Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-27020 — Photobooth has a XSS vulnerability in user input

Photobooth prior to 1.0.1 has a cross-site scripting (XSS) vulnerability in user input fields. Malicious users could inject scripts through unvalidated form inputs. This vulnerability is fixed in 1.0…

Remote | Cross-Site Scripting
Feb 20, 2026 Feb 23, 2026
Feb 20, 2026
Feb 23, 2026
9.3 CRITICAL
CVE-2026-25896 — fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE enti…

fast-xml-parser fast-xml-parser | Remote | Cross-Site Scripting
Feb 20, 2026 Mar 02, 2026
Feb 20, 2026
Mar 02, 2026
8.8 HIGH
CVE-2026-24892 — openITCOCKPIT has Unsafe Deserialization in openITCOCKPIT Changelog Handling

openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. openITCOCKPIT Community Edition 5.3.1 and earlier contains an unsafe PHP des…

openitcockpit | Remote | Injection
Feb 20, 2026 Mar 02, 2026
Feb 20, 2026
Mar 02, 2026
9.0 HIGH
CVE-2026-2855 — D-Link DWR-M960 DDNS Settings formDdns sub_4648F0 stack-based overflow

A vulnerability has been found in D-Link DWR-M960 1.01.07. Affected is the function sub_4648F0 of the file /boafrm/formDdns of the component DDNS Settings Handler. The manipulation of the argument su…

dwr-m960_firmware dwr-m960 | Remote | Memory Corruption
Feb 20, 2026 Feb 23, 2026
Feb 20, 2026
Feb 23, 2026
9.0 HIGH
CVE-2026-2854 — D-Link DWR-M960 NTP Configuration Endpoint formNtp sub_4611CC stack-based overflow

A flaw has been found in D-Link DWR-M960 1.01.07. This impacts the function sub_4611CC of the file /boafrm/formNtp of the component NTP Configuration Endpoint. Executing a manipulation of the argumen…

dwr-m960_firmware dwr-m960 | Remote | Memory Corruption
Feb 20, 2026 Feb 23, 2026
Feb 20, 2026
Feb 23, 2026
9.0 HIGH
CVE-2026-2853 — D-Link DWR-M960 System Log Configuration Endpoint formSysLog sub_462E14 stack-based overf…

A vulnerability was detected in D-Link DWR-M960 1.01.07. This affects the function sub_462E14 of the file /boafrm/formSysLog of the component System Log Configuration Endpoint. Performing a manipulat…

dwr-m960_firmware dwr-m960 | Remote | Memory Corruption
Feb 20, 2026 Feb 23, 2026
Feb 20, 2026
Feb 23, 2026
7.7 HIGH
CVE-2026-2473 — Bucket Squatting in Vertex AI Experiments leads to RCE and Model Theft.

Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not including) 1.133.0 on Google Cloud Platform allows an unauthenticated remote attacker t…

Remote | Misconfiguration
Feb 20, 2026 Feb 23, 2026
Feb 20, 2026
Feb 23, 2026
8.6 HIGH
CVE-2026-2472 — Stored Cross-Site Scripting (XSS) in Vertex AI Python SDK Visualization

Stored Cross-Site Scripting (XSS) in the _genai/_evals_visualization component of Google Cloud Vertex AI SDK (google-cloud-aiplatform) versions from 1.98.0 up to (but not including) 1.131.0 allows an…

Remote | Cross-Site Scripting
Feb 20, 2026 Feb 27, 2026
Feb 20, 2026
Feb 27, 2026
6.1 MEDIUM
CVE-2025-62326 — HCL Digital Experience is susceptible to stored cross-site scripting (XSS)

HCL Digital Experience is susceptible to stored cross-site scripting (XSS) in the administrative user interface which would require elevated privileges to exploit.

digital_experience | Remote | Cross-Site Scripting
Feb 20, 2026 Feb 24, 2026
Feb 20, 2026
Feb 24, 2026
6.5 MEDIUM
CVE-2026-2852 — yeqifu warehouse Sales Endpoint SalesController.java deleteSales access control

A vulnerability was identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This issue affects the function addSales/updateSales/deleteSales of the file dataset\repos\warehouse…

warehouse | Remote | Authorization
Feb 20, 2026 Feb 26, 2026
Feb 20, 2026
Feb 26, 2026
10.0 CRITICAL
CVE-2021-35402 — PROLiNK PRC2402M Command Injection Vulnerability

PROLiNK PRC2402M 20190909 before 2021-06-13 allows live_api.cgi?page=satellite_list OS command injection via shell metacharacters in the ip parameter (for satellite_status).

Remote | Injection
Feb 20, 2026 Feb 23, 2026
Feb 20, 2026
Feb 23, 2026
6.1 MEDIUM
CVE-2019-25445 — Fiverr Clone Script 1.2.2 Cross-Site Scripting via search-results.php

Fiverr Clone Script 1.2.2 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the keyword parameter. Attackers can craft UR…

fiverr_clone_script | Remote | Cross-Site Scripting
Feb 20, 2026 Feb 26, 2026
Feb 20, 2026
Feb 26, 2026
9.1 CRITICAL
CVE-2019-25444 — Fiverr Clone Script 1.2.2 SQL Injection via page Parameter

Fiverr Clone Script 1.2.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the page parameter. Attackers can …

fiverr_clone_script | Remote | Injection
Feb 20, 2026 Mar 02, 2026
Feb 20, 2026
Mar 02, 2026
6.5 MEDIUM
CVE-2026-2851 — yeqifu warehouse Inport Endpoint InportController.java deleteInport access control

A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This vulnerability affects the function addInport/updateInport/deleteInport of the file dataset\repo…

warehouse | Remote | Authorization
Feb 20, 2026 Feb 26, 2026
Feb 20, 2026
Feb 26, 2026
6.5 MEDIUM
CVE-2026-2850 — yeqifu warehouse Customer Endpoint CustomerController.java deleteCustomer access control

A vulnerability was found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function addCustomer/updateCustomer/deleteCustomer of the file dataset\repos\warehouse\s…

warehouse | Remote | Authorization
Feb 20, 2026 Feb 26, 2026
Feb 20, 2026
Feb 26, 2026
5.3 MEDIUM
CVE-2026-2832 — Certain Samsung MultiXpress Multifunction Printers Firmware – Potential Information Discl…

Certain Samsung MultiXpress Multifunction Printers may be vulnerable to information disclosure, potentially exposing address book entries and other device configuration information through specific A…

| Information Disclosure
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
7.1 HIGH
CVE-2026-27115 — ADB Explorer is Vulnerable to Arbitrary Directory Deletion via Command-Line Argument

ADB Explorer is a fluent UI for ADB on Windows. Versions 0.9.26020 and below have an unvalidated command-line argument that allows any user to trigger recursive deletion of arbitrary directories on t…

adb_explorer | Path Traversal
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
7.5 HIGH
CVE-2026-24891 — openITCOCKPIT has Unsafe PHP Deserialization in Gearman Worker Allowing Conditional Objec…

openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. Versions 5.3.1 and below contain an unsafe deserialization sink in the Gearm…

openitcockpit | Remote | Injection
Feb 20, 2026 Feb 24, 2026
Feb 20, 2026
Feb 24, 2026
6.3 MEDIUM
CVE-2026-2849 — yeqifu warehouse Cache Sync CacheController.java syncCache access control

A vulnerability has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this issue is the function deleteCache/removeAllCache/syncCache of the file dataset\repo…

warehouse | Remote | Authorization
Feb 20, 2026 Feb 26, 2026
Feb 20, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-2848 — SourceCodester Simple Responsive Tourism Website Registration Master.php sql injection

A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=register of the component R…

simple_responsive_tourism_website | Remote | Injection
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
Showing 20 of 5066 Results