Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2024-48928 — Piwigo's secret key can be brute forced

Piwigo is an open source photo gallery application for the web. In versions on the 14.x branch, when installing, the secret_key configuration parameter is set to MD5(RAND()) in MySQL. However, RAND()…

piwigo | Remote | Cross-Site Request Forgery
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
7.5 HIGH
CVE-2026-27521 — Binardat 10G08-0800GSM Network Switch Missing Login Rate Limiting

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior do not implement rate limiting or account lockout on failed login attempts, enabling brute-force attacks against user c…

10g08-0800gsm_firmware 10g08-0800gsm | Remote | Authentication
Feb 24, 2026 Mar 02, 2026
Feb 24, 2026
Mar 02, 2026
8.7 HIGH
CVE-2026-27520 — Binardat 10G08-0800GSM Network Switch Base64-encoded Password Stored in Cookie

Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 store a user password in a client-side cookie as a Base64-encoded value accessible via the web interface. Because Base6…

10g08-0800gsm_firmware 10g08-0800gsm | Remote | Information Disclosure
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
8.7 HIGH
CVE-2026-27519 — Binardat 10G08-0800GSM Network Switch Hard-coded RC4 Encryption Key

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior use RC4 with a hard-coded key embedded in client-side JavaScript. Because the key is static and exposed, an attacker ca…

10g08-0800gsm_firmware 10g08-0800gsm | Remote | Cryptography
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
5.1 MEDIUM
CVE-2026-27518 — Binardat 10G08-0800GSM Network Switch CSRF

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior lack CSRF protections for state-changing actions in the administrative interface. An attacker can trick an authenticate…

10g08-0800gsm_firmware 10g08-0800gsm | Remote | Cross-Site Request Forgery
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
6.1 MEDIUM
CVE-2026-27517 — Binardat 10G08-0800GSM Network Switch XSS

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior reflect unsanitized user input in the web interface, allowing an attacker to inject and execute arbitrary JavaScript in…

10g08-0800gsm_firmware 10g08-0800gsm | Remote | Cross-Site Scripting
Feb 24, 2026 Mar 02, 2026
Feb 24, 2026
Mar 02, 2026
8.6 HIGH
CVE-2026-27516 — Binardat 10G08-0800GSM Network Switch Plaintext Password Exposure

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior expose user passwords in plaintext within the administrative interface and HTTP responses, allowing recovery of valid c…

10g08-0800gsm_firmware 10g08-0800gsm | Remote | Information Disclosure
Feb 24, 2026 Mar 02, 2026
Feb 24, 2026
Mar 02, 2026
9.3 CRITICAL
CVE-2026-27515 — Binardat 10G08-0800GSM Network Switch Predictable Session Identifiers

Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 generate predictable numeric session identifiers in the web management interface. An attacker can guess valid session I…

10g08-0800gsm_firmware 10g08-0800gsm | Remote | Authentication
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
9.8 CRITICAL
CVE-2026-27507 — Binardat 10G08-0800GSM Network Switch Hard-coded Credentials

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain hard-coded administrative credentials that cannot be changed by users. Knowledge of these credentials allows fu…

10g08-0800gsm_firmware 10g08-0800gsm | Remote | Authentication
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
8.8 HIGH
CVE-2026-23678 — Binardat 10G08-0800GSM Network Switch Traceroute CLI Command Injection

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain a command injection vulnerability in the traceroute diagnostic function of the affected device web management i…

10g08-0800gsm_firmware 10g08-0800gsm | Remote | Injection
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
9.8 CRITICAL
CVE-2025-69985 — FUXA JWT Referer Header Bypass RCE

FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, which improperly trus…

fuxa | Remote | Authentication
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
8.8 HIGH
CVE-2025-63409 — GCOM EPON 1GE C00R371V00B01 Privilege Escalation and Improper Access Control Vulnerability

Privilege escalation and improper access control in GCOM EPON 1GE C00R371V00B01 allows remote authenticated users to modify administrator only settings and extract administrator credentials.

gcom_epon_1ge_firmware gcom_epon_1ge | Remote | Authorization
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
5.7 MEDIUM
CVE-2025-47904 — Unsigned upgrade package

Download of Code Without Integrity Check vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.

Feb 24, 2026 Mar 03, 2026
Feb 24, 2026
Mar 03, 2026
8.8 HIGH
CVE-2026-3102 — exiftool PNG File MacOS.pm SetMacOSTags os command injection

A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function SetMacOSTags of the file lib/Image/ExifTool/MacOS.pm of the component PNG File Parser. This manipulati…

macos exiftool | Remote
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
8.8 HIGH
CVE-2026-3101 — Intelbras TIP 635G Ping os command injection

A vulnerability was found in Intelbras TIP 635G 1.12.3.5. This vulnerability affects unknown code of the component Ping Handler. The manipulation results in os command injection. The attack can be ex…

tip_635g_firmware tip_635g | Remote | Injection
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
8.6 HIGH
CVE-2026-27732 — AVideo has Authenticated Server-Side Request Forgery via downloadURL in aVideoEncoder.jso…

WWBN AVideo is an open source video platform. Prior to version 22.0, the `aVideoEncoder.json.php` API endpoint accepts a `downloadURL` parameter and fetches the referenced resource server-side withou…

avideo | Remote | Server-Side Request Forgery
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
9.2 CRITICAL
CVE-2026-27584 — ActualBudget server is Missing Authentication for SimpleFIN and Pluggy AI bank sync endpo…

Actual is a local-first personal finance tool. Prior to version 26.2.1, missing authentication middleware in the ActualBudget server component allows any unauthenticated user to query the SimpleFIN a…

actual | Remote | Authentication
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
6.1 MEDIUM
CVE-2026-27568 — AVideo has Stored Cross-Site Scripting via Markdown Comment Injection

WWBN AVideo is an open source video platform. Prior to version 21.0, AVideo allows Markdown in video comments and uses Parsedown (v1.7.4) without Safe Mode enabled. Markdown links are not sufficientl…

avideo | Remote | Cross-Site Scripting
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
6.5 MEDIUM
CVE-2026-27567 — Payload has Server-Side Request Forgery (SSRF) in External File URL Uploads

Payload is a free and open source headless content management system. Prior to 3.75.0, a Server-Side Request Forgery (SSRF) vulnerability exists in Payload's external file upload functionality. When …

payload | Remote | Server-Side Request Forgery
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
8.8 HIGH
CVE-2026-27483 — MindsDB has Path Traversal in /api/files Leading to Remote Code Execution

MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.9.1.1, there is a path traversal vulnerability in Mindsdb's /api/files interface, which an authent…

mindsdb | Remote | Path Traversal
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
Showing 20 of 5307 Results