Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-1709 — Keylime: keylime: authentication bypass allows unauthorized administrative operations due…

A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows u…

Feb 06, 2026 Mar 05, 2026
Feb 06, 2026
Mar 05, 2026
3.3 LOW
CVE-2025-15320 — Tanium addressed a denial of service vulnerability in Tanium Client.

Tanium addressed a denial of service vulnerability in Tanium Client.

client | Denial of Service
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
7.2 HIGH
CVE-2026-2063 — D-Link DIR-823X Web Management set_ac_server os command injection

A security flaw has been discovered in D-Link DIR-823X 250416. This vulnerability affects unknown code of the file /goform/set_ac_server of the component Web Management Interface. The manipulation of…

dir-823x_firmware dir-823x | Remote | Injection
Feb 06, 2026 Feb 11, 2026
Feb 06, 2026
Feb 11, 2026
7.5 HIGH
CVE-2026-2062 — Open5GS PGW S5U Address sgwc_sxa_handle_session_modification_response null pointer derefe…

A vulnerability was identified in Open5GS up to 2.7.6. This affects the function sgwc_s5c_handle_modify_bearer_response/sgwc_sxa_handle_session_modification_response of the component PGW S5U Address …

open5gs | Remote | Memory Corruption
Feb 06, 2026 Feb 11, 2026
Feb 06, 2026
Feb 11, 2026
9.8 CRITICAL
CVE-2026-25753 — PlaciPy has a Hard-Coded Default Password for All Student Accounts (Account Takeover)

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application uses a hard-coded, static default password for all newly created student accounts. Th…

placipy | Remote | Authentication
Feb 06, 2026 Feb 11, 2026
Feb 06, 2026
Feb 11, 2026
9.3 CRITICAL
CVE-2026-25752 — FUXA Unauthenticated Remote Arbitrary Device Tag Write

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An authorization bypass vulnerability in FUXA allows an unauthenticated, remote attacker to modify device tags via WebSockets…

fuxa | Remote | Authorization
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
9.1 CRITICAL
CVE-2026-25751 — FUXA Unauthenticated Exposure of Plaintext Database Credentials

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An information disclosure vulnerability in FUXA allows an unauthenticated, remote attacker to retrieve sensitive administrati…

fuxa | Remote | Information Disclosure
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
6.1 MEDIUM
CVE-2026-25651 — client-certificate-auth has an Open Redirect via Host Header Injection in HTTP-to-HTTPS r…

client-certificate-auth is middleware for Node.js implementing client SSL certificate authentication/authorization. Versions 0.2.1 and 0.3.0 of client-certificate-auth contain an open redirect vulner…

client-certificate-auth | Remote | Misconfiguration
Feb 06, 2026 Feb 24, 2026
Feb 06, 2026
Feb 24, 2026
7.5 HIGH
CVE-2026-25650 — MCP Salesforce Connector has arbitrary attribute access which leads to disclosure of Sale…

MCP Salesforce Connector is a Model Context Protocol (MCP) server implementation for Salesforce integration. Prior to 0.1.10, arbitrary attribute access leads to disclosure of Salesforce auth token. …

mcp_salesforce_connector | Remote | Information Disclosure
Feb 06, 2026 Feb 24, 2026
Feb 06, 2026
Feb 24, 2026
5.4 MEDIUM
CVE-2026-25647 — Lute has a Stored Cross-Site Scripting (XSS) via Markdown hyperlink

Lute is a structured Markdown engine supporting Go and JavaScript. Lute 1.7.6 and earlier (as used in SiYuan before) has a Stored Cross-Site Scripting (XSS) vulnerability in the Markdown rendering en…

siyuan | Remote | Cross-Site Scripting
Feb 06, 2026 Feb 24, 2026
Feb 06, 2026
Feb 24, 2026
8.7 HIGH
CVE-2026-24418 — OpenSTAManager has an SQL Injection vulnerability in the Scadenzario bulk operations modu…

OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contain a critical Error-Based SQL Injection vulnerability in the bulk o…

openstamanager | Remote | Injection
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
8.7 HIGH
CVE-2026-24417 — OpenSTAManager has a Time-Based Blind SQL Injection with Amplified Denial of Service

OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contain a critical Time-Based Blind SQL Injection vulnerability in the g…

openstamanager | Remote | Injection
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
8.7 HIGH
CVE-2026-24416 — OpenSTAManager has a Time-Based Blind SQL Injection in Article Pricing Module

OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contain a critical Time-Based Blind SQL Injection vulnerability in the a…

openstamanager | Remote | Injection
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
5.4 MEDIUM
CVE-2026-24050 — Zulip affected by Stored XSS in user profile modal

Zulip is an open-source team collaboration tool. From 5.0 to before 11.5, some administrative actions on the user profile were susceptible to stored XSS in group names or channel names. Exploiting th…

zulip zulip_server | Remote | Cross-Site Scripting
Feb 06, 2026 Feb 23, 2026
Feb 06, 2026
Feb 23, 2026
8.2 HIGH
CVE-2026-23989 — REVA Public Link Exploit

REVA is an interoperability platform. Prior to 2.42.3 and 2.40.3, a bug in the GRPC authorization middleware of the "Reva" component of OpenCloud allows a malicious user to bypass the scope verificat…

opencloud_reva | Remote | Authorization
Feb 06, 2026 Feb 24, 2026
Feb 06, 2026
Feb 24, 2026
8.7 HIGH
CVE-2025-69216 — OpenSTAManager has an SQL Injection in Scadenzario Print Template

OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an authenticated SQL injection vulnerability in OpenSTAManager's Scadenzario (Paymen…

openstamanager | Remote | Injection
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
8.8 HIGH
CVE-2025-69214 — OpenSTAManager has a SQL Injection in ajax_select.php (componenti endpoint)

OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an SQL Injection vulnerability exists in the ajax_select.php endpoint when handling …

openstamanager | Remote | Injection
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
9.4 CRITICAL
CVE-2025-69212 — OpenSTAManager has an OS Command Injection in P7M File Processing

OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a critical OS Command Injection vulnerability exists in the P7M (signed XML) file de…

openstamanager | Remote | Injection
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
7.2 HIGH
CVE-2026-2061 — D-Link DIR-823X set_ipv6 sub_424D20 os command injection

A vulnerability was determined in D-Link DIR-823X 250416. Affected by this issue is the function sub_424D20 of the file /goform/set_ipv6. Executing a manipulation can lead to os command injection. It…

dir-823x_firmware dir-832x | Remote | Injection
Feb 06, 2026 Feb 11, 2026
Feb 06, 2026
Feb 11, 2026
9.8 CRITICAL
CVE-2026-2060 — code-projects Simple Blood Donor Management System editcampaignform.php sql injection

A vulnerability was found in code-projects Simple Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /simpleblooddonor/editcampaignform.php. Per…

Feb 06, 2026 Feb 11, 2026
Feb 06, 2026
Feb 11, 2026
Showing 20 of 5092 Results