CVE Feed

    Dashboard / CVE

    1.9
    Low

    CVE-2026-2241

    Last Modified: 18 Apr 2026

    A vulnerability was found in janet-lang janet up to 1.40.1. This affects the function os_strftime of the file src/core/os.c. Performing a manipulation results in out-of-bounds read. The attack must be initiated from a local position. The exploit has been made public and could be used. The patch is named 0f285855f0e34f9183956be5f16e045f54626bff. To fix this issue, it is recommended to deploy a patch.

    Published: 9 Feb 2026
    1.9
    Low

    CVE-2026-2240

    Last Modified: 17 Apr 2026

    A vulnerability has been found in janet-lang janet up to 1.40.1. The impacted element is the function janetc_pop_funcdef of the file src/core/compile.c. Such manipulation leads to out-of-bounds read. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The name of the patch is 4dd08a4cdef5b1c42d9a2c19fc24412e97ef51d5. A patch should be applied to remediate this issue.

    Published: 9 Feb 2026
    5.3
    Medium

    CVE-2026-24095

    Last Modified: 18 Apr 2026

    Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p21, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows users with the "Use WATO" permission to access the "Analyze configuration" page by directly navigating to its URL, bypassing the intended "Access analyze configuration" permission check. If these users also have the "Make changes, perform actions" permission, they can perform unauthorized actions such as disabling checks or acknowledging results.

    Published: 9 Feb 2026
    6.5
    Medium

    CVE-2025-59024

    Last Modified: 20 Apr 2026

    Crafted delegations or IP fragments can poison cached delegations in Recursor.

    Published: 9 Feb 2026
    8.2
    High

    CVE-2025-59023

    Last Modified: 20 Apr 2026

    Crafted delegations or IP fragments can poison cached delegations in Recursor.

    Published: 9 Feb 2026
    5.3
    Medium

    CVE-2025-14831

    Last Modified: 29 Jun 2026

    A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs).

    Published: 9 Feb 2026
    5.3
    Medium

    CVE-2026-24027

    Last Modified: 20 Apr 2026

    Crafted zones can lead to increased incoming network traffic.

    Published: 9 Feb 2026
    5.3
    Medium

    CVE-2026-0398

    Last Modified: 20 Apr 2026

    Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor.

    Published: 9 Feb 2026
    8.8
    High

    CVE-2025-10465

    Last Modified: 5 Jun 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Sensaway allows Upload a Web Shell to a Web Server. This issue affects Sensaway: through 09022026. NOTE: Because the product was developed using outdated technology, the manufacturer is unable to fix the relevant vulnerabilities. Users of the Sensaway application are advised to contact the manufacturer and review updated products developed with newer technology.

    Published: 9 Feb 2026
    6.5
    Medium

    CVE-2025-10464

    Last Modified: 5 Jun 2026

    Insecure Storage of Sensitive Information vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Senseway allows Retrieve Embedded Sensitive Data. This issue affects Senseway: through 09022026. NOTE: Because the product was developed using outdated technology, the manufacturer is unable to fix the relevant vulnerabilities. Users of the Sensaway application are advised to contact the manufacturer and review updated products developed with newer technology.

    Published: 9 Feb 2026
    7.3
    High

    CVE-2025-10463

    Last Modified: 5 Jun 2026

    Improper Authentication vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Senseway allows Authentication Abuse. This issue affects Senseway: through 09022026.  NOTE: Because the product was developed using outdated technology, the manufacturer is unable to fix the relevant vulnerabilities. Users of the Sensaway application are advised to contact the manufacturer and review updated products developed with newer technology.

    Published: 9 Feb 2026
    6.8
    Medium

    CVE-2025-7708

    Last Modified: 13 Aug 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in Atlas Educational Software Industry Ltd. Co. K12net allows Communication Channel Manipulation. This issue affects k12net: through 26072025.

    Published: 9 Feb 2026
    5.1
    Medium

    CVE-2026-1960

    Last Modified: 17 Apr 2026

    Stored Cross-Site Scripting (XSS) vulnerability in Loggro Pymes, via the 'Facebook' parameter in '/loggrodemo/jbrain/ConsultaTerceros' endpoint.

    Published: 9 Feb 2026
    5.1
    Medium

    CVE-2026-1959

    Last Modified: 17 Apr 2026

    Stored Cross-Site Scripting (XSS) vulnerability in Loggro Pymes, via the 'descripción' parameter in the '/loggrodemo/jbrain/MaestraCuentasBancarias' endpoint.

    Published: 9 Feb 2026
    5.4
    Medium

    CVE-2026-0632

    Last Modified: 15 Apr 2026

    The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.12 via the 'saveDataSource' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

    Published: 9 Feb 2026
    9.8
    Critical

    CVE-2025-6830

    Last Modified: 5 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpoda Türkiye Information Technology Inc. Password Module allows SQL Injection. This issue affects Password Module: through 11022026.

    Published: 9 Feb 2026
    9.1
    Critical

    CVE-2026-25848

    Last Modified: 18 Apr 2026

    In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible

    Published: 9 Feb 2026
    8.2
    High

    CVE-2026-25847

    Last Modified: 17 Apr 2026

    In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possible

    Published: 9 Feb 2026
    6.5
    Medium

    CVE-2026-25846

    Last Modified: 17 Apr 2026

    In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs

    Published: 9 Feb 2026
    6.5
    Medium

    CVE-2026-22922

    Last Modified: 17 Apr 2026

    Apache Airflow versions 3.1.0 through 3.1.6 contain an authorization flaw that can allow an authenticated user with custom permissions limited to task access to view task logs without having task log access. Users are recommended to upgrade to Apache Airflow 3.1.7 or later, which resolves this issue.

    Published: 9 Feb 2026
    6.5
    Medium

    CVE-2026-24098

    Last Modified: 16 Apr 2026

    Apache Airflow versions 3.0.0 - 3.1.7, has vulnerability that allows authenticated UI users with permission to one or more specific Dags to view import errors generated by other Dags they did not have access to. Users are advised to upgrade to 3.1.7 or later, which resolves this issue

    Published: 9 Feb 2026
    2
    Low

    CVE-2026-2227

    Last Modified: 18 Apr 2026

    A vulnerability was found in D-Link DCS-931L up to 1.13.0. Impacted is the function doSystem of the file /setSystemAdmin. Performing a manipulation of the argument AdminID results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 9 Feb 2026
    2
    Low

    CVE-2026-2226

    Last Modified: 17 Apr 2026

    A vulnerability has been found in DouPHP up to 1.9. This issue affects some unknown processing of the file /admin/file.php of the component ZIP File Handler. Such manipulation of the argument sql_filename leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 9 Feb 2026
    5.3
    Medium

    CVE-2026-23903

    Last Modified: 20 Aug 2026

    Authentication Bypass by Alternate Name vulnerability in Apache Shiro. This issue affects Apache Shiro: before 2.0.7. Users are recommended to upgrade to version 2.0.7, which fixes the issue. The issue only effects static files. If static files are served from a case-insensitive filesystem, such as default macOS setup, static files may be accessed by varying the case of the filename in the request. If only lower-case (common default) filters are present in Shiro, they may be bypassed this way. Shiro 2.1.0 and later has a new parameters to remediate this issue shiro.ini: filterChainResolver.caseInsensitive = true application.properties: shiro.caseInsensitive=true Shiro 3.0.0 and later makes this the default in shiro.ini-based configurations. Shiro 3.0.1 and later makes this the default in all configurations, including programmatic and Spring / Spring Boot.

    Published: 9 Feb 2026
    5.5
    Medium

    CVE-2026-2225

    Last Modified: 17 Apr 2026

    A flaw has been found in itsourcecode News Portal Project 1.0. This vulnerability affects unknown code of the file /admin/index.php of the component Administrator Login. This manipulation of the argument email causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.

    Published: 9 Feb 2026
    5.8
    Medium

    CVE-2026-25905

    Last Modified: 17 Apr 2026

    The Python code being run by 'runPython' or 'runPythonAsync' is not isolated from the rest of the JS code, allowing any Python code to use the Pyodide APIs to modify the JS environment. This may result in an attacker hijacking the MCP server - for malicious purposes including MCP tool shadowing. Note - the "mcp-run-python" project is archived and unlikely to receive a fix.

    Published: 9 Feb 2026
    5.8
    Medium

    CVE-2026-25904

    Last Modified: 18 Apr 2026

    The Pydantic-AI MCP Run Python tool configures the Deno sandbox with an overly permissive configuration that allows the underlying Python code to access the localhost interface of the host to perform SSRF attacks. Note - the "mcp-run-python" project is archived and unlikely to receive a fix.

    Published: 9 Feb 2026
    2
    Low

    CVE-2026-2224

    Last Modified: 18 Apr 2026

    A vulnerability was detected in code-projects Online Reviewer System 1.0. This affects an unknown part of the file /system/system/admins/manage/users/btn_functions.php. The manipulation of the argument firstname results in cross site scripting. It is possible to launch the attack remotely. The exploit is now public and may be used.

    Published: 9 Feb 2026
    4.3
    Medium

    CVE-2026-25916

    Last Modified: 18 Apr 2026

    Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.

    Published: 9 Feb 2026
    8.6
    High

    CVE-2025-7799

    Last Modified: 5 Jun 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zirve Information Technologies Inc. E-Taxpayer Accounting Website allows Reflected XSS. This issue affects e-Taxpayer Accounting Website: through 07082025.

    Published: 9 Feb 2026
    5.5
    Medium

    CVE-2026-2223

    Last Modified: 17 Apr 2026

    A security vulnerability has been detected in code-projects Online Reviewer System 1.0. Affected by this issue is some unknown functionality of the file /system/system/students/assessments/pretest/take/index.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.

    Published: 9 Feb 2026
    9.8
    Critical

    CVE-2026-22906

    Last Modified: 17 Apr 2026

    User credentials are stored using AES‑ECB encryption with a hardcoded key. An unauthenticated remote attacker obtaining the configuration file can decrypt and recover plaintext usernames and passwords, especially when combined with the authentication bypass.

    Published: 9 Feb 2026
    7.5
    High

    CVE-2026-22905

    Last Modified: 17 Apr 2026

    An unauthenticated remote attacker can bypass authentication by exploiting insufficient URI validation and using path traversal sequences (e.g., /js/../cgi-bin/post.cgi), gaining unauthorized access to protected CGI endpoints and configuration downloads.

    Published: 9 Feb 2026
    9.8
    Critical

    CVE-2026-22904

    Last Modified: 17 Apr 2026

    Improper length handling when parsing multiple cookie fields (including TRACKID) allows an unauthenticated remote attacker to send oversized cookie values and trigger a stack buffer overflow, resulting in a denial‑of‑service condition and possible remote code execution.

    Published: 9 Feb 2026
    9.8
    Critical

    CVE-2026-22903

    Last Modified: 17 Apr 2026

    An unauthenticated remote attacker can send a crafted HTTP request containing an overly long SESSIONID cookie. This can trigger a stack buffer overflow in the modified lighttpd server, causing it to crash and potentially enabling remote code execution due to missing stack protections.

    Published: 9 Feb 2026
    1.9
    Low

    CVE-2026-2222

    Last Modified: 17 Apr 2026

    A weakness has been identified in code-projects Online Reviewer System 1.0. Affected by this vulnerability is an unknown functionality of the file /system/system/admins/manage/users/btn_functions.php. Executing a manipulation of the argument firstname can lead to cross site scripting. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.

    Published: 9 Feb 2026
    8.7
    High

    CVE-2026-2236

    Last Modified: 18 Apr 2026

    C&Cm@il developed by HGiga has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

    Published: 9 Feb 2026
    7.1
    High

    CVE-2026-2235

    Last Modified: 17 Apr 2026

    C&Cm@il developed by HGiga has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.

    Published: 9 Feb 2026
    9.3
    Critical

    CVE-2026-2234

    Last Modified: 17 Apr 2026

    C&Cm@il developed by HGiga has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read and modify any user's mail content.

    Published: 9 Feb 2026
    2.8
    Low

    CVE-2026-2239

    Last Modified: 15 Apr 2026

    A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread_pascal_string function when processing a specially crafted PSD (Photoshop Document) file. This occurs because the buffer allocated for a Pascal string is not properly null-terminated, leading to an out-of-bounds read when strlen() is subsequently called. Successfully exploiting this vulnerability can cause the application to crash, resulting in an application level Denial of Service.

    Published: 9 Feb 2026
    5.5
    Medium

    CVE-2026-2221

    Last Modified: 17 Apr 2026

    A security flaw has been discovered in code-projects Online Reviewer System 1.0. Affected is an unknown function of the file /login/index.php of the component Login. Performing a manipulation of the argument Username results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.

    Published: 9 Feb 2026
    8.4
    High

    CVE-2026-24466

    Last Modified: 17 Apr 2026

    Products provided by Oki Electric Industry Co., Ltd. and its OEM products (Ricoh Co., Ltd., Murata Machinery, Ltd.) register Windows services with unquoted file paths. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.

    Published: 9 Feb 2026
    9.9
    Critical

    CVE-2026-1868

    Last Modified: 17 Apr 2026

    GitLab has remediated a vulnerability in the Duo Workflow Service component of GitLab AI Gateway affecting all versions of the AI Gateway from 18.1.6, 18.2.6, 18.3.1 to 18.6.1, 18.7.0, and 18.8.0 in which AI Gateway was vulnerable to insecure template expansion of user supplied data via crafted Duo Agent Platform Flow definitions. This vulnerability could be used to cause Denial of Service or gain code execution on the Gateway. This has been fixed in versions 18.6.2, 18.7.1, and 18.8.1 of the GitLab AI Gateway.

    Published: 9 Feb 2026
    5.5
    Medium

    CVE-2026-2220

    Last Modified: 18 Apr 2026

    A vulnerability was identified in code-projects Online Reviewer System 1.0. This impacts an unknown function of the file /system/system/admins/assessments/pretest/btn_functions.php. Such manipulation of the argument difficulty_id leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.

    Published: 9 Feb 2026
    8.5
    High

    CVE-2026-0870

    Last Modified: 17 Apr 2026

    MacroHub developed by GIGABYTE has a Local Privilege Escalation vulnerability. Due to the MacroHub application launching external applications with improper privileges, allowing authenticated local attackers to execute arbitrary code with SYSTEM privileges.

    Published: 9 Feb 2026
    2.1
    Low

    CVE-2026-2218

    Last Modified: 18 Apr 2026

    A vulnerability was determined in D-Link DCS-933L up to 1.14.11. This affects an unknown function of the file /setSystemAdmin of the component alphapd. This manipulation of the argument AdminID causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 9 Feb 2026
    5.7
    Medium

    CVE-2026-22613

    Last Modified: 18 Apr 2026

    The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacker to perform a Man-in-the-middle attack. This security issue has been fixed in the latest firmware version of Eaton Network M3 which is available on the Eaton download center.

    Published: 9 Feb 2026
    5.5
    Medium

    CVE-2026-2217

    Last Modified: 18 Apr 2026

    A vulnerability was found in itsourcecode Event Management System 1.0. The impacted element is an unknown function of the file /admin/manage_user.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.

    Published: 9 Feb 2026
    2.1
    Low

    CVE-2026-2216

    Last Modified: 17 Apr 2026

    A flaw has been found in rachelos WeRSS we-mp-rss up to 1.4.8. Impacted is the function download_export_file of the file apis/tools.py. Executing a manipulation of the argument filename can lead to path traversal. The attack can be launched remotely. The exploit has been published and may be used.

    Published: 9 Feb 2026
    8.2
    High

    CVE-2026-1615

    Last Modified: 25 Aug 2026

    Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. The library relies on the static-eval module to process JSON Path input, which is not designed to handle untrusted data safely. An attacker can exploit this vulnerability by supplying a malicious JSON Path expression that, when evaluated, executes arbitrary JavaScript code, leading to Remote Code Execution in Node.js environments or Cross-site Scripting (XSS) in browser contexts. This affects all methods that evaluate JSON Paths against objects, including .query, .nodes, .paths, .value, .parent, and .apply.

    Published: 9 Feb 2026