Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.4 MEDIUM
CVE-2026-1909 — WaveSurfer-WP <= 2.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sr…

The WaveSurfer-WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's audio shortcode in all versions up to, and including, 2.8.3 due to insufficient input sanitization…

Remote | Cross-Site Scripting
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
6.4 MEDIUM
CVE-2026-1888 — Docus <= 1.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode A…

The Docus – YouTube Video Playlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'docusplaylist' shortcode in all versions up to, and including, 1.0.6 due to insufficient …

Remote | Cross-Site Scripting
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
6.4 MEDIUM
CVE-2026-1808 — Orange Confort+ accessibility toolbar for WordPress <= 0.7 - Authenticated (Contributor+)…

The Orange Confort+ accessibility toolbar for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' parameter of the ocplus_button shortcode in all versions up t…

Remote | Cross-Site Scripting
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
6.4 MEDIUM
CVE-2026-1401 — Tune Library <= 1.6.3 - Missing Authorization to Authenticated (Subscriber+) Stored Cross…

The Tune Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via CSV import in all versions up to, and including, 1.6.3. This is due to insufficient input sanitization and outpu…

tune_library | Remote | Cross-Site Scripting
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
6.1 MEDIUM
CVE-2026-0521 — Reflected Cross-Site Scripting in PDF Export Error Message

A reflected cross-site scripting (XSS) vulnerability in the PDF export functionality of the TYDAC AG MAP+ solution allows unauthenticated attackers to craft a malicious URL, that if visited by a vict…

map\+ | Remote | Cross-Site Scripting
Feb 06, 2026 Feb 18, 2026
Feb 06, 2026
Feb 18, 2026
5.3 MEDIUM
CVE-2025-10753 — OAuth Single Sign On – SSO (OAuth Client) <= 6.26.14 - Missing Authorization

The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 6.26.14. This is due to missing capability checks and aut…

oauth_single_sign_on | Remote | Authentication
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
5.5 MEDIUM
CVE-2026-1991 — libuvc UVC Descriptor device.c uvc_scan_streaming null pointer dereference

A vulnerability was detected in libuvc up to 0.0.7. Affected is the function uvc_scan_streaming of the file src/device.c of the component UVC Descriptor Handler. The manipulation results in null poin…

libuvc | Memory Corruption
Feb 06, 2026 Mar 05, 2026
Feb 06, 2026
Mar 05, 2026
4.2 MEDIUM
CVE-2026-0598 — Ansible-lightspeed: broken object level authorization leading to cross-user ai conversati…

A security flaw was identified in the Ansible Lightspeed API conversation endpoints that handle AI chat interactions. The APIs do not properly verify whether a conversation identifier belongs to the …

Remote | Authorization
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
4.8 MEDIUM
CVE-2026-1990 — oatpp Type.hpp ObjectWrapper null pointer dereference

A security vulnerability has been detected in oatpp up to 1.3.1. This impacts the function oatpp::data::type::ObjectWrapper::ObjectWrapper of the file src/oatpp/data/type/Type.hpp. The manipulation l…

| Memory Corruption
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
5.5 MEDIUM
CVE-2026-1979 — mruby JMPNOT-to-JMPIF Optimization vm.c mrb_vm_exec use after free

A flaw has been found in mruby up to 3.4.0. This affects the function mrb_vm_exec of the file src/vm.c of the component JMPNOT-to-JMPIF Optimization. Executing a manipulation can lead to use after fr…

mruby | Memory Corruption
Feb 06, 2026 Feb 28, 2026
Feb 06, 2026
Feb 28, 2026
7.5 HIGH
CVE-2026-1978 — kalyan02 NanoCMS User Information pagesdata.txt direct request

A vulnerability was detected in kalyan02 NanoCMS up to 0.4. Affected by this issue is some unknown functionality of the file /data/pagesdata.txt of the component User Information Handler. Performing …

nanocms | Remote | Misconfiguration
Feb 06, 2026 Feb 27, 2026
Feb 06, 2026
Feb 27, 2026
6.5 MEDIUM
CVE-2026-1977 — isaacwasserman mcp-vegalite-server visualize_data eval code injection

A security vulnerability has been detected in isaacwasserman mcp-vegalite-server up to 16aefed598b8cd897b78e99b907f6e2984572c61. Affected by this vulnerability is the function eval of the component v…

Remote | Injection
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
8.8 HIGH
CVE-2025-15566 — ingress-nginx auth-proxy-set-headers nginx configuration injection

A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-proxy-set-headers` Ingress annotation can be used to inject configuration into nginx. This can lead to arb…

ingress-nginx | Remote | Injection
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
7.5 HIGH
CVE-2026-1976 — Free5GC SMF SessionDeletionResponse null pointer dereference

A weakness has been identified in Free5GC up to 4.1.0. Affected is the function SessionDeletionResponse of the component SMF. This manipulation causes null pointer dereference. The attack is possible…

free5gc | Remote | Memory Corruption
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
7.5 HIGH
CVE-2026-1975 — Free5GC pfcp_reports.go identityTriggerType null pointer dereference

A security flaw has been discovered in Free5GC up to 4.1.0. This impacts the function identityTriggerType of the file pfcp_reports.go. The manipulation results in null pointer dereference. The attack…

free5gc | Remote | Memory Corruption
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
4.3 MEDIUM
CVE-2026-1228 — Timeline Block <= 1.3.3 - Insecure Direct Object Reference to Authenticated (Author+) Pri…

The Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inclu…

Remote | Information Disclosure
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
7.5 HIGH
CVE-2026-1974 — Free5GC SMF datapath.go ResolveNodeIdToIp denial of service

A vulnerability was identified in Free5GC up to 4.1.0. This affects the function ResolveNodeIdToIp of the file internal/sbi/processor/datapath.go of the component SMF. The manipulation leads to denia…

free5gc | Remote | Denial of Service
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
7.5 HIGH
CVE-2026-1973 — Free5GC SMF establishPfcpSession null pointer dereference

A vulnerability was determined in Free5GC up to 4.1.0. The impacted element is the function establishPfcpSession of the component SMF. Executing a manipulation can lead to null pointer dereference. T…

free5gc | Remote | Memory Corruption
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
7.5 HIGH
CVE-2026-1972 — Edimax BR-6208AC auth_check_userpass2 default credentials

A vulnerability was found in Edimax BR-6208AC 2_1.02. The affected element is the function auth_check_userpass2. Performing a manipulation of the argument Username/Password results in use of default …

br-6208ac_firmware br-6208ac | Remote | Authentication
Feb 06, 2026 Feb 20, 2026
Feb 06, 2026
Feb 20, 2026
4.8 MEDIUM
CVE-2026-1971 — Edimax BR-6288ACL wiz_WISP24gmanual.asp wiz_WISP24gmanual cross site scripting

A vulnerability has been found in Edimax BR-6288ACL up to 1.12. Impacted is the function wiz_WISP24gmanual of the file wiz_WISP24gmanual.asp. Such manipulation of the argument manualssid leads to cro…

br-6288acl_firmware br-6288acl | Remote | Cross-Site Scripting
Feb 06, 2026 Feb 20, 2026
Feb 06, 2026
Feb 20, 2026
Showing 20 of 5112 Results