Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.3 MEDIUM
CVE-2026-24923 — "HPDC HDC Permission Control Vulnerability"

Permission control vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

harmonyos | Authorization
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
6.9 MEDIUM
CVE-2026-24922 — Cisco HDC Buffer Overflow Vulnerability

Buffer overflow vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Memory Corruption
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
7.1 HIGH
CVE-2026-24921 — Cisco HDC Module Read Vulnerability

Address read vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

harmonyos | Information Disclosure
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
6.0 MEDIUM
CVE-2026-24919 — "Adobe DFX Out-of-Bounds Write Vulnerability"

Out-of-bounds write vulnerability in the DFX module. Impact: Successful exploitation of this vulnerability may affect availability.

emui harmonyos | Memory Corruption
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
6.8 MEDIUM
CVE-2026-24918 — Apache Communication Module Read Vulnerability

Address read vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.

emui harmonyos | Denial of Service
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
6.5 MEDIUM
CVE-2026-24917 — Apache Security Module Use-After-Free Vulnerability

UAF vulnerability in the security module. Impact: Successful exploitation of this vulnerability may affect availability.

emui harmonyos | Memory Corruption
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
5.9 MEDIUM
CVE-2026-24916 — Microsoft Windows Identity Authentication Bypass

Identity authentication bypass vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

harmonyos | Authentication
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
7.1 HIGH
CVE-2026-24915 — Cisco Media Out-of-Bounds Read Vulnerability

Out-of-bounds read issue in the media subsystem. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

harmonyos | Memory Corruption
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
5.5 MEDIUM
CVE-2026-24914 — "Canon Camera Type Confusion Vulnerability"

Type confusion vulnerability in the camera module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Memory Corruption
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
9.8 CRITICAL
CVE-2026-21643 — Fortinet FortiClientEMS SQL Injection

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized co…

forticlientems | Remote | Injection
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
4.3 MEDIUM
CVE-2026-1785 — Code Snippets <= 3.9.4 - Cross-Site Request Forgery to Cloud Snippet Download/Update Acti…

The Code Snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.9.4. This is due to missing nonce validation on the cloud snippet download a…

Remote | Cross-Site Request Forgery
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
9.8 CRITICAL
CVE-2026-1499 — WP Duplicate <= 1.1.8 - Authenticated (Subscriber+) Arbitrary File Upload via 'process_ad…

The WP Duplicate plugin for WordPress is vulnerable to Missing Authorization leading to Arbitrary File Upload in all versions up to and including 1.1.8. This is due to a missing capability check on t…

Remote | Authorization
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
6.4 MEDIUM
CVE-2026-1252 — Events Listing Widget <= 1.3.4 - Authenticated (Author+) Stored Cross-Site Scripting via …

The Events Listing Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Event URL' parameter in all versions up to, and including, 1.3.4 due to insufficient input sanitiz…

Remote | Cross-Site Scripting
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
4.2 MEDIUM
CVE-2026-2010 — Sanluan PublicCMS Trade Payment TradePaymentService.java paid improper authorization

A vulnerability has been found in Sanluan PublicCMS up to 4.0.202506.d/5.202506.d/6.202506.d. Impacted is the function Paid of the file publiccms-parent/publiccms-trade/src/main/java/com/publiccms/lo…

publiccms | Remote | Authorization
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
6.5 MEDIUM
CVE-2026-2009 — SourceCodester Gas Agency Management System createUser.php access control

A flaw has been found in SourceCodester Gas Agency Management System 1.0. This issue affects some unknown processing of the file /gasmark/php_action/createUser.php. Executing a manipulation can lead …

gas_agency_management_system | Remote | Authorization
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
9.2 CRITICAL
CVE-2026-21626 — Extension - stackideas.com - Information disclosure in post custom fields in EasyDiscuss …

Access control settings for forum post custom fields are not applied to the JSON output type, leading to an ACL violation vector an information disclosure

easydiscuss | Remote | Information Disclosure
Feb 06, 2026 Feb 18, 2026
Feb 06, 2026
Feb 18, 2026
6.4 MEDIUM
CVE-2026-1279 — Employee Directory <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting vi…

The Employee Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_title' parameter in the `search_employee_directory` shortcode in all versions up to, and includi…

Remote | Cross-Site Scripting
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
8.8 HIGH
CVE-2026-2008 — abhiphile fermat-mcp eqn_chart.py eqn_chart code injection

A vulnerability was detected in abhiphile fermat-mcp up to 47f11def1cd37e45dd060f30cdce346cbdbd6f0a. This vulnerability affects the function eqn_chart of the file fmcp/mpl_mcp/core/eqn_chart.py. Perf…

fermat | Remote | Injection
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
7.2 HIGH
CVE-2026-2000 — DCN DCME-320 Web Management Backend bridge_cfg.php apply_config command injection

A vulnerability was found in DCN DCME-320 up to 20260121. Impacted is the function apply_config of the file /function/system/basic/bridge_cfg.php of the component Web Management Backend. Performing a…

dcme-320_firmware dcme-320 | Remote | Injection
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
5.5 MEDIUM
CVE-2026-1998 — micropython runtime.c mp_import_all memory corruption

A flaw has been found in micropython up to 1.27.0. This vulnerability affects the function mp_import_all of the file py/runtime.c. This manipulation causes memory corruption. The attack needs to be l…

micropython | Memory Corruption
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
Showing 20 of 5112 Results