Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2024-55270 — phpgurukul Student Management System SQL Injection

phpgurukul Student Management System 1.0 is vulnerable to SQL Injection in studentms/admin/search.php via the searchdata parameter.

student_management_system | Remote | Injection
Feb 17, 2026 Feb 23, 2026
Feb 17, 2026
Feb 23, 2026
7.4 HIGH
CVE-2026-2618 — Beetel 777VR1 SSH Service risky encryption

A vulnerability was determined in Beetel 777VR1 up to 01.00.09. This impacts an unknown function of the component SSH Service. This manipulation causes risky cryptographic algorithm. The attack is po…

777vr1_firmware 777vr1 | Remote | Cryptography
Feb 17, 2026 Feb 19, 2026
Feb 17, 2026
Feb 19, 2026
8.5 HIGH
CVE-2026-23648 — Glory RBG-100 Recycler System Local Privilege Escalation via Insecure File Permissions

Glory RBG-100 recycler systems using the ISPK-08 software component contain multiple system binaries with overly permissive file permissions. Several binaries executed by the root user are writable a…

| Misconfiguration
Feb 17, 2026 Feb 18, 2026
Feb 17, 2026
Feb 18, 2026
9.8 CRITICAL
CVE-2026-23647 — Glory RBG-100 Recycler System Hard-coded OS Credentials

Glory RBG-100 recycler systems using the ISPK-08 software component contain hard-coded operating system credentials that allow remote authentication to the underlying Linux system. Multiple local use…

Remote | Authentication
Feb 17, 2026 Feb 18, 2026
Feb 17, 2026
Feb 18, 2026
8.7 HIGH
CVE-2025-67905 — Malwarebytes AdwCleaner Local File Inclusion Privilege Escalation Vulnerability

Malwarebytes AdwCleaner before v.8.7.0 runs as Administrator and performs an insecure log file delete operation in which the target location is user-controllable, allowing a non-admin user to escalat…

| Path Traversal
Feb 17, 2026 Feb 18, 2026
Feb 17, 2026
Feb 18, 2026
3.5 LOW
CVE-2024-55271 — PhpGurukul Gym Management System CSRF Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in phpgurukul Gym Management System 1.0. This issue is present in the profile update functionality of the User Panel, specificall…

gym_management_system | Remote | Cross-Site Request Forgery
Feb 17, 2026 Feb 23, 2026
Feb 17, 2026
Feb 23, 2026
8.8 HIGH
CVE-2026-2617 — Beetel 777VR1 Telnet Service/SSH Service insecure default initialization of resource

A vulnerability was found in Beetel 777VR1 up to 01.00.09. This affects an unknown function of the component Telnet Service/SSH Service. The manipulation results in insecure default initialization of…

777vr1_firmware 777vr1 | Misconfiguration
Feb 17, 2026 Feb 19, 2026
Feb 17, 2026
Feb 19, 2026
9.9 CRITICAL
CVE-2025-70830 — Datart Freemarker SSTI Vulnerability

A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows authenticated attackers to execute arbitrary code via injecting crafted Freemarker…

Remote | Injection
Feb 17, 2026 Feb 18, 2026
Feb 17, 2026
Feb 18, 2026
8.8 HIGH
CVE-2025-70828 — Datart Unvalidated Parameter Remote Code Execution Vulnerability

An issue in Datart v1.0.0-rc.3 allows attackers to execute arbitrary code via the url parameter in the JDBC configuration

Remote | Injection
Feb 17, 2026 Feb 19, 2026
Feb 17, 2026
Feb 19, 2026
8.8 HIGH
CVE-2025-70397 — Jizhicms SQL Injection Vulnerability

jizhicms 2.5.6 is vulnerable to SQL Injection in Article/deleteAll and Extmolds/deleteAll via the data parameter.

jizhicms | Remote | Injection
Feb 17, 2026 Feb 19, 2026
Feb 17, 2026
Feb 19, 2026
9.0 CRITICAL
CVE-2025-65753 — Guardian Gryphon TLS Certification Command Execution

An issue in the TLS certification mechanism of Guardian Gryphon v01.06.0006.22 allows attackers to execute commands as root.

Remote | Authentication
Feb 17, 2026 Feb 19, 2026
Feb 17, 2026
Feb 19, 2026
9.8 CRITICAL
CVE-2026-2616 — Beetel 777VR1 Web Management hard-coded credentials

A vulnerability has been found in Beetel 777VR1 up to 01.00.09. The impacted element is an unknown function of the component Web Management Interface. The manipulation leads to hard-coded credentials…

777vr1_firmware 777vr1 | Remote | Authentication
Feb 17, 2026 Feb 19, 2026
Feb 17, 2026
Feb 19, 2026
9.6 CRITICAL
CVE-2026-22208 — OpenS100 Portrayal Engine Unrestricted Lua Standard Library Access

OpenS100 (the reference implementation S-100 viewer) prior to commit 753cf29 contain a remote code execution vulnerability via an unrestricted Lua interpreter. The Portrayal Engine initializes Lua us…

Remote | Injection
Feb 17, 2026 Feb 18, 2026
Feb 17, 2026
Feb 18, 2026
5.7 MEDIUM
CVE-2025-70829 — Datart H2 JDBC Connection String Information Exposure

An information exposure vulnerability in Datart v1.0.0-rc.3 allows authenticated attackers to access sensitive data via a custom H2 JDBC connection string.

datart | Information Disclosure
Feb 17, 2026 Feb 23, 2026
Feb 17, 2026
Feb 23, 2026
6.5 MEDIUM
CVE-2024-31118 — WordPress SP Project & Document Manager plugin <= 4.70 - Broken Access Control to XSS vul…

Missing Authorization vulnerability in Smartypants SP Project & Document Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SP Project & Document Manag…

sp_project_\&_document_manager | Remote | Authorization
Feb 17, 2026 Feb 18, 2026
Feb 17, 2026
Feb 18, 2026
6.5 MEDIUM
CVE-2022-41650 — WordPress Custom Content by Country plugin <= 3.1.2 - Broken Access Control vulnerability

Missing Authorization vulnerability in Paul Custom Content by Country (by Shield Security) custom-content-by-country.This issue affects Custom Content by Country (by Shield Security): from n/a throug…

Remote | Authorization
Feb 17, 2026 Feb 18, 2026
Feb 17, 2026
Feb 18, 2026
7.0 HIGH
CVE-2026-25087 — Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering

Use After Free vulnerability in Apache Arrow C++. This issue affects Apache Arrow C++ from 15.0.0 through 23.0.0. It can be triggered when reading an Arrow IPC file (but not an IPC stream) with pre-…

arrow | Remote | Memory Corruption
Feb 17, 2026 Feb 18, 2026
Feb 17, 2026
Feb 18, 2026
5.4 MEDIUM
CVE-2026-23861 — Dell Unisphere for PowerMax Cross-site Scripting

Dell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with …

Remote | Cross-Site Scripting
Feb 17, 2026 Feb 18, 2026
Feb 17, 2026
Feb 18, 2026
6.1 MEDIUM
CVE-2025-7706 — Improper Access Control in TUBITAK BILGEM's Liderahenk

Missing Authentication for Critical Function vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Remote Code Inclusion.This issue affects Liderahenk: from 3.0.0…

Remote | Authentication
Feb 17, 2026 Feb 18, 2026
Feb 17, 2026
Feb 18, 2026
8.3 HIGH
CVE-2026-2615 — Wavlink WL-NU516U1 firewall.cgi singlePortForwardDelete command injection

A flaw has been found in Wavlink WL-NU516U1 up to 20251208. The affected element is the function singlePortForwardDelete of the file /cgi-bin/firewall.cgi. Executing a manipulation of the argument de…

wl-nu516u1_firmware wl-nu516u1 | Remote | Injection
Feb 17, 2026 Feb 18, 2026
Feb 17, 2026
Feb 18, 2026
Showing 20 of 5042 Results