Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-2556 — cskefu Endpoint MediaController.java server-side request forgery

A security vulnerability has been detected in cskefu up to 8.0.1. This issue affects some unknown processing of the file com/cskefu/cc/controller/resource/MediaController.java of the component Endpoi…

cskefu | Remote | Server-Side Request Forgery
Feb 16, 2026 Feb 20, 2026
Feb 16, 2026
Feb 20, 2026
7.6 HIGH
CVE-2026-1046 — Arbitrary application execution via unvalidated server-controlled URLs in Help menu

Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via the user clicking o…

mattermost_server | Remote | Path Traversal
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
3.8 LOW
CVE-2025-14573 — Team Admin Bypass of Invite Permissions via allow_open_invite Field

Mattermost versions 10.11.x <= 10.11.9 fail to enforce invite permissions when updating team settings, which allows team administrators without proper permissions to bypass restrictions and add users…

mattermost_server | Remote | Authorization
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
4.3 MEDIUM
CVE-2025-14350 — Information disclosure via channel mentions in posts

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate team membership when processing channel mentions which allows authenticated users to determine the…

mattermost_server | Remote | Information Disclosure
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
7.5 HIGH
CVE-2026-2555 — JeecgBoot Retrieval-Augmented Generation AiragKnowledgeController.java importDocumentFrom…

A weakness has been identified in JeecgBoot 3.9.1. This vulnerability affects the function importDocumentFromZip of the file org/jeecg/modules/airag/llm/controller/AiragKnowledgeController.java of th…

jeecg_boot | Remote | Injection
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
6.5 MEDIUM
CVE-2026-2553 — tushar-2223 Hotel-Management-System HTTP POST Request home.php sql injection

A security flaw has been discovered in tushar-2223 Hotel-Management-System up to bb1f3b3666124b888f1e4bcf51b6fba9fbb01d15. This affects an unknown part of the file /home.php of the component HTTP POS…

Remote | Injection
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
5.5 MEDIUM
CVE-2026-2552 — ZenTao Editor control.php delete path traversal

A vulnerability was identified in ZenTao up to 21.7.8. Affected by this issue is the function delete of the file editor/control.php of the component Committer. Such manipulation of the argument fileP…

zentao | Path Traversal
Feb 16, 2026 Feb 20, 2026
Feb 16, 2026
Feb 20, 2026
4.3 MEDIUM
CVE-2025-2418 — Open Redirect in TR7's Web Application Firewall

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in TR7 Cyber ​​Defense Inc. Web Application Firewall allows Phishing.This issue affects Web Application Firewall: from 4.30 through 1…

| Misconfiguration
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
5.7 MEDIUM
CVE-2025-13821 — User profile update exposes password hash and MFA secrets

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to sanitize sensitive data in WebSocket messages which allows authenticated users to exfiltrate password hashes and MFA…

mattermost_server | Remote | Information Disclosure
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
5.5 MEDIUM
CVE-2026-2551 — ZenTao Backup control.php delete path traversal

A vulnerability was determined in ZenTao up to 21.7.8. Affected by this vulnerability is the function delete of the file editor/control.php of the component Backup Handler. This manipulation of the a…

zentao | Remote | Path Traversal
Feb 16, 2026 Feb 20, 2026
Feb 16, 2026
Feb 20, 2026
7.5 HIGH
CVE-2026-2452 — Unsafe variable evaluation in email templates

Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's name for the fina…

pretix | Remote | Information Disclosure
Feb 16, 2026 Mar 02, 2026
Feb 16, 2026
Mar 02, 2026
7.5 HIGH
CVE-2026-2451 — Unsafe variable evaluation in email templates

Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's name for the fina…

Remote | Information Disclosure
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
7.5 HIGH
CVE-2026-2415 — Unsafe variable evaluation in email templates

Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's name for the fina…

pretix | Remote | Information Disclosure
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
10.0 CRITICAL
CVE-2026-2577 — Nanobot Unauthenticated WhatsApp Session Hijack via WebSocket Bridge

The WhatsApp bridge component in Nanobot binds the WebSocket server to all network interfaces (0.0.0.0) on port 3001 by default and does not require authentication for incoming connections. An unauth…

Remote | Authentication
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
10.0 HIGH
CVE-2026-2550 — EFM iptime A6004MX timepro.cgi commit_vpncli_file_upload unrestricted upload

A vulnerability was found in EFM iptime A6004MX 14.18.2. Affected is the function commit_vpncli_file_upload of the file /cgi/timepro.cgi. The manipulation results in unrestricted upload. The attack m…

Remote | Misconfiguration
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
7.5 HIGH
CVE-2026-2549 — zhanghuanhao LibrarySystem 图书馆管理系统 BookController.java access control

A vulnerability has been found in zhanghuanhao LibrarySystem 图书馆管理系统 up to 1.1.1. This impacts an unknown function of the file BookController.java. The manipulation leads to improper access controls.…

Remote | Authorization
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
5.4 MEDIUM
CVE-2026-0999 — Authentication bypass via userID login when email and username login are disabled

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate login method restrictions which allows an authenticated user to bypass SSO-only login requirements…

mattermost_server | Remote | Authentication
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
4.3 MEDIUM
CVE-2026-0998 — Mattermost Zoom Plugin allows unauthorized meeting creation and post modification via ins…

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 fail to validate user identity and post ownership in the {{/api/v1/askPMI}} end…

mattermost_server zoom | Remote | Authentication
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
4.3 MEDIUM
CVE-2026-0997 — Mattermost Zoom Plugin channel preference API lacks authorization checks

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 fail to validate the authenticated user when processing {{/plugins/zoom/api/v1/…

mattermost_server zoom | Remote | Authentication
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
4.8 MEDIUM
CVE-2025-59905 — Reflected Cross-Site Scripting (XSS) in Kubysoft

Cross-Site Scripting (XSS) vulnerability reflected in Kubysoft, which occurs through multiple parameters within the endpoint ‘/node/kudaby/nodeFN/procedure’. This flaw allows the injection of arbitra…

Remote | Cross-Site Scripting
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
Showing 20 of 5033 Results