Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-25998 — strongMan vulnerable to private credential recovery due to key and counter reuse

strongMan is a management interface for strongSwan, an OpenSource IPsec-based VPN. When storing credentials in the database (private keys, EAP secrets), strongMan encrypts the corresponding database …

strongman | Remote | Cryptography
Feb 19, 2026 Feb 23, 2026
Feb 19, 2026
Feb 23, 2026
9.3 CRITICAL
CVE-2026-24834 — Kata Container to Guest micro VM privilege escalation

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 3.27.0, an issue in Kata with …

kata_containers | Authentication
Feb 19, 2026 Feb 23, 2026
Feb 19, 2026
Feb 23, 2026
7.5 HIGH
CVE-2026-1581 — wpForo Forum <= 2.4.14 - Unauthenticated Time-Based SQL Injection

The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all versions up to, and including, 2.4.14 due to insufficient escaping on the user supplie…

wpforo_forum | Remote | Injection
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
4.7 MEDIUM
CVE-2025-69725 — Chi Open Redirect Vulnerability

An Open Redirect vulnerability in the go-chi/chi >=5.2.2 RedirectSlashes function allows remote attackers to redirect victim users to malicious websites using the legitimate website domain.

Remote | Misconfiguration
Feb 19, 2026 Feb 23, 2026
Feb 19, 2026
Feb 23, 2026
9.8 CRITICAL
CVE-2025-69674 — CDATA FD614GS3-R850 Buffer Overflow Arbitrary Code Execution

Buffer Overflow vulnerability in CDATA FD614GS3-R850 V3.2.7_P161006 (Build.0333.250211) allows an attacker to execute arbitrary code via the node_mac, node_opt, opt_param, and domainblk parameters of…

Remote | Memory Corruption
Feb 19, 2026 Feb 25, 2026
Feb 19, 2026
Feb 25, 2026
Showing 20 of 5585 Results