Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-2985 — Tiandy Video Surveillance System 视频监控平台 CLSBODownLoad.java downloadImage server-side requ…

A security flaw has been discovered in Tiandy Video Surveillance System 视频监控平台 7.17.0. This impacts the function downloadImage of the file /com/tiandy/easy7/core/bo/CLSBODownLoad.java. Performing a m…

Remote | Server-Side Request Forgery
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
6.9 MEDIUM
CVE-2026-2984 — SourceCodester Student Result Management System drop_user.php denial of service

A vulnerability was identified in SourceCodester Student Result Management System 1.0. This affects an unknown function of the file /admin/core/drop_user.php. Such manipulation of the argument ID lea…

Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
5.9 MEDIUM
CVE-2025-59873 — Session Token Exposure via URL Query Parameters

An information exposure vulnerability exists in Vulnerability in HCL Software ZIE for Web. The application transmits sensitive session tokens and authentication identifiers within the URL query par…

Remote | Information Disclosure
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
5.1 MEDIUM
CVE-2025-40986 — Reflected Cross-Site Scripting in PideTuCita

Reflected Cross-Site Scripting (XSS) vulnerability in PideTuCita. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL using the…

Remote | Cross-Site Scripting
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
5.1 MEDIUM
CVE-2025-40701 — Reflected Cross-Site scripting (XSS) in SOTE's SOTESHOP

Reflected Cross-Site Scripting vulnerability in SOTESHOP, version 8.3.4. THis vulnerability allows an attacker execute JavaScript code in the victim's browser when a malicious URL with the 'id' param…

soteshop | Remote | Cross-Site Scripting
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
9.8 CRITICAL
CVE-2026-2983 — SourceCodester Student Result Management System Bulk Import import_users.php access contr…

A vulnerability was determined in SourceCodester Student Result Management System 1.0. The impacted element is an unknown function of the file /admin/core/import_users.php of the component Bulk Impor…

Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
9.3 CRITICAL
CVE-2025-41002 — SQL injection in Infoticketing

SQL injection vulnerability in Infoticketing. This vulnerability allows an unauthenticated attacker to retrieve, create, update, and delete the database by sending a POST request using the 'code' p…

Remote | Injection
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
9.0 HIGH
CVE-2026-2981 — UTT HiPER 810G formTaskEdit_ap strcpy buffer overflow

A vulnerability was found in UTT HiPER 810G up to 1.7.7-1711. The affected element is the function strcpy of the file /goform/formTaskEdit_ap. The manipulation of the argument txtMin2 results in buff…

810g_firmware 810g | Remote | Memory Corruption
Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
8.3 HIGH
CVE-2026-2980 — UTT HiPER 810G setSysAdm strcpy buffer overflow

A vulnerability has been found in UTT HiPER 810G up to 1.7.7-1711. Impacted is the function strcpy of the file /goform/setSysAdm. The manipulation of the argument passwd1 leads to buffer overflow. Th…

810g_firmware 810g | Remote | Memory Corruption
Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
8.8 HIGH
CVE-2026-2979 — FastApiAdmin Scheduled Task API controller.py user_avatar_upload_controller unrestricted …

A flaw has been found in FastApiAdmin up to 2.2.0. This issue affects the function user_avatar_upload_controller of the file /backend/app/api/v1/module_system/user/controller.py of the component Sche…

fastapi-admin fastapiadmin | Remote | Misconfiguration
Feb 23, 2026 Mar 05, 2026
Feb 23, 2026
Mar 05, 2026
4.0 MEDIUM
CVE-2026-26365 — Akamai CDN HTTP Request Smuggling Vulnerability

Akamai Ghost on Akamai CDN edge servers before 2026-02-06 mishandles processing of custom hop-by-hop HTTP headers, where an incoming request containing the header "Connection: Transfer-Encoding" coul…

Remote | Injection
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
8.8 HIGH
CVE-2026-25747 — Apache Camel: Deserialization of Untrusted Data in Camel LevelDB

Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes data read from the LevelDB aggregation repository usi…

camel | Remote | Authentication
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
9.1 CRITICAL
CVE-2026-23552 — Apache Camel: Camel-Keycloak: Cross-Realm Token Acceptance Bypass in KeycloakSecurityPoli…

Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component.  The Camel-Keycloak KeycloakSecurityPolicy does not validate the iss (issuer) claim of JWT tokens again…

camel | Remote | Authentication
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
8.8 HIGH
CVE-2026-2978 — FastApiAdmin Scheduled Task API controller.py upload_file_controller unrestricted upload

A vulnerability was detected in FastApiAdmin up to 2.2.0. This vulnerability affects the function upload_file_controller of the file /backend/app/api/v1/module_system/params/controller.py of the comp…

fastapi-admin fastapiadmin | Remote | Misconfiguration
Feb 23, 2026 Mar 05, 2026
Feb 23, 2026
Mar 05, 2026
8.8 HIGH
CVE-2026-2977 — FastApiAdmin Scheduled Task API controller.py upload_controller unrestricted upload

A security vulnerability has been detected in FastApiAdmin up to 2.2.0. This affects the function upload_controller of the file /backend/app/api/v1/module_common/file/controller.py of the component S…

fastapi-admin fastapiadmin | Remote | Misconfiguration
Feb 23, 2026 Mar 05, 2026
Feb 23, 2026
Mar 05, 2026
8.3 HIGH
CVE-2026-1367 — SQL Injection

Zohocorp ManageEngine ADSelfService Plus versions 6522 and below are vulnerable to authenticated SQL Injection in the search report option.

manageengine_adselfservice_plus | Remote | Injection
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
6.5 MEDIUM
CVE-2026-2976 — FastApiAdmin Download Endpoint controller.py download_controller information disclosure

A weakness has been identified in FastApiAdmin up to 2.2.0. Affected by this issue is the function download_controller of the file /backend/app/api/v1/module_common/file/controller.py of the componen…

fastapi-admin fastapiadmin | Remote | Information Disclosure
Feb 23, 2026 Mar 05, 2026
Feb 23, 2026
Mar 05, 2026
5.5 MEDIUM
CVE-2026-2975 — FastApiAdmin Custom Documentation Endpoint init_app.py reset_api_docs information disclos…

A security flaw has been discovered in FastApiAdmin up to 2.2.0. Affected by this vulnerability is the function reset_api_docs of the file /backend/app/plugin/init_app.py of the component Custom Docu…

fastapi-admin fastapiadmin | Remote | Information Disclosure
Feb 23, 2026 Mar 05, 2026
Feb 23, 2026
Mar 05, 2026
2.5 LOW
CVE-2026-2974 — AliasVault App Backup aliasvault.xml backup

A vulnerability was identified in AliasVault App up to 0.25.3 on Android/iOS. This vulnerability affects unknown code of the file shared_prefs/aliasvault.xml of the component Backup Handler. The mani…

| Information Disclosure
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
5.4 MEDIUM
CVE-2026-2972 — a466350665 Smart-SSO Role Edit UserController.java save cross site scripting

A vulnerability was determined in a466350665 Smart-SSO up to 2.1.1. This affects the function Save of the file smart-sso-server/src/main/java/openjoe/smart/sso/server/controller/admin/UserController.…

smart-sso | Remote | Cross-Site Scripting
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
Showing 20 of 5217 Results