Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.1 MEDIUM
CVE-2026-3043 — itsourcecode Event Management System navbar.php cross site scripting

A flaw has been found in itsourcecode Event Management System 1.0. The impacted element is an unknown function of the file /admin/navbar.php. Executing a manipulation of the argument page can lead to…

event_management_system | Remote | Cross-Site Scripting
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
9.8 CRITICAL
CVE-2026-3042 — itsourcecode Event Management System index.php sql injection

A vulnerability was detected in itsourcecode Event Management System 1.0. The affected element is an unknown function of the file /admin/index.php. Performing a manipulation of the argument ID result…

event_management_system | Remote | Injection
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
7.5 HIGH
CVE-2025-69252 — free5GC has Null Pointer Dereference in UDM, Leading to Service Panic

free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.1 have a NULL Pointer Dereference…

free5gc udm | Remote | Denial of Service
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
6.6 MEDIUM
CVE-2025-69251 — free5GC has Improper Input Validation in UDM, Leading to Information Exposure

free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.1, remote attackers can inject…

free5gc udm | Remote | Injection
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
7.5 HIGH
CVE-2025-69250 — free5GC has Improper Error Handling in UDM, Leading to Information Exposure

free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.1, the service reliably leaks …

free5gc udm | Remote | Information Disclosure
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
9.1 CRITICAL
CVE-2024-58041 — Smolder versions through 1.51 for Perl uses insecure rand() function for cryptographic fu…

Smolder versions through 1.51 for Perl uses insecure rand() function for cryptographic functions. Smolder 1.51 and earlier for Perl uses the rand() function as the default source of entropy, which i…

smolder | Remote | Cryptography
Feb 24, 2026 Mar 04, 2026
Feb 24, 2026
Mar 04, 2026
8.8 HIGH
CVE-2026-3063 — Google Chrome DevTools Privilege Escalation Vulnerability

Inappropriate implementation in DevTools in Google Chrome prior to 145.0.7632.116 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged…

linux_kernel chrome macos windows edge_chromium | Remote | Cross-Site Scripting
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
9.8 CRITICAL
CVE-2026-3062 — Google Chrome Tint Out-of-Bounds Memory Access Vulnerability

Out of bounds read and write in Tint in Google Chrome on Mac prior to 145.0.7632.116 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security sever…

linux_kernel chrome macos windows edge_chromium | Remote | Memory Corruption
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
9.1 CRITICAL
CVE-2026-3061 — Google Chrome Media Out-of-Bounds Read Vulnerability

Out of bounds read in Media in Google Chrome prior to 145.0.7632.116 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

linux_kernel chrome macos windows edge_chromium | Remote | Memory Corruption
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
7.7 HIGH
CVE-2026-21665 — Fiserv Originate Loans Peripherals .NET Remoting TCP Channel Remote Code Execution Vulner…

The Print Service component of Fiserv Originate Loans Peripherals (formerly Velocity Services) in unsupported version 2021.2.4 (build 4.7.3155.0011) uses deprecated .NET Remoting TCP channels that al…

Remote | Misconfiguration
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
4.8 MEDIUM
CVE-2026-3041 — xingfuggz BaykeShop Article Sidebar custom.html cross site scripting

A security vulnerability has been detected in xingfuggz BaykeShop up to 1.3.20. Impacted is an unknown function of the file src/baykeshop/contrib/article/templates/baykeshop/sidebar/custom.html of th…

Remote | Cross-Site Scripting
Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
7.2 HIGH
CVE-2026-3040 — DrayTek Vigor 300B Web Management uploadlangs cgiGetFile os command injection

A vulnerability was identified in DrayTek Vigor 300B up to 1.5.1.6. This affects the function cgiGetFile of the file /cgi-bin/mainfunction.cgi/uploadlangs of the component Web Management Interface. T…

vigor300b_firmware vigor300b | Remote | Injection
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
6.1 MEDIUM
CVE-2026-3028 — erzhongxmu JEEWMS JeecgListDemoController.java doAdd cross site scripting

A vulnerability was determined in erzhongxmu JEEWMS up to 3.7. This vulnerability affects the function doAdd of the file src/main/java/com/jeecg/demo/controller/JeecgListDemoController.java. This man…

jeewms jeewms | Remote | Cross-Site Scripting
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
5.4 MEDIUM
CVE-2026-27742 — Bludit <= 3.16.2 Stored XSS in Post Content

Bludit version 3.16.2 contains a stored cross-site scripting (XSS) vulnerability in the post content functionality. The application performs client-side sanitation of content input but does not enfor…

bludit | Remote | Cross-Site Scripting
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
5.1 MEDIUM
CVE-2026-27741 — Bludit <= 3.16.1 CSRF in Plugin and Theme Management Endpoints

Bludit version 3.16.1 contains a cross-site request forgery (CSRF) vulnerability in the /admin/uninstall-plugin/ and /admin/install-theme/ endpoints. The application does not implement anti-CSRF toke…

bludit | Remote | Cross-Site Request Forgery
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
8.7 HIGH
CVE-2026-25649 — Traccar Vulnerable to Authorization Code Theft via Open Redirect in OIDC Provider Endpoin…

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users can steal OAuth 2.0 authorization codes by exploiting an open redirect…

traccar | Remote | Authentication
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
7.5 HIGH
CVE-2025-69248 — free5GC has Array Index Out of Bounds in AMF Leading to Denial of Service

free5GC is an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.1 of free5GC's AMF service have a Buffer Overflow vulnerability leading to Denial of S…

free5gc amf | Remote | Denial of Service
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
7.5 HIGH
CVE-2025-69247 — free5GC has Heap Buffer Overflow in UPF Leading to Denial of Service

free5GC go-upf is the User Plane Function (UPF) implementation for 5G networks that is part of the free5GC project. Versions prior to 1.2.8 have a Heap-based Buffer Overflow (CWE-122) vulnerability l…

free5gc go-upf | Remote | Memory Corruption
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
7.5 HIGH
CVE-2025-69232 — free5GC hasProtocol Compliance Violation in UPF Leading to SMF Service Disruption

free5GC is an open-source project for 5th generation (5G) mobile core networks. free5GC go-upf versions up to and including 1.2.6, corresponding to free5gc smf up to and including 1.4.0, have an Impr…

free5gc smf go-upf | Remote | Denial of Service
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
5.3 MEDIUM
CVE-2025-69208 — free5GC UDR's NEF incorrectly returns 500 for missing PFD data (UDR 404) in Nnef_PfdManag…

free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. Versions prior to 1.4.1 contain an Improper Error Handling vulnerabi…

free5gc udr | Remote | Information Disclosure
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
Showing 20 of 5329 Results