Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-2848 — SourceCodester Simple Responsive Tourism Website Registration Master.php sql injection

A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=register of the component R…

simple_responsive_tourism_website | Remote | Injection
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
8.2 HIGH
CVE-2026-2818 — Zip Slip Path Traversal in Snapshot Archive Extraction (Windows-Specific)

A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to b…

Remote | Path Traversal
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
9.8 CRITICAL
CVE-2026-2333 — Improper Neutralization of Special Elements used in a Command ('Command Injection') in Ow…

Improper Neutralization of Special Elements used in a Command ('Command Injection') in Owl opds 2.2.0.4 allows Command Injection via a crafted network request.

opds-talon opds-100 opds-1000 | Remote | Injection
Feb 20, 2026 Feb 26, 2026
Feb 20, 2026
Feb 26, 2026
6.1 MEDIUM
CVE-2026-27506 — SVXportal <= 2.5 Profile Update Stored XSS

SVXportal version 2.5 and prior contain a stored cross-site scripting vulnerability in the user profile update workflow (user_settings.php submitting to admin/update_user.php). Authenticated users ca…

svxportal | Remote | Cross-Site Scripting
Feb 20, 2026 Feb 23, 2026
Feb 20, 2026
Feb 23, 2026
6.1 MEDIUM
CVE-2026-27505 — SVXportal <= 2.5 admin/user_action.php Stored XSS

SVXportal version 2.5 and prior contain a stored cross-site scripting vulnerability in the user registration workflow (index.php submitting to admin/user_action.php). User-supplied fields such as Fir…

svxportal | Remote | Cross-Site Scripting
Feb 20, 2026 Feb 23, 2026
Feb 20, 2026
Feb 23, 2026
6.1 MEDIUM
CVE-2026-27504 — SVXportal <= 2.5 radiomobile_front.php stationid Reflected XSS

SVXportal version 2.5 and prior contain a reflected cross-site scripting vulnerability in radiomobile_front.php via the stationid query parameter. When an authenticated administrator views a crafted …

svxportal | Remote | Cross-Site Scripting
Feb 20, 2026 Feb 23, 2026
Feb 20, 2026
Feb 23, 2026
6.1 MEDIUM
CVE-2026-27503 — SVXportal <= 2.5 admin/log.php Search Reflected XSS

SVXportal version 2.5 and prior contain a reflected cross-site scripting vulnerability in admin/log.php via the search query parameter. When an authenticated administrator views a crafted URL, the ap…

svxportal | Remote | Cross-Site Scripting
Feb 20, 2026 Feb 23, 2026
Feb 20, 2026
Feb 23, 2026
6.1 MEDIUM
CVE-2026-27502 — SVXportal <= 2.5 log.php Search Reflected XSS

SVXportal version 2.5 and prior contain a reflected cross-site scripting vulnerability in log.php via the search query parameter. The application embeds the unsanitized parameter value directly into …

svxportal | Remote | Cross-Site Scripting
Feb 20, 2026 Feb 23, 2026
Feb 20, 2026
Feb 23, 2026
9.1 CRITICAL
CVE-2026-26747 — Monica Host Header Poisoning

A Host Header Poisoning vulnerability exists in Monica 4.1.2 due to improper handling of the HTTP Host header in app/Providers/AppServiceProvider.php, combined with the default misconfiguration where…

monica | Remote | Misconfiguration
Feb 20, 2026 Feb 26, 2026
Feb 20, 2026
Feb 26, 2026
8.8 HIGH
CVE-2026-26746 — OpenSourcePOS Local File Inclusion (LFI)

OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files on the web server by manipulating the Invoice Typ…

open_source_point_of_sale | Remote | Path Traversal
Feb 20, 2026 Feb 24, 2026
Feb 20, 2026
Feb 24, 2026
5.3 MEDIUM
CVE-2026-26745 — OpenSourcePOS SQL Injection Vulnerability

OpenSourcePOS 3.4.1 has a second order SQL Injection vulnerability in the handling of the currency_symbol configuration field. Although the input is initially stored without immediate execution, it i…

open_source_point_of_sale | Remote | Injection
Feb 20, 2026 Feb 24, 2026
Feb 20, 2026
Feb 24, 2026
9.8 CRITICAL
CVE-2026-26725 — Edu Business Solutions Print Shop Pro WebDesk Privilege Escalation Vulnerability

An issue in edu Business Solutions Print Shop Pro WebDesk v.18.34 allows a remote attacker to escalate privileges via the AccessID parameter.

print_shop_pro_webdesk | Remote | Authorization
Feb 20, 2026 Feb 26, 2026
Feb 20, 2026
Feb 26, 2026
7.6 HIGH
CVE-2026-26724 — Key Systems Inc Global Facilities Management Software Cross Site Scripting Vulnerability

Cross Site Scripting vulnerability in Key Systems Inc Global Facilities Management Software v. 20230721a allows a remote attacker to execute arbitrary code via the selectgroup and gn parameters on th…

global_facilities_management_software | Remote | Cross-Site Scripting
Feb 20, 2026 Feb 26, 2026
Feb 20, 2026
Feb 26, 2026
8.2 HIGH
CVE-2026-26723 — Key Systems Inc Global Facilities Management Software XSS

Cross Site Scripting vulnerability in Key Systems Inc Global Facilities Management Software v. 20230721a allows a remote attacker to execute arbitrary code via the function parameter.

global_facilities_management_software | Remote | Cross-Site Scripting
Feb 20, 2026 Feb 26, 2026
Feb 20, 2026
Feb 26, 2026
9.4 CRITICAL
CVE-2026-26722 — Key Systems Inc Global Facilities Management Software Privilege Escalation Vulnerability

An issue in Key Systems Inc Global Facilities Management Software v.20230721a allows a remote attacker to escalate privileges via PIN component of the login functionality.

global_facilities_management_software | Remote | Authentication
Feb 20, 2026 Feb 26, 2026
Feb 20, 2026
Feb 26, 2026
7.1 HIGH
CVE-2026-26721 — Key Systems Inc Global Facilities Management Software Information Disclosure

An issue in Key Systems Inc Global Facilities Management Software v.20230721a allows a remote attacker to obtain sensitive information via the sid query parameter.

global_facilities_management_software | Remote | Information Disclosure
Feb 20, 2026 Feb 26, 2026
Feb 20, 2026
Feb 26, 2026
8.5 HIGH
CVE-2026-26102 — Incorrect Permission Assignment for Critical Resource in Owl opds

Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File Manipulation via a crafted network request.

opds-talon opds-100 opds-1000 | Authorization
Feb 20, 2026 Feb 27, 2026
Feb 20, 2026
Feb 27, 2026
8.5 HIGH
CVE-2026-26101 — Incorrect Permission Assignment for Critical Resource in Owl opds

Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File Manipulation via a crafted network request.

opds-talon opds-100 opds-1000 | Authorization
Feb 20, 2026 Feb 27, 2026
Feb 20, 2026
Feb 27, 2026
6.8 MEDIUM
CVE-2026-26100 — Incorrect Permission Assignment for Critical Resource in Owl opds

Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File Manipulation via a crafted network request.

opds-talon opds-100 opds-1000 | Authorization
Feb 20, 2026 Feb 27, 2026
Feb 20, 2026
Feb 27, 2026
8.4 HIGH
CVE-2026-26099 — Uncontrolled Search Path Element in Owl opds

Uncontrolled Search Path Element in Owl opds 2.2.0.4 allows Leveraging/Manipulating Configuration File Search Paths via a crafted network request.

opds-talon opds-100 opds-1000 | Path Traversal
Feb 20, 2026 Feb 27, 2026
Feb 20, 2026
Feb 27, 2026
Showing 20 of 5217 Results