Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2025-61144 — Libtiff Stack Overflow Vulnerability

libtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function.

libtiff | Remote | Memory Corruption
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
5.5 MEDIUM
CVE-2025-61143 — Libtiff NULL Pointer Dereference Vulnerability

libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c.

libtiff | Memory Corruption
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
6.1 MEDIUM
CVE-2026-26464 — Society Management System Portal Stored XSS Vulnerability

Stored Cross-Site Scripting (XSS) was found in the /admin/edit_user.php page of Society Management System Portal V1.0, which allows remote attackers to inject and store arbitrary JavaScript code that…

society_management_system_portal | Remote | Cross-Site Scripting
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
6.5 MEDIUM
CVE-2026-2698 — Improper Access Control

An improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope.

security_center | Remote | Authorization
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
7.1 HIGH
CVE-2026-27514 — Tenda F3 Plaintext Credential Exposure in Configuration Download

Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a sensitive information exposure vulnerability in the configuration download functionality. The configuration download response …

f3_firmware f3 | Remote | Information Disclosure
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
5.1 MEDIUM
CVE-2026-27513 — Tenda F3 CSRF in Web Management Interface

Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a cross-site request forgery (CSRF) vulnerability in the web-based administrative interface. The interface does not implement an…

f3_firmware f3 | Remote | Cross-Site Request Forgery
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
6.1 MEDIUM
CVE-2026-27512 — Tenda F3 Reflected Script Execution via Missing nosniff Header

Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a content-type confusion vulnerability in the administrative interface. Responses omit the X-Content-Type-Options: nosniff heade…

f3_firmware f3 | Remote | Cross-Site Scripting
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
5.1 MEDIUM
CVE-2026-27511 — Tenda F3 Clickjacking in Web Management Interface

Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a clickjacking vulnerability in the web-based administrative interface. The interface does not set the X-Frame-Options header, a…

f3_firmware f3 | Remote | Cross-Site Request Forgery
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
5.5 MEDIUM
CVE-2026-22568 — Unauthorized information retrieval in ZIA Admin UI

Improper neutralization of special elements in user-supplied input within the ZIA Admin UI could allow an authenticated administrator to access or retrieve unauthorized internal information in rare c…

zscaler_internet_access_admin_portal | Remote | Information Disclosure
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
7.6 HIGH
CVE-2026-22567 — ZIA Admin UI Input Validation Bug

Improper validation of user-supplied input in the ZIA Admin UI could allow an authenticated administrator to initiate backend functions through specific input fields in limited scenarios.

Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
9.0 HIGH
CVE-2026-3016 — UTT HiPER 810G formP2PLimitConfig strcpy buffer overflow

A vulnerability was identified in UTT HiPER 810G up to 1.7.7-171114. The affected element is the function strcpy of the file /goform/formP2PLimitConfig. The manipulation of the argument except leads …

810g_firmware 810g | Remote | Memory Corruption
Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
9.0 HIGH
CVE-2026-3015 — UTT HiPER 810G formPolicyRouteConf strcpy buffer overflow

A vulnerability was determined in UTT HiPER 810G up to 1.7.7-171114. Impacted is the function strcpy of the file /goform/formPolicyRouteConf. Executing a manipulation of the argument GroupName can le…

810g_firmware 810g | Remote | Memory Corruption
Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
8.8 HIGH
CVE-2026-2697 — Indirect Object Reference (IDOR) in Security Center

An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter.

security_center | Remote | Authorization
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
7.4 HIGH
CVE-2025-70058 — "YMFE yapi TLS/SSL Certificate Validation Bypass"

An issue pertaining to CWE-295: Improper Certificate Validation was discovered in YMFE yapi v1.12.0. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in …

yapi | Remote | Cryptography
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
7.4 HIGH
CVE-2025-70045 — Jxcore JXM TLS/SSL Certificate Validation Bypass

An issue pertaining to CWE-295: Improper Certificate Validation was discovered in jxcore jxm master. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in …

jxm | Remote | Misconfiguration
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
6.5 MEDIUM
CVE-2025-70044 — uTools-quickcommand SSL Certificate Validation Weakness

An issue pertaining to CWE-295: Improper Certificate Validation was discovered in fofolee uTools-quickcommand 5.0.3.

utools-quickcommand | Remote | Misconfiguration
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
9.1 CRITICAL
CVE-2025-70043 — Ayms TLS Certificate Validation Bypass

An issue pertaining to CWE-295: Improper Certificate Validation was discovered in Ayms node-To master. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false i…

Remote | Misconfiguration
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
7.2 HIGH
CVE-2025-14905 — 389-ds-base: 389-ds-base: remote code execution and denial of service via heap buffer ove…

A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callback` function within the `schema.c` file. This occurs because the code incorrectl…

enterprise_linux libssh gix-date | Remote | Memory Corruption
Feb 23, 2026 Mar 02, 2026
Feb 23, 2026
Mar 02, 2026
7.8 HIGH
CVE-2026-21420 — Dell Repository Manager Uncontrolled Search Path Element Remote Code Execution Vulnerabil…

Dell Repository Manager (DRM), versions prior to 3.4.8, contains an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerab…

repository_manager | Path Traversal
Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
7.5 HIGH
CVE-2025-69700 — Tenda FH1203 Stack-Based Buffer Overflow

Tenda FH1203 V2.0.1.6 contains a stack-based buffer overflow vulnerability in the modify_add_client_prio function, which is reachable via the formSetClientPrio CGI handler.

fh1203_firmware fh1203 | Remote | Memory Corruption
Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
Showing 20 of 5272 Results