Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-23623 — Collabora Online vulnerable to Authorization Bypass

Collabora Online is a collaborative online office suite based on LibreOffice technology. Prior to Collabora Online Development Edition version 25.04.08.2 and prior to Collabora Online versions 23.05.…

online | Remote | Authorization
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
9.8 CRITICAL
CVE-2026-24302 — Azure Arc Elevation of Privilege Vulnerability

Azure Arc Elevation of Privilege Vulnerability

azure_arc | Remote
Feb 05, 2026 Feb 12, 2026
Feb 05, 2026
Feb 12, 2026
9.8 CRITICAL
CVE-2026-24300 — Azure Front Door Elevation of Privilege Vulnerability

Azure Front Door Elevation of Privilege Vulnerability

Feb 05, 2026 Feb 12, 2026
Feb 05, 2026
Feb 12, 2026
8.2 HIGH
CVE-2026-21532 — Azure Function Information Disclosure Vulnerability

Azure Function Information Disclosure Vulnerability

Feb 05, 2026 Feb 12, 2026
Feb 05, 2026
Feb 12, 2026
6.5 MEDIUM
CVE-2026-0391 — Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability

User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.

Feb 05, 2026 Feb 18, 2026
Feb 05, 2026
Feb 18, 2026
3.7 LOW
CVE-2025-68458 — webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-ti…

Webpack is a module bundler. From version 5.49.0 to before 5.104.1, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) can be bypassed to fetch resources from hosts out…

webpack | Remote | Server-Side Request Forgery
Feb 05, 2026 Feb 13, 2026
Feb 05, 2026
Feb 13, 2026
3.7 LOW
CVE-2025-68157 — webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects

Webpack is a module bundler. From version 5.49.0 to before 5.104.0, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) enforces allowedUris only for the initial URL, bu…

webpack | Remote | Server-Side Request Forgery
Feb 05, 2026 Feb 13, 2026
Feb 05, 2026
Feb 13, 2026
8.7 HIGH
CVE-2025-32393 — AutoGPT has a DoS vulnerability in ReadRSSFeedBlock

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6.32, there is a DoS…

autogpt_platform | Remote | Denial of Service
Feb 05, 2026 Feb 17, 2026
Feb 05, 2026
Feb 17, 2026
3.2 LOW
CVE-2026-25815 — Fortinet FortiOS LDAP Credentials Decryption Vulnerability

Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exploited in the wild from 2025-12-16 through 2026 (by default, the encryption key…

fortios | Cryptography
Feb 05, 2026 Feb 06, 2026
Feb 05, 2026
Feb 06, 2026
6.1 MEDIUM
CVE-2026-1970 — Edimax BR-6258n formStaDrvSetup redirect

A flaw has been found in Edimax BR-6258n up to 1.18. This issue affects the function formStaDrvSetup of the file /goform/formStaDrvSetup. This manipulation of the argument submit-url causes open redi…

br-6258n_firmware br-6258n | Remote | Information Disclosure
Feb 05, 2026 Feb 20, 2026
Feb 05, 2026
Feb 20, 2026
5.3 MEDIUM
CVE-2026-1964 — WeKan REST Endpoint boards.js BoardTitleRESTBleed access control

A vulnerability was determined in WeKan up to 8.20. This impacts an unknown function of the file models/boards.js of the component REST Endpoint. This manipulation causes improper access controls. Re…

wekan | Remote | Authorization
Feb 05, 2026 Feb 12, 2026
Feb 05, 2026
Feb 12, 2026
9.8 CRITICAL
CVE-2026-1963 — WeKan Attachment Storage attachments.js MoveStorageBleed access control

A vulnerability was found in WeKan up to 8.20. This affects an unknown function of the file models/attachments.js of the component Attachment Storage. The manipulation results in improper access cont…

wekan | Remote | Authorization
Feb 05, 2026 Mar 06, 2026
Feb 05, 2026
Mar 06, 2026
9.8 CRITICAL
CVE-2026-1962 — WeKan Attachment Migration attachmentMigration.js AttachmentMigrationBleed access control

A vulnerability has been found in WeKan up to 8.20. The impacted element is an unknown function of the file server/attachmentMigration.js of the component Attachment Migration. The manipulation leads…

wekan | Remote | Authorization
Feb 05, 2026 Feb 12, 2026
Feb 05, 2026
Feb 12, 2026
9.3 CRITICAL
CVE-2026-0106 — "VPU MMAP Privilege Escalation Vulnerability"

In vpu_mmap of vpu_ioctl, there is a possible arbitrary address mmap due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. Us…

android | Memory Corruption
Feb 05, 2026 Feb 19, 2026
Feb 05, 2026
Feb 19, 2026
6.5 MEDIUM
CVE-2025-12131 — Truncated 802.15.4 packet leads to denial of service

A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service.

Feb 05, 2026 Feb 12, 2026
Feb 05, 2026
Feb 12, 2026
6.8 MEDIUM
CVE-2026-1301 — Out-of-bounds Write in o6 Automation GmbH Open62541

In builds with PubSub and JSON enabled, a crafted JSON message can cause the decoder to write beyond a heap-allocated array before authentication, reliably crashing the process and corrupting memory.

Remote | Memory Corruption
Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
6.5 MEDIUM
CVE-2025-15343 — Tanium addressed an incorrect default permissions vulnerability in Enforce.

Tanium addressed an incorrect default permissions vulnerability in Enforce.

service_enforce enforce | Remote | Authorization
Feb 05, 2026 Feb 10, 2026
Feb 05, 2026
Feb 10, 2026
4.3 MEDIUM
CVE-2025-15342 — Tanium addressed an improper access controls vulnerability in Reputation.

Tanium addressed an improper access controls vulnerability in Reputation.

service_reputation reputation | Remote | Authorization
Feb 05, 2026 Feb 10, 2026
Feb 05, 2026
Feb 10, 2026
6.5 MEDIUM
CVE-2025-15341 — Tanium addressed an incorrect default permissions vulnerability in Benchmark.

Tanium addressed an incorrect default permissions vulnerability in Benchmark.

service_benchmark benchmark | Remote | Authorization
Feb 05, 2026 Feb 10, 2026
Feb 05, 2026
Feb 10, 2026
6.5 MEDIUM
CVE-2025-15340 — Tanium addressed an incorrect default permissions vulnerability in Comply.

Tanium addressed an incorrect default permissions vulnerability in Comply.

service_comply comply | Remote | Authorization
Feb 05, 2026 Feb 10, 2026
Feb 05, 2026
Feb 10, 2026
Showing 20 of 5112 Results