Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.1 MEDIUM
CVE-2019-25390 — Smoothwall Express 3.1 'interfaces.cgi' Cross-Site Scripting

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the interfaces.cgi script that allow attackers to inject malicious scripts through …

smoothwall_express smoothwall | Remote | Cross-Site Scripting
Feb 16, 2026 Feb 20, 2026
Feb 16, 2026
Feb 20, 2026
6.1 MEDIUM
CVE-2019-25389 — Smoothwall Express 3.1 'timedaccess.cgi' Cross-Site Scripting

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the MACHINES …

smoothwall_express smoothwall | Remote | Cross-Site Scripting
Feb 16, 2026 Feb 20, 2026
Feb 16, 2026
Feb 20, 2026
6.1 MEDIUM
CVE-2019-25388 — Smoothwall Express 3.1 'ipblock.cgi' Cross-Site Scripting

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted input t…

smoothwall_express smoothwall | Remote | Cross-Site Scripting
Feb 16, 2026 Feb 20, 2026
Feb 16, 2026
Feb 20, 2026
6.1 MEDIUM
CVE-2019-25387 — Smoothwall Express 3.1 'xtaccess.cgi' Cross-Site Scripting

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted input t…

smoothwall_express smoothwall | Remote | Cross-Site Scripting
Feb 16, 2026 Feb 20, 2026
Feb 16, 2026
Feb 20, 2026
6.1 MEDIUM
CVE-2019-25386 — Smoothwall Express 3.1 'dmzholes.cgi' Cross-Site Scripting

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the dmzholes.cgi script that allow attackers to inject malicious scripts through un…

smoothwall_express smoothwall | Remote | Cross-Site Scripting
Feb 16, 2026 Feb 20, 2026
Feb 16, 2026
Feb 20, 2026
6.1 MEDIUM
CVE-2019-25385 — Smoothwall Express 3.1 'outgoing.cgi' Cross-Site Scripting

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the MACHINE and MACHINECOMMEN…

smoothwall_express smoothwall | Remote | Cross-Site Scripting
Feb 16, 2026 Feb 20, 2026
Feb 16, 2026
Feb 20, 2026
6.1 MEDIUM
CVE-2019-25384 — Smoothwall Express 3.1 'portfw.cgi' Cross-Site Scripting

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the portfw.cgi script that allow attackers to inject malicious scripts through unva…

smoothwall_express smoothwall | Remote | Cross-Site Scripting
Feb 16, 2026 Feb 20, 2026
Feb 16, 2026
Feb 20, 2026
6.1 MEDIUM
CVE-2019-25383 — Smoothwall Express 3.1 'apcupsd.cgi' Cross-Site Scripting

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the apcupsd.cgi script that allow attackers to inject malicious scripts through mul…

smoothwall_express smoothwall | Remote | Cross-Site Scripting
Feb 16, 2026 Feb 20, 2026
Feb 16, 2026
Feb 20, 2026
6.1 MEDIUM
CVE-2019-25382 — Smoothwall Express 3.1 'time.cgi' Cross-Site Scripting

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the NTP_SERVE…

smoothwall_express smoothwall | Remote | Cross-Site Scripting
Feb 16, 2026 Feb 20, 2026
Feb 16, 2026
Feb 20, 2026
6.1 MEDIUM
CVE-2019-25381 — Smoothwall Express 3.1 'hosts.cgi' Cross-Site Scripting

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the hosts.cgi script that allow attackers to inject malicious scripts through unval…

smoothwall_express smoothwall | Remote | Cross-Site Scripting
Feb 16, 2026 Feb 20, 2026
Feb 16, 2026
Feb 20, 2026
6.1 MEDIUM
CVE-2019-25380 — Smoothwall Express 3.1 'dhcp.cgi' Cross-Site Scripting

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the dhcp.cgi script that allow attackers to inject malicious scripts through multip…

smoothwall_express smoothwall | Remote | Cross-Site Scripting
Feb 16, 2026 Feb 20, 2026
Feb 16, 2026
Feb 20, 2026
7.2 HIGH
CVE-2019-25379 — Smoothwall Express 3.1 'urlfilter.cgi' Cross-Site Scripting

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains stored and reflected cross-site scripting vulnerabilities in the urlfilter.cgi endpoint that allow attackers to inject malicious scripts. Atta…

smoothwall_express smoothwall | Remote | Cross-Site Scripting
Feb 16, 2026 Feb 20, 2026
Feb 16, 2026
Feb 20, 2026
6.1 MEDIUM
CVE-2019-25378 — Smoothwall Express 3.1 'proxy.cgi' Cross-Site Scripting

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple cross-site scripting vulnerabilities in the proxy.cgi endpoint that allow attackers to inject malicious scripts through parameters in…

smoothwall_express smoothwall | Remote | Cross-Site Scripting
Feb 16, 2026 Feb 20, 2026
Feb 16, 2026
Feb 20, 2026
6.8 MEDIUM
CVE-2026-2565 — Wavlink WL-NU516U1 adm.cgi sub_40785C stack-based overflow

A weakness has been identified in Wavlink WL-NU516U1 20251208. Affected by this issue is the function sub_40785C of the file /cgi-bin/adm.cgi. This manipulation of the argument time_zone causes stack…

wl-nu516u1_firmware wl-nu516u1 | Remote | Memory Corruption
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
9.2 CRITICAL
CVE-2026-2564 — Intelbras VIP 3260 Z IA OutsideCmd password recovery

A security flaw has been discovered in Intelbras VIP 3260 Z IA 2.840.00IB005.0.T. Affected by this vulnerability is an unknown functionality of the file /OutsideCmd. The manipulation results in weak …

Remote | Authentication
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
8.7 HIGH
CVE-2026-2101 — Reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIAvpm Web Access from EN…

A Reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIAvpm Web Access from ENOVIAvpm Version 1 Release 16 through ENOVIAvpm Version 1 Release 19 allows an attacker to execute arbitrary …

Remote | Cross-Site Scripting
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
7.2 HIGH
CVE-2026-26930 — SmarterTools SmarterMail MAPI Cross-Site Scripting Vulnerability

SmarterTools SmarterMail before 9526 allows XSS via MAPI requests.

smartermail | Remote | Cross-Site Scripting
Feb 16, 2026 Feb 22, 2026
Feb 16, 2026
Feb 22, 2026
8.8 HIGH
CVE-2026-2563 — JingDong JD Cloud Box AX6600 jdcapp_rpc controlDevice get_status privileges management

A vulnerability was identified in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. Affected is the function set_stcreenen_deabled_status/get_status of the file /f/service/controlDevice of the componen…

ax6600_firmware ax6600 | Remote | Authentication
Feb 16, 2026 Feb 23, 2026
Feb 16, 2026
Feb 23, 2026
9.1 CRITICAL
CVE-2025-65717 — Visual Studio Code Extensions Live Server File Exfiltration Vulnerability

An issue in Visual Studio Code Extensions Live Server v5.7.9 allows attackers to exfiltrate files via user interaction with a crafted HTML page.

live_server | Remote | Path Traversal
Feb 16, 2026 Feb 25, 2026
Feb 16, 2026
Feb 25, 2026
8.8 HIGH
CVE-2025-65716 — Visual Studio Code Extensions Markdown Preview Enhanced Code Execution Vulnerability

An issue in Visual Studio Code Extensions Markdown Preview Enhanced v0.8.18 allows attackers to execute arbitrary code via uploading a crafted .Md file.

markdown_preview_enhanced | Remote | Injection
Feb 16, 2026 Feb 25, 2026
Feb 16, 2026
Feb 25, 2026
Showing 20 of 5013 Results