Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.1 MEDIUM
CVE-2026-3027 — erzhongxmu JEEWMS UEditor getContent.jsp cross site scripting

A vulnerability was found in erzhongxmu JEEWMS up to 3.7. This affects an unknown part of the file src/main/webapp/plug-in/ueditor/jsp/getContent.jsp of the component UEditor. The manipulation of the…

jeewms | Remote | Cross-Site Scripting
Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
7.5 HIGH
CVE-2026-3026 — erzhongxmu JEEWMS UEditor getRemoteImage.jsp server-side request forgery

A vulnerability has been found in erzhongxmu JEEWMS 3.7. Affected by this issue is some unknown functionality of the file /plug-in/ueditor/jsp/getRemoteImage.jsp of the component UEditor. The manipul…

jeewms | Remote | Server-Side Request Forgery
Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
9.8 CRITICAL
CVE-2026-3025 — ShuoRen Smart Heating Integrated Management Platform ExampleNodeService.asmx unrestricted…

A flaw has been found in ShuoRen Smart Heating Integrated Management Platform 1.0.0. Affected by this vulnerability is an unknown functionality of the file /MP/Service/Webservice/ExampleNodeService.a…

smart_heating_integrated_management_platform | Remote | Misconfiguration
Feb 23, 2026 Mar 03, 2026
Feb 23, 2026
Mar 03, 2026
8.7 HIGH
CVE-2026-25648 — Traccar Vulnerable to Stored Cross-Site Scripting (XSS) via Malicious SVG File Upload

Versions of the Traccar open-source GPS tracking system starting with 6.11.1 contain an issue in which authenticated users can execute arbitrary JavaScript in the context of other users' browsers by …

traccar | Remote | Cross-Site Scripting
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
5.1 MEDIUM
CVE-2026-23694 — Aruba HiSpeed Cache < 3.0.5 CSRF in Multiple Administrative AJAX Actions

Aruba HiSpeed Cache (aruba-hispeed-cache) WordPress plugin versions prior to 3.0.5 contain a cross-site request forgery (CSRF) vulnerability affecting multiple administrative AJAX actions. The handle…

aruba_hispeed_cache | Remote | Cross-Site Request Forgery
Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
10.0 CRITICAL
CVE-2026-23693 — ElementsKit Elementor Addons < 3.7.9 Unauthenticated Mailchimp REST Endpoint

ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor (elementskit-lite) WordPress plugin versions prior to 3.7.9 expose the REST endpoint /wp-json/elementskit/v1/widget/ma…

Remote | Server-Side Request Forgery
Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
6.5 MEDIUM
CVE-2026-23521 — Traccar vulnerable to Path Traversal and External Control of File Name or Path

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users who can create or edit devices can set a device `uniqueId` to an absol…

traccar | Remote | Path Traversal
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
9.1 CRITICAL
CVE-2025-71056 — GCOM EPON Session Hijacking Vulnerability

Improper session management in GCOM EPON 1GE ONU version C00R371V00B01 allows attackers to execute a session hijacking attack via spoofing the IP address of an authenticated user.

Remote | Authentication
Feb 23, 2026 Feb 27, 2026
Feb 23, 2026
Feb 27, 2026
8.8 HIGH
CVE-2025-70328 — TOTOLINK X6000R OS Command Injection

TOTOLINK X6000R v9.4.0cu.1498_B20250826 contains an OS command injection vulnerability in the NTPSyncWithHost handler of the /usr/sbin/shttpd executable. The host_time parameter is retrieved via sub_…

x6000r_firmware x6000r | Remote | Injection
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2025-70327 — TOTOLINK X5000R Argument Injection Vulnerability

TOTOLINK X5000R v9.1.0cu_2415_B20250515 contains an argument injection vulnerability in the setDiagnosisCfg handler of the /usr/sbin/lighttpd executable. The ip parameter is retrieved via websGetVar …

x5000r_firmware x5000r | Remote | Injection
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
7.1 HIGH
CVE-2025-68930 — Traccar Missing Origin Validation in WebSockets

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability in the `/api/socket` endpoint. The application fails …

traccar | Remote | Authentication
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
7.5 HIGH
CVE-2026-27623 — Valkey has Pre-Authentication DOS from malformed RESP request

Valkey is a distributed key-value database. Starting in version 9.0.0 and prior to version 9.0.3, a malicious actor with network access to Valkey can cause the system to abort by triggering an assert…

valkey | Remote | Denial of Service
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
7.5 HIGH
CVE-2026-21863 — Malformed Valkey Cluster bus message can lead to Remote DoS

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus port can send an invalid packet that may cause an…

valkey | Remote | Denial of Service
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
8.0 HIGH
CVE-2025-70329 — TOTOLink X5000R OS Command Injection Vulnerability

TOTOLink X5000R v9.1.0cu_2415_B20250515 contains an OS command injection vulnerability in the setIptvCfg handler of the /usr/sbin/lighttpd executable. The vlanVidLan1 (and other vlanVidLanX) paramete…

x5000r_firmware x5000r | Injection
Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
8.5 HIGH
CVE-2025-67733 — Valkey Affected by RESP Protocol Injection via Lua error_reply

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary information into the response stream for…

valkey | Remote | Injection
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
7.4 HIGH
CVE-2025-63946 — Tencent PC Manager Privilege Escalation Vulnerability

A privilege escalation (PE) vulnerability in the Tencent PC Manager app thru 17.10.28554.205 on Windows devices enables a local user to execute programs with elevated privileges. However, execution r…

pcmanager | Authorization
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
7.4 HIGH
CVE-2025-63945 — Tencent iOA App Privilege Escalation Vulnerability

A privilege escalation (PE) vulnerability in the Tencent iOA app thru 210.9.28693.621001 on Windows devices enables a local user to execute programs with elevated privileges. However, execution requi…

ioa | Authorization
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
6.2 MEDIUM
CVE-2025-61147 — StrukturAG libde265 Segmentation Fault (Memory Corruption)

strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table().

| Memory Corruption
Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
4.0 MEDIUM
CVE-2025-61146 — Saitoha Libsixel Memory Leak Vulnerability

saitoha libsixel until v1.8.7 was discovered to contain a memory leak via the component malloc_stub.c.

libsixel | Memory Corruption
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
5.5 MEDIUM
CVE-2025-61145 — Libtiff Double Free Vulnerability

libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c.

libtiff | Memory Corruption
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
Showing 20 of 5272 Results