Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.8 MEDIUM
CVE-2026-0947 — AT Internet Piano Analytics - Moderately critical - Cross-site Scripting - SA-CONTRIB-202…

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AT Internet Piano Analytics allows Cross-Site Scripting (XSS).This issue affects AT Intern…

at_internet_piano_analytics | Remote | Cross-Site Scripting
Feb 04, 2026 Feb 11, 2026
Feb 04, 2026
Feb 11, 2026
6.1 MEDIUM
CVE-2026-0946 — AT Internet SmartTag - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-003

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AT Internet SmartTag allows Cross-Site Scripting (XSS).This issue affects AT Internet Smar…

at_internet_smarttag | Remote | Cross-Site Scripting
Feb 04, 2026 Feb 11, 2026
Feb 04, 2026
Feb 11, 2026
5.4 MEDIUM
CVE-2026-0945 — Role Delegation - Moderately critical - Access bypass - SA-CONTRIB-2026-002

Privilege Defined With Unsafe Actions vulnerability in Drupal Role Delegation allows Privilege Escalation.This issue affects Role Delegation: from 1.3.0 before 1.5.0.

Remote | Authorization
Feb 04, 2026 Feb 12, 2026
Feb 04, 2026
Feb 12, 2026
5.3 MEDIUM
CVE-2026-0944 — Group invite - Moderately critical - Access bypass - SA-CONTRIB-2026-001

Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Group invite allows Forceful Browsing.This issue affects Group invite: from 0.0.0 before 2.3.9, from 3.0.0 before 3.0.4, f…

group_invite | Remote | Authorization
Feb 04, 2026 Feb 11, 2026
Feb 04, 2026
Feb 11, 2026
3.5 LOW
CVE-2025-2134 — IBM Jazz Reporting Service Denial of Service

IBM Jazz Reporting Service could allow an authenticated user on the network to affect the system's performance using complicated queries due to insufficient resource pooling.

jazz_reporting_service | Denial of Service
Feb 04, 2026 Feb 23, 2026
Feb 04, 2026
Feb 23, 2026
3.5 LOW
CVE-2025-27550 — IBM Jazz Reporting Service Information Disclosure

IBM Jazz Reporting Service could allow an authenticated user on the host network to obtain sensitive information about other projects that reside on the server.

jazz_reporting_service | Information Disclosure
Feb 04, 2026 Feb 23, 2026
Feb 04, 2026
Feb 23, 2026
3.5 LOW
CVE-2025-1823 — IBM Jazz Reporting Service Denial of Service

IBM Jazz Reporting Service could allow an authenticated user on the host network to cause a denial of service using specially crafted SQL query that consumes excess memory resources.

jazz_reporting_service | Denial of Service
Feb 04, 2026 Feb 12, 2026
Feb 04, 2026
Feb 12, 2026
8.2 HIGH
CVE-2025-15555 — Open5GS VoLTE Cx-Test hss-cx-path.c hss_ogs_diam_cx_mar_cb stack-based overflow

A security flaw has been discovered in Open5GS up to 2.7.6. Affected by this vulnerability is the function hss_ogs_diam_cx_mar_cb of the file src/hss/hss-cx-path.c of the component VoLTE Cx-Test. The…

open5gs | Remote | Memory Corruption
Feb 04, 2026 Feb 11, 2026
Feb 04, 2026
Feb 11, 2026
9.8 CRITICAL
CVE-2025-13375 — IBM Common Cryptographic Architecture Arbitrary Command Execution

IBM Common Cryptographic Architecture (CCA) 7.5.52 and 8.4.82 could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system.

common_cryptographic_architecture | Remote | Authentication
Feb 04, 2026 Feb 05, 2026
Feb 04, 2026
Feb 05, 2026
5.3 MEDIUM
CVE-2024-39724 — IBM Db2 Big SQL on Cloud Pak for Data is vulnerable to a denial of service due to lack of…

IBM Db2 Big SQL on Cloud Pak for Data versions 7.6 (on CP4D 4.8), 7.7 (on CP4D 5.0), and 7.8 (on CP4D 5.1) do not properly limit the allocation of system resources. An authenticated user with interna…

big_sql | Remote | Denial of Service
Feb 04, 2026 Feb 05, 2026
Feb 04, 2026
Feb 05, 2026
5.3 MEDIUM
CVE-2023-38281 — Multiple Vulnerabilities in IBM Cloud Pak System

IBM Cloud Pak System does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting th…

cloud_pak_system os_image_for_red_hat_linux_systems | Remote | Information Disclosure
Feb 04, 2026 Feb 25, 2026
Feb 04, 2026
Feb 25, 2026
5.3 MEDIUM
CVE-2023-38017 — Multiple Vulnerabilities in IBM Cloud Pak System

IBM Cloud Pak System is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leadi…

cloud_pak_system os_image_for_red_hat_linux_systems | Remote | Cross-Site Scripting
Feb 04, 2026 Feb 25, 2026
Feb 04, 2026
Feb 25, 2026
7.5 HIGH
CVE-2023-38010 — Multiple Vulnerabilities in IBM Cloud Pak System

IBM Cloud Pak System displays sensitive information in user messages that could aid in further attacks against the system.

cloud_pak_system os_image_for_red_hat_linux_systems | Remote | Information Disclosure
Feb 04, 2026 Feb 25, 2026
Feb 04, 2026
Feb 25, 2026
8.8 HIGH
CVE-2026-25514 — FacturaScripts has SQL Injection vulnerability in Autocomplete Actions

FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScripts contains a critical SQL injection vulnerability in the autocomplete functi…

facturascripts | Remote | Injection
Feb 04, 2026 Feb 23, 2026
Feb 04, 2026
Feb 23, 2026
8.8 HIGH
CVE-2026-25513 — FacturaScripts has SQL Injection vulnerability in API ORDER BY Clause

FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScripts contains a critical SQL injection vulnerability in the REST API that allow…

facturascripts | Remote | Injection
Feb 04, 2026 Feb 23, 2026
Feb 04, 2026
Feb 23, 2026
9.8 CRITICAL
CVE-2026-25505 — Bambuddy Uses Hardcoded Secret Key + Many API Endpoints do not Require Authentication

Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardcoded secret key used for signing JWTs is checked into source code and ManyAPI r…

bambuddy | Remote | Authentication
Feb 04, 2026 Feb 27, 2026
Feb 04, 2026
Feb 27, 2026
9.6 CRITICAL
CVE-2026-25481 — Langroid has WAF Bypass Leading to RCE in TableChatAgent

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.59.32, there is a bypass to the fix for CVE-2025-46724. TableChatAgent can call pandas_eval tool to …

langroid | Remote | Injection
Feb 04, 2026 Feb 20, 2026
Feb 04, 2026
Feb 20, 2026
6.5 MEDIUM
CVE-2026-25475 — OpenClaw Vulnerable to Local File Inclusion via MEDIA: Path Extraction

OpenClaw is a personal AI assistant. Prior to version 2026.1.30, the isValidMedia() function in src/media/parse.ts allows arbitrary file paths including absolute paths, home directory paths, and dire…

openclaw | Remote | Path Traversal
Feb 04, 2026 Feb 13, 2026
Feb 04, 2026
Feb 13, 2026
8.8 HIGH
CVE-2026-25161 — Alist vulnerable to Path Traversal in multiple file operation handlers

Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the application contains path traversal vulnerability in multiple file operation han…

alist | Remote | Path Traversal
Feb 04, 2026 Feb 13, 2026
Feb 04, 2026
Feb 13, 2026
9.1 CRITICAL
CVE-2026-25160 — Alist has Insecure TLS Config

Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the application disables TLS certificate verification by default for all outgoing st…

alist | Remote | Misconfiguration
Feb 04, 2026 Feb 13, 2026
Feb 04, 2026
Feb 13, 2026
Showing 20 of 5149 Results