CVE Feed

    Dashboard / CVE

    6.4
    Medium

    CVE-2026-1909

    Last Modified: 16 Apr 2026

    The WaveSurfer-WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's audio shortcode in all versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping on the 'src' attribute. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 6 Feb 2026
    5.3
    Medium

    CVE-2025-10753

    Last Modified: 22 Apr 2026

    The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 6.26.14. This is due to missing capability checks and authentication verification on the OAuth redirect functionality accessible via the 'oauthredirect' option parameter. This makes it possible for unauthenticated attackers to set the global redirect URL option via the redirect_url parameter granted they can access the site directly.

    Published: 6 Feb 2026
    6.4
    Medium

    CVE-2026-1808

    Last Modified: 15 Apr 2026

    The Orange Confort+ accessibility toolbar for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' parameter of the ocplus_button shortcode in all versions up to, and including, 0.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 6 Feb 2026
    6.4
    Medium

    CVE-2026-1888

    Last Modified: 15 Apr 2026

    The Docus – YouTube Video Playlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'docusplaylist' shortcode in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 6 Feb 2026
    2
    Low

    CVE-2026-2000

    Last Modified: 18 Apr 2026

    A vulnerability was found in DCN DCME-320 up to 20260121. Impacted is the function apply_config of the file /function/system/basic/bridge_cfg.php of the component Web Management Backend. Performing a manipulation of the argument ip_list results in command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 6 Feb 2026
    5.6
    Medium

    CVE-2026-0521

    Last Modified: 18 Apr 2026

    A reflected cross-site scripting (XSS) vulnerability in the PDF export functionality of the TYDAC AG MAP+ solution allows unauthenticated attackers to craft a malicious URL, that if visited by a victim, will execute arbitrary JavaScript in the victim's context. Such a URL could be delivered through various means, for instance, by sending a link or by tricking victims to visit a page crafted by the attacker. This issue was verified in MAP+: 3.4.0.

    Published: 6 Feb 2026
    1.9
    Low

    CVE-2026-1998

    Last Modified: 18 Apr 2026

    A flaw has been found in micropython up to 1.27.0. This vulnerability affects the function mp_import_all of the file py/runtime.c. This manipulation causes memory corruption. The attack needs to be launched locally. The exploit has been published and may be used. Patch name: 570744d06c5ba9dba59b4c3f432ca4f0abd396b6. It is suggested to install a patch to address this issue.

    Published: 6 Feb 2026
    1.9
    Low

    CVE-2026-1991

    Last Modified: 18 Apr 2026

    A vulnerability was detected in libuvc up to 0.0.7. Affected is the function uvc_scan_streaming of the file src/device.c of the component UVC Descriptor Handler. The manipulation results in null pointer dereference. The attack needs to be approached locally. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 6 Feb 2026
    1.9
    Low

    CVE-2026-1990

    Last Modified: 17 Apr 2026

    A security vulnerability has been detected in oatpp up to 1.3.1. This impacts the function oatpp::data::type::ObjectWrapper::ObjectWrapper of the file src/oatpp/data/type/Type.hpp. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 6 Feb 2026
    1.9
    Low

    CVE-2026-1979

    Last Modified: 18 Apr 2026

    A flaw has been found in mruby up to 3.4.0. This affects the function mrb_vm_exec of the file src/vm.c of the component JMPNOT-to-JMPIF Optimization. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been published and may be used. This patch is called e50f15c1c6e131fa7934355eb02b8173b13df415. It is advisable to implement a patch to correct this issue.

    Published: 6 Feb 2026
    5.5
    Medium

    CVE-2026-1978

    Last Modified: 18 Apr 2026

    A vulnerability was detected in kalyan02 NanoCMS up to 0.4. Affected by this issue is some unknown functionality of the file /data/pagesdata.txt of the component User Information Handler. Performing a manipulation results in direct request. It is possible to initiate the attack remotely. The exploit is now public and may be used. You should change the configuration settings.

    Published: 6 Feb 2026
    2.1
    Low

    CVE-2026-1977

    Last Modified: 17 Apr 2026

    A security vulnerability has been detected in isaacwasserman mcp-vegalite-server up to 16aefed598b8cd897b78e99b907f6e2984572c61. Affected by this vulnerability is the function eval of the component visualize_data. Such manipulation of the argument vegalite_specification leads to code injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 6 Feb 2026
    8.8
    High

    CVE-2025-15566

    Last Modified: 15 Apr 2026

    A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-proxy-set-headers` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

    Published: 6 Feb 2026
    5.5
    Medium

    CVE-2026-1976

    Last Modified: 17 Apr 2026

    A weakness has been identified in Free5GC up to 4.1.0. Affected is the function SessionDeletionResponse of the component SMF. This manipulation causes null pointer dereference. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. It is suggested to install a patch to address this issue.

    Published: 6 Feb 2026
    5.5
    Medium

    CVE-2026-1975

    Last Modified: 18 Apr 2026

    A security flaw has been discovered in Free5GC up to 4.1.0. This impacts the function identityTriggerType of the file pfcp_reports.go. The manipulation results in null pointer dereference. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. Applying a patch is advised to resolve this issue.

    Published: 6 Feb 2026
    4.3
    Medium

    CVE-2026-1228

    Last Modified: 15 Apr 2026

    The Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.3 via the tlgb_shortcode() function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, to disclose private timeline content via the id attribute supplied to the 'timeline_block' shortcode.

    Published: 6 Feb 2026
    5.5
    Medium

    CVE-2026-1974

    Last Modified: 17 Apr 2026

    A vulnerability was identified in Free5GC up to 4.1.0. This affects the function ResolveNodeIdToIp of the file internal/sbi/processor/datapath.go of the component SMF. The manipulation leads to denial of service. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. It is recommended to apply a patch to fix this issue.

    Published: 6 Feb 2026
    5.5
    Medium

    CVE-2026-1973

    Last Modified: 17 Apr 2026

    A vulnerability was determined in Free5GC up to 4.1.0. The impacted element is the function establishPfcpSession of the component SMF. Executing a manipulation can lead to null pointer dereference. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. It is best practice to apply a patch to resolve this issue.

    Published: 6 Feb 2026
    5.5
    Medium

    CVE-2026-1972

    Last Modified: 17 Apr 2026

    A vulnerability was found in Edimax BR-6208AC 2_1.02. The affected element is the function auth_check_userpass2. Performing a manipulation of the argument Username/Password results in use of default credentials. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor confirms that the affected product is end-of-life. They confirm that they "will issue a consolidated Security Advisory on our official support website." This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 6 Feb 2026
    1.9
    Low

    CVE-2026-1971

    Last Modified: 17 Apr 2026

    A vulnerability has been found in Edimax BR-6288ACL up to 1.12. Impacted is the function wiz_WISP24gmanual of the file wiz_WISP24gmanual.asp. Such manipulation of the argument manualssid leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor confirms that the affected product is end-of-life. They confirm that they "will issue a consolidated Security Advisory on our official support website." This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 6 Feb 2026
    4.2
    Medium

    CVE-2026-0598

    Last Modified: 4 May 2026

    A security flaw was identified in the Ansible Lightspeed API conversation endpoints that handle AI chat interactions. The APIs do not properly verify whether a conversation identifier belongs to the authenticated user making the request. As a result, an attacker with valid credentials could access or influence conversations owned by other users. This exposes sensitive conversation data and allows unauthorized manipulation of AI-generated outputs.

    Published: 6 Feb 2026
    7.6
    High

    CVE-2025-70963

    Last Modified: 10 Feb 2026

    Gophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived API key directly inside the rendered HTML/JavaScript of the page on every login. This makes permanent API credentials accessible to any script running in the browser context.

    Published: 6 Feb 2026
    5.3
    Medium

    CVE-2026-23623

    Last Modified: 17 Apr 2026

    Collabora Online is a collaborative online office suite based on LibreOffice technology. Prior to Collabora Online Development Edition version 25.04.08.2 and prior to Collabora Online versions 23.05.20.1, 24.04.17.3, and 25.04.7.5, a user with view-only rights and no download privileges can obtain a local copy of a shared file. Although there are no corresponding buttons in the interface, pressing Ctrl+Shift+S initiates the file download process. This allows the user to bypass the access restrictions and leads to unauthorized data retrieval. This issue has been patched in Collabora Online Development Edition version 25.04.08.2 and Collabora Online versions 23.05.20.1, 24.04.17.3, and 25.04.7.5.

    Published: 5 Feb 2026
    3.7
    Low

    CVE-2025-68157

    Last Modified: 13 Feb 2026

    Webpack is a module bundler. From version 5.49.0 to before 5.104.0, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) enforces allowedUris only for the initial URL, but does not re-validate allowedUris after following HTTP 30x redirects. As a result, an import that appears restricted to a trusted allow-list can be redirected to HTTP(S) URLs outside the allow-list. This is a policy/allow-list bypass that enables build-time SSRF behavior (requests from the build machine to internal-only endpoints, depending on network access) and untrusted content inclusion in build outputs (redirected content is treated as module source and bundled). This issue has been patched in version 5.104.0.

    Published: 5 Feb 2026
    3.7
    Low

    CVE-2025-68458

    Last Modified: 13 Feb 2026

    Webpack is a module bundler. From version 5.49.0 to before 5.104.1, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) can be bypassed to fetch resources from hosts outside allowedUris by using crafted URLs that include userinfo (username:password@host). If allowedUris enforcement relies on a raw string prefix check (e.g., uri.startsWith(allowed)), a URL that looks allow-listed can pass validation while the actual network request is sent to a different authority/host after URL parsing. This is a policy/allow-list bypass that enables build-time SSRF behavior (outbound requests from the build machine to internal-only endpoints, depending on network access) and untrusted content inclusion (the fetched response is treated as module source and bundled). This issue has been patched in version 5.104.1.

    Published: 5 Feb 2026
    8.7
    High

    CVE-2025-32393

    Last Modified: 17 Feb 2026

    AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6.32, there is a DoS vulnerability in ReadRSSFeedBlock. In RSSBlock, feedparser.parser is called to obtain the XML file according to the URL input by the user, parse the XML, and finally obtain the parsed result. However, during the parsing process, there is no limit on the parsing time and the resources that can be allocated for parsing. When a malicious user lets RSSBlock parse a carefully constructed, deep XML, it will cause memory resources to be exhausted, eventually causing DoS. This issue has been patched in autogpt-platform-beta-v0.6.32.

    Published: 5 Feb 2026
    6.5
    Medium

    CVE-2026-0391

    Last Modified: 15 Apr 2026

    User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.

    Published: 5 Feb 2026
    9.8
    Critical

    CVE-2026-24300

    Last Modified: 15 Apr 2026

    Azure Front Door Elevation of Privilege Vulnerability

    Published: 5 Feb 2026
    8.2
    High

    CVE-2026-21532

    Last Modified: 15 Apr 2026

    Azure Function Information Disclosure Vulnerability

    Published: 5 Feb 2026
    8.6
    High

    CVE-2026-24302

    Last Modified: 15 Apr 2026

    Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

    Published: 5 Feb 2026
    2
    Low

    CVE-2026-1970

    Last Modified: 17 Apr 2026

    A flaw has been found in Edimax BR-6258n up to 1.18. This issue affects the function formStaDrvSetup of the file /goform/formStaDrvSetup. This manipulation of the argument submit-url causes open redirect. The attack can be initiated remotely. The exploit has been published and may be used. The vendor confirms that the affected product is end-of-life. They confirm that they "will issue a consolidated Security Advisory on our official support website." This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 5 Feb 2026
    5.3
    Medium

    CVE-2026-1964

    Last Modified: 17 Apr 2026

    A vulnerability was determined in WeKan up to 8.20. This impacts an unknown function of the file models/boards.js of the component REST Endpoint. This manipulation causes improper access controls. Remote exploitation of the attack is possible. Upgrading to version 8.21 will fix this issue. Patch name: 545566f5663545d16174e0f2399f231aa693ab6e. It is advisable to upgrade the affected component.

    Published: 5 Feb 2026
    3.2
    Low

    CVE-2026-25815

    Last Modified: 17 Apr 2026

    Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exploited in the wild from 2025-12-16 through 2026 (by default, the encryption key is the same across all customers' installations). NOTE: the Supplier's position is that the instance of CWE-1394 is not a vulnerability because customers "are supposed to enable" a non-default option that eliminates the weakness. However, that non-default option can disrupt functionality as shown in the "Managing FortiGates with private data encryption" document, and is therefore intentionally not a default option.

    Published: 5 Feb 2026
    5.3
    Medium

    CVE-2026-1963

    Last Modified: 17 Apr 2026

    A vulnerability was found in WeKan up to 8.20. This affects an unknown function of the file models/attachments.js of the component Attachment Storage. The manipulation results in improper access controls. The attack may be launched remotely. Upgrading to version 8.21 mitigates this issue. The patch is identified as c413a7e860bc4d93fe2adcf82516228570bf382d. Upgrading the affected component is advised.

    Published: 5 Feb 2026
    5.3
    Medium

    CVE-2026-1962

    Last Modified: 17 Apr 2026

    A vulnerability has been found in WeKan up to 8.20. The impacted element is an unknown function of the file server/attachmentMigration.js of the component Attachment Migration. The manipulation leads to improper access controls. The attack may be initiated remotely. Upgrading to version 8.21 is sufficient to resolve this issue. The identifier of the patch is 053bf1dfb76ef230db162c64a6ed50ebedf67eee. It is recommended to upgrade the affected component.

    Published: 5 Feb 2026
    9.3
    Critical

    CVE-2026-0106

    Last Modified: 17 Apr 2026

    In vpu_mmap of vpu_ioctl, there is a possible arbitrary address mmap due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 5 Feb 2026
    5.3
    Medium

    CVE-2025-12131

    Last Modified: 12 Feb 2026

    A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service.

    Published: 5 Feb 2026
    6.8
    Medium

    CVE-2026-1301

    Last Modified: 18 Apr 2026

    In builds with PubSub and JSON enabled, a crafted JSON message can cause the decoder to write beyond a heap-allocated array before authentication, reliably crashing the process and corrupting memory.

    Published: 5 Feb 2026
    7.8
    High

    CVE-2025-15311

    Last Modified: 10 Feb 2026

    Tanium addressed an unauthorized code execution vulnerability in Tanium Appliance.

    Published: 5 Feb 2026
    6.6
    Medium

    CVE-2025-15312

    Last Modified: 10 Feb 2026

    Tanium addressed an improper output sanitization vulnerability in Tanium Appliance.

    Published: 5 Feb 2026
    6.6
    Medium

    CVE-2025-15324

    Last Modified: 10 Feb 2026

    Tanium addressed a documentation issue in Engage.

    Published: 5 Feb 2026
    6.3
    Medium

    CVE-2025-15325

    Last Modified: 10 Feb 2026

    Tanium addressed an improper input validation vulnerability in Discover.

    Published: 5 Feb 2026
    4.3
    Medium

    CVE-2025-15326

    Last Modified: 10 Feb 2026

    Tanium addressed an improper access controls vulnerability in Patch.

    Published: 5 Feb 2026
    4.3
    Medium

    CVE-2025-15327

    Last Modified: 10 Feb 2026

    Tanium addressed an improper access controls vulnerability in Deploy.

    Published: 5 Feb 2026
    5
    Medium

    CVE-2025-15328

    Last Modified: 10 Feb 2026

    Tanium addressed an improper link resolution before file access vulnerability in Enforce.

    Published: 5 Feb 2026
    8.8
    High

    CVE-2025-15330

    Last Modified: 10 Feb 2026

    Tanium addressed an improper input validation vulnerability in Deploy.

    Published: 5 Feb 2026
    4.3
    Medium

    CVE-2025-15331

    Last Modified: 10 Feb 2026

    Tanium addressed an uncontrolled resource consumption vulnerability in Connect.

    Published: 5 Feb 2026
    4.9
    Medium

    CVE-2025-15329

    Last Modified: 10 Feb 2026

    Tanium addressed an information disclosure vulnerability in Threat Response.

    Published: 5 Feb 2026
    4.9
    Medium

    CVE-2025-15332

    Last Modified: 10 Feb 2026

    Tanium addressed an information disclosure vulnerability in Threat Response.

    Published: 5 Feb 2026
    2.7
    Low

    CVE-2025-15321

    Last Modified: 10 Feb 2026

    Tanium addressed an improper input validation vulnerability in Tanium Appliance.

    Published: 5 Feb 2026