026
    9.9
    Critical

    CVE-2025-70830

    Last Modified: 15 Apr 2026

    A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows authenticated attackers to execute arbitrary code via injecting crafted Freemarker template syntax into the SQL script field.

    Published: 17 Feb 2026
    8.8
    High

    CVE-2025-70828

    Last Modified: 3 Apr 2026

    An issue in Datart v1.0.0-rc.3 allows attackers to execute arbitrary code via the url parameter in the JDBC configuration

    Published: 17 Feb 2026
    8.8
    High

    CVE-2024-55270

    Last Modified: 23 Feb 2026

    phpgurukul Student Management System 1.0 is vulnerable to SQL Injection in studentms/admin/search.php via the searchdata parameter.

    Published: 17 Feb 2026
    5.7
    Medium

    CVE-2025-70829

    Last Modified: 23 Feb 2026

    An information exposure vulnerability in Datart v1.0.0-rc.3 allows authenticated attackers to access sensitive data via a custom H2 JDBC connection string.

    Published: 17 Feb 2026
    3.5
    Low

    CVE-2024-55271

    Last Modified: 23 Feb 2026

    A Cross-Site Request Forgery (CSRF) vulnerability has been identified in phpgurukul Gym Management System 1.0. This issue is present in the profile update functionality of the User Panel, specifically the /profile.php endpoint.

    Published: 17 Feb 2026
    8.7
    High

    CVE-2025-67905

    Last Modified: 15 Apr 2026

    Malwarebytes AdwCleaner before v.8.7.0 runs as Administrator and performs an insecure log file delete operation in which the target location is user-controllable, allowing a non-admin user to escalate privileges to SYSTEM via a symbolic link, a related issue to CVE-2023-28892. To exploit this, an attacker must create a file in a given folder path and intercept the application log file deletion flow.

    Published: 17 Feb 2026
    8.8
    High

    CVE-2026-26731

    Last Modified: 16 Apr 2026

    TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the routernamer`parameter in the formDnsv6 function.

    Published: 17 Feb 2026
    9.4
    Critical

    CVE-2025-59793

    Last Modified: 3 Apr 2026

    Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able to upload files. However, the application doesn't properly sanitize the jobDirectory parameter, which allows path traversal sequences to be included. This allows writing files to arbitrary local filesystem locations and may subsequently lead to remote code execution.

    Published: 17 Feb 2026
    8.8
    High

    CVE-2025-12062

    Last Modified: 22 Apr 2026

    The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8.6 via the fc_load_template function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary .html files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .html file types can be uploaded and included.

    Published: 16 Feb 2026
    9.8
    Critical

    CVE-2026-2439

    Last Modified: 17 Apr 2026

    Concierge::Sessions versions from 0.8.1 before 0.8.5 for Perl generate insecure session ids. The generate_session_id function in Concierge::Sessions::Base defaults to using the uuidgen command to generate a UUID, with a fallback to using Perl's built-in rand function. Neither of these methods are secure, and attackers are able to guess session_ids that can grant them access to systems. Specifically, * There is no warning when uuidgen fails. The software can be quietly using the fallback rand() function with no warnings if the command fails for any reason. * The uuidgen command will generate a time-based UUID if the system does not have a high-quality random number source, because the call does not explicitly specify the --random option. Note that the system time is shared in HTTP responses. * UUIDs are identifiers whose mere possession grants access, as per RFC 9562. * The output of the built-in rand() function is predictable and unsuitable for security applications.

    Published: 16 Feb 2026
    9.8
    Critical

    CVE-2025-15578

    Last Modified: 10 Mar 2026

    Maypole versions from 2.10 through 2.13 for Perl generates session ids insecurely. The session id is seeded with the system time (which is available from HTTP response headers), a call to the built-in rand() function, and the PID.

    Published: 16 Feb 2026
    7.5
    High

    CVE-2026-2474

    Last Modified: 18 Apr 2026

    Crypt::URandom versions from 0.41 before 0.55 for Perl is vulnerable to a heap buffer overflow in the XS function crypt_urandom_getrandom(). The function does not validate that the length parameter is non-negative. If a negative value (e.g. -1) is supplied, the expression length + 1u causes an integer wraparound, resulting in a zero-byte allocation. The subsequent call to getrandom(data, length, GRND_NONBLOCK) passes the original negative value, which is implicitly converted to a large unsigned value (typically SIZE_MAX). This can result in writes beyond the allocated buffer, leading to heap memory corruption and application crash (denial of service). In common usage, the length argument is typically hardcoded by the caller, which reduces the likelihood of attacker-controlled exploitation. Applications that pass untrusted input to this parameter may be affected.

    Published: 16 Feb 2026