Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.3 CRITICAL
CVE-2026-24834 — Kata Container to Guest micro VM privilege escalation

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 3.27.0, an issue in Kata with …

kata_containers | Authentication
Feb 19, 2026 Feb 23, 2026
Feb 19, 2026
Feb 23, 2026
7.5 HIGH
CVE-2026-1581 — wpForo Forum <= 2.4.14 - Unauthenticated Time-Based SQL Injection

The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all versions up to, and including, 2.4.14 due to insufficient escaping on the user supplie…

wpforo_forum | Remote | Injection
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
4.7 MEDIUM
CVE-2025-69725 — Chi Open Redirect Vulnerability

An Open Redirect vulnerability in the go-chi/chi >=5.2.2 RedirectSlashes function allows remote attackers to redirect victim users to malicious websites using the legitimate website domain.

Remote | Misconfiguration
Feb 19, 2026 Feb 23, 2026
Feb 19, 2026
Feb 23, 2026
9.8 CRITICAL
CVE-2025-69674 — CDATA FD614GS3-R850 Buffer Overflow Arbitrary Code Execution

Buffer Overflow vulnerability in CDATA FD614GS3-R850 V3.2.7_P161006 (Build.0333.250211) allows an attacker to execute arbitrary code via the node_mac, node_opt, opt_param, and domainblk parameters of…

Remote | Memory Corruption
Feb 19, 2026 Feb 25, 2026
Feb 19, 2026
Feb 25, 2026
8.5 HIGH
CVE-2026-2274 — Arbitrary File Read and SSRF in Google AppSheet

A SSRF and Arbitrary File Read vulnerability in AppSheet Core in Google AppSheet prior to 2025-11-23 allows an authenticated remote attacker to read sensitive local files and access internal network …

Remote | Server-Side Request Forgery
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
8.6 HIGH
CVE-2026-26345 — SPIP < 4.4.8 Cross-Site Scripting in Public Area

SPIP before 4.4.8 contains a stored cross-site scripting (XSS) vulnerability in the public area triggered in certain edge-case usage patterns. The echapper_html_suspect() function does not adequately…

spip | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 24, 2026
Feb 19, 2026
Feb 24, 2026
6.1 MEDIUM
CVE-2026-26223 — SPIP < 4.4.8 Cross-Site Scripting via Iframe Tags in Private Area

SPIP before 4.4.8 allows cross-site scripting (XSS) in the private area via malicious iframe tags. The application does not properly sandbox or escape iframe content in the back-office, allowing an a…

spip | Remote | Cross-Site Scripting
Feb 19, 2026 Mar 02, 2026
Feb 19, 2026
Mar 02, 2026
8.1 HIGH
CVE-2026-25940 — jsPDF's PDF Injection in AcroForm module allows Arbitrary JavaScript Execution (RadioButt…

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actio…

jspdf | Remote | Injection
Feb 19, 2026 Feb 23, 2026
Feb 19, 2026
Feb 23, 2026
5.3 MEDIUM
CVE-2026-25766 — Echo has a Windows path traversal via backslash in middleware.Static default filesystem

Echo is a Go web framework. In versions 5.0.0 through 5.0.2 on Windows, Echo’s `middleware.Static` using the default filesystem allows path traversal via backslashes, enabling unauthenticated remote …

windows echo | Remote | Path Traversal
Feb 19, 2026 Feb 23, 2026
Feb 19, 2026
Feb 23, 2026
5.4 MEDIUM
CVE-2026-25739 — Indico affected by Cross-Site-Scripting via material uploads

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Versions prior to 3.3.10 are vulnerable to cross-site scripting when uploading certain…

indico | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 26, 2026
Feb 19, 2026
Feb 26, 2026
6.9 MEDIUM
CVE-2026-25738 — Indico has Server-Side Request Forgery (SSRF) in multiple places

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Versions prior to 3.3.10 are vulnerable to server-side request forgery. Indico makes o…

indico | Remote | Server-Side Request Forgery
Feb 19, 2026 Feb 26, 2026
Feb 19, 2026
Feb 26, 2026
6.1 MEDIUM
CVE-2025-71244 — SPIP < 4.4.5 Open Redirect via Login Form

SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a malicious URL that, when visited by a victim, redirects them to an arbitrary ext…

spip | Remote | Misconfiguration
Feb 19, 2026 Feb 24, 2026
Feb 19, 2026
Feb 24, 2026
9.8 CRITICAL
CVE-2025-71243 — SPIP Saisies Plugin < 5.11.1 Remote Code Execution

The 'Saisies pour formulaire' (Saisies) plugin for SPIP versions 5.4.0 through 5.11.0 contains a critical Remote Code Execution (RCE) vulnerability. An attacker can exploit this vulnerability to exec…

saisies_pour_formulaire saisies | Remote | Injection
Feb 19, 2026 Feb 26, 2026
Feb 19, 2026
Feb 26, 2026
6.5 MEDIUM
CVE-2025-71242 — SPIP < 4.3.6 Authorization Bypass Leading to Content Disclosure

SPIP before 4.3.6, 4.2.17, and 4.1.20 allows unauthorized content disclosure in the private area. The application does not properly check authorization when displaying content of articles and section…

spip | Remote | Authorization
Feb 19, 2026 Mar 02, 2026
Feb 19, 2026
Mar 02, 2026
6.1 MEDIUM
CVE-2025-71241 — SPIP < 4.3.6 Cross-Site Scripting in Private Area

SPIP before 4.3.6, 4.2.17, and 4.1.20 allows Cross-Site Scripting (XSS) in the private area. The content of the error message displayed by the 'transmettre' API is not properly sanitized, allowing an…

spip | Remote | Cross-Site Scripting
Feb 19, 2026 Mar 02, 2026
Feb 19, 2026
Mar 02, 2026
5.4 MEDIUM
CVE-2025-71240 — SPIP < 4.2.15 Cross-Site Scripting via Code Tags

SPIP before 4.2.15 allows Cross-Site Scripting (XSS) via crafted content in HTML code tags. The application does not properly verify JavaScript within code tags, allowing an attacker to inject malici…

spip | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 24, 2026
Feb 19, 2026
Feb 24, 2026
8.8 HIGH
CVE-2026-25755 — jsPDF has PDF Object Injection via Unsanitized Input in addJS Method

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the argument of the `addJS` method allows an attacker to inject arbitrary PDF objects into the generated document. B…

jspdf | Remote | Injection
Feb 19, 2026 Feb 23, 2026
Feb 19, 2026
Feb 23, 2026
8.7 HIGH
CVE-2026-25535 — jsPDF Affected by Client-Side/Server-Side Denial of Service via Malicious GIF Dimensions

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the first argument of the `addImage` method results in denial of service. If given the possibility to pass unsanitiz…

jspdf | Remote | Denial of Service
Feb 19, 2026 Feb 23, 2026
Feb 19, 2026
Feb 23, 2026
5.3 MEDIUM
CVE-2026-25527 — changedetection.io vulnerable to unauthenticated static path traversal

changedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the `/static/<group>/<filename>` route accepts `group=".."`, which causes `send_from_directory("s…

changedetection changedetection | Remote | Path Traversal
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
9.1 CRITICAL
CVE-2025-55853 — SoftVision webPDF SSRF Vulnerability

SoftVision webPDF before 10.0.2 is vulnerable to Server-Side Request Forgery (SSRF). The PDF converter function does not check if internal or external resources are requested in the uploaded files an…

Remote | Server-Side Request Forgery
Feb 19, 2026 Feb 23, 2026
Feb 19, 2026
Feb 23, 2026
Showing 20 of 5069 Results