Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.2 HIGH
CVE-2026-22548 — BIG-IP Advanced WAF and ASM vulnerability

When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests along with conditions beyond the attacker's control can cause the bd process to terminate.  N…

Feb 04, 2026 Feb 13, 2026
Feb 04, 2026
Feb 13, 2026
4.3 MEDIUM
CVE-2026-20732 — BIG-IP Configuration utility vulnerability

A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages.  Note: Software versions which have reached End of Technical Support (Eo…

Feb 04, 2026 Feb 13, 2026
Feb 04, 2026
Feb 13, 2026
3.3 LOW
CVE-2026-20730 — BIG-IP Edge Client for Windows vulnerability

A vulnerability exists in BIG-IP Edge Client and browser VPN clients on Windows that may allow attackers to gain access to sensitive information.  Note: Software versions which have reached End of Te…

Feb 04, 2026 Feb 13, 2026
Feb 04, 2026
Feb 13, 2026
8.2 HIGH
CVE-2026-1642 — NGINX vulnerability

A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream se…

Feb 04, 2026 Feb 13, 2026
Feb 04, 2026
Feb 13, 2026
8.1 HIGH
CVE-2025-70997 — Eladmin Unauthenticated Password Reset Vulnerability

A vulnerability has been discovered in eladmin v2.7 and before. This vulnerability allows for an arbitrary user password reset under any user permission level.

eladmin | Remote | Authentication
Feb 04, 2026 Feb 12, 2026
Feb 04, 2026
Feb 12, 2026
6.5 MEDIUM
CVE-2025-69618 — Tarot, Astro & Healing File Import Arbitrary File Overwrite Vulnerability

An arbitrary file overwrite vulnerability in the file import process of Tarot, Astro & Healing v11.4.0 allows attackers to overwrite critical internal files, potentially leading to arbitrary code exe…

coto | Remote | Path Traversal
Feb 04, 2026 Feb 11, 2026
Feb 04, 2026
Feb 11, 2026
9.8 CRITICAL
CVE-2025-5329 — SQLi in Martcode Software's Delta Course Automation

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Martcode Software Inc. Delta Course Automation allows SQL Injection.This issue affects Delta Cour…

Remote | Injection
Feb 04, 2026 Feb 04, 2026
Feb 04, 2026
Feb 04, 2026
8.8 HIGH
CVE-2025-15368 — SportsPress <= 2.7.26 - Authenticated (Contributor+) Local File Inclusion via Shortcode

The SportsPress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.7.26 via shortcodes 'template_name' attribute. This makes it possible for authentica…

sportspress | Remote | Path Traversal
Feb 04, 2026 Feb 04, 2026
Feb 04, 2026
Feb 04, 2026
6.7 MEDIUM
CVE-2025-14740 — Docker Desktop for Windows Incorrect Permission Assignment Privilege Escalation Vulnerabi…

Docker Desktop for Windows contains multiple incorrect permission assignment vulnerabilities in the installer's handling of the C:\ProgramData\DockerDesktop directory. The installer creates this dire…

desktop | Misconfiguration
Feb 04, 2026 Feb 04, 2026
Feb 04, 2026
Feb 04, 2026
7.5 HIGH
CVE-2026-24735 — Apache Answer: Revision API Improper Access Control leads to Information Disclosure

Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 1.7.1. An unauthenticated API endpoint incorrectly expose…

answer | Remote | Information Disclosure
Feb 04, 2026 Feb 06, 2026
Feb 04, 2026
Feb 06, 2026
4.8 MEDIUM
CVE-2026-0873 — Privilege Elevation in Ercom Cryptobox administration console

On a Cryptobox platform where administrator segregation based on entities is used, some vulnerabilities in Ercom Cryptobox administration console allows an authenticated entity administrator with kno…

cryptobox | Remote | Authorization
Feb 04, 2026 Feb 04, 2026
Feb 04, 2026
Feb 04, 2026
10.0 CRITICAL
CVE-2025-59818 — Authenticated Remote Code Execution via the file name of an uploaded file

This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file name of an uploaded file.

tcis-3_firmware tcis-3 | Remote | Injection
Feb 04, 2026 Feb 11, 2026
Feb 04, 2026
Feb 11, 2026
4.8 MEDIUM
CVE-2026-1622 — Unredacted data exposure in query.log

Neo4j Enterprise and Community editions versions prior to 2026.01.3 and 5.26.21 are vulnerable to a potential information disclosure by a user who has ability to access the local log files. The "ob…

neo4j | Information Disclosure
Feb 04, 2026 Feb 04, 2026
Feb 04, 2026
Feb 04, 2026
5.1 MEDIUM
CVE-2025-41085 — Stored Cross-Site Scripting (XSS) in Apidog web platform

Stored Cross-Site Scripting (XSS) vulnerability type in Apidog in the version 2.7.15, where SVG image uploads are not properly sanitized. This allows attackers to embed malicious scripts in SVG file…

apidog_web_platform | Remote | Cross-Site Scripting
Feb 04, 2026 Feb 04, 2026
Feb 04, 2026
Feb 04, 2026
4.9 MEDIUM
CVE-2026-1370 — SIBS - WooCommerce <= 2.2.0 - Authenticated (Admin+) SQL Injection via 'referencedId' Par…

The SIBS woocommerce payment gateway plugin for WordPress is vulnerable to time-based SQL Injection via the ‘referencedId’ parameter in all versions up to, and including, 2.2.0 due to insufficient es…

Remote | Injection
Feb 04, 2026 Feb 04, 2026
Feb 04, 2026
Feb 04, 2026
4.9 MEDIUM
CVE-2026-0816 — All push notification for WP <= 1.5.3 - Authenticated (Administrator+) SQL Injection via …

The All push notification for WP plugin for WordPress is vulnerable to time-based SQL Injection via the 'delete_id' parameter in all versions up to, and including, 1.5.3 due to insufficient escaping …

Remote | Injection
Feb 04, 2026 Feb 04, 2026
Feb 04, 2026
Feb 04, 2026
4.4 MEDIUM
CVE-2026-0743 — WP Content Permission <= 1.2 - Authenticated (Administrator+) Stored Cross-Site Scripting…

The WP Content Permission plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ohmem-message' parameter in all versions up to, and including, 1.2 due to insufficient input sanit…

Remote | Cross-Site Scripting
Feb 04, 2026 Feb 04, 2026
Feb 04, 2026
Feb 04, 2026
6.4 MEDIUM
CVE-2026-0742 — Smart Appointment & Booking <= 1.0.7 - Authenticated (Subscriber+) Stored Cross-Site Scri…

The Smart Appointment & Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the saab_save_form_data AJAX action in all versions up to, and including, 1.0.7 due to insufficie…

Remote | Cross-Site Scripting
Feb 04, 2026 Feb 04, 2026
Feb 04, 2026
Feb 04, 2026
4.4 MEDIUM
CVE-2026-0681 — Extended Random Number Generator <= 1.1 - Authenticated (Administrator+) Stored Cross-Sit…

The Extended Random Number Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in all versions up to, and including, 1.1 due to insufficient input sani…

Remote | Cross-Site Scripting
Feb 04, 2026 Feb 04, 2026
Feb 04, 2026
Feb 04, 2026
5.3 MEDIUM
CVE-2026-0679 — Fortis for WooCommerce <= 1.2.0 - Missing Authorization to Unauthenticated Arbitrary Orde…

The Fortis for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to an inverted nonce check in the 'check_fortis_notify_response' function in all versions up to, and includin…

Remote | Authorization
Feb 04, 2026 Feb 04, 2026
Feb 04, 2026
Feb 04, 2026
Showing 20 of 5210 Results