Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.9 MEDIUM
CVE-2026-24931 — Verifone Card Module Information Disclosure Vulnerability

Vulnerability of improper criterion security check in the card module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

harmonyos | Authorization
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
8.4 HIGH
CVE-2026-24930 — Adobe Flash UAF Concurrency Vulnerability

UAF concurrency vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Memory Corruption
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
5.9 MEDIUM
CVE-2026-24929 — Adobe Flash Out-of-bounds Read Vulnerability

Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Memory Corruption
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
8.4 HIGH
CVE-2026-24926 — "Canon Camera Out-of-Bounds Write Vulnerability"

Out-of-bounds write vulnerability in the camera module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Memory Corruption
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
7.3 HIGH
CVE-2026-24925 — Apache Image Heap Buffer Overflow

Heap-based buffer overflow vulnerability in the image module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Memory Corruption
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
6.3 MEDIUM
CVE-2026-24923 — "HPDC HDC Permission Control Vulnerability"

Permission control vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

harmonyos | Authorization
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
6.9 MEDIUM
CVE-2026-24922 — Cisco HDC Buffer Overflow Vulnerability

Buffer overflow vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Memory Corruption
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
7.1 HIGH
CVE-2026-24921 — Cisco HDC Module Read Vulnerability

Address read vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

harmonyos | Information Disclosure
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
6.0 MEDIUM
CVE-2026-24919 — "Adobe DFX Out-of-Bounds Write Vulnerability"

Out-of-bounds write vulnerability in the DFX module. Impact: Successful exploitation of this vulnerability may affect availability.

emui harmonyos | Memory Corruption
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
6.8 MEDIUM
CVE-2026-24918 — Apache Communication Module Read Vulnerability

Address read vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.

emui harmonyos | Denial of Service
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
6.5 MEDIUM
CVE-2026-24917 — Apache Security Module Use-After-Free Vulnerability

UAF vulnerability in the security module. Impact: Successful exploitation of this vulnerability may affect availability.

emui harmonyos | Memory Corruption
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
5.9 MEDIUM
CVE-2026-24916 — Microsoft Windows Identity Authentication Bypass

Identity authentication bypass vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

harmonyos | Authentication
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
7.1 HIGH
CVE-2026-24915 — Cisco Media Out-of-Bounds Read Vulnerability

Out-of-bounds read issue in the media subsystem. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

harmonyos | Memory Corruption
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
5.5 MEDIUM
CVE-2026-24914 — "Canon Camera Type Confusion Vulnerability"

Type confusion vulnerability in the camera module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Memory Corruption
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
9.8 CRITICAL
CVE-2026-21643 — Fortinet FortiClientEMS SQL Injection

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized co…

forticlientems | Remote | Injection
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
4.3 MEDIUM
CVE-2026-1785 — Code Snippets <= 3.9.4 - Cross-Site Request Forgery to Cloud Snippet Download/Update Acti…

The Code Snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.9.4. This is due to missing nonce validation on the cloud snippet download a…

Remote | Cross-Site Request Forgery
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
9.8 CRITICAL
CVE-2026-1499 — WP Duplicate <= 1.1.8 - Authenticated (Subscriber+) Arbitrary File Upload via 'process_ad…

The WP Duplicate plugin for WordPress is vulnerable to Missing Authorization leading to Arbitrary File Upload in all versions up to and including 1.1.8. This is due to a missing capability check on t…

Remote | Authorization
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
6.4 MEDIUM
CVE-2026-1252 — Events Listing Widget <= 1.3.4 - Authenticated (Author+) Stored Cross-Site Scripting via …

The Events Listing Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Event URL' parameter in all versions up to, and including, 1.3.4 due to insufficient input sanitiz…

Remote | Cross-Site Scripting
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
4.2 MEDIUM
CVE-2026-2010 — Sanluan PublicCMS Trade Payment TradePaymentService.java paid improper authorization

A vulnerability has been found in Sanluan PublicCMS up to 4.0.202506.d/5.202506.d/6.202506.d. Impacted is the function Paid of the file publiccms-parent/publiccms-trade/src/main/java/com/publiccms/lo…

publiccms | Remote | Authorization
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
6.5 MEDIUM
CVE-2026-2009 — SourceCodester Gas Agency Management System createUser.php access control

A flaw has been found in SourceCodester Gas Agency Management System 1.0. This issue affects some unknown processing of the file /gasmark/php_action/createUser.php. Executing a manipulation can lead …

gas_agency_management_system | Remote | Authorization
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
Showing 20 of 5134 Results