Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.4 MEDIUM
CVE-2026-1319 — Robin Image Optimizer <= 2.0.2 - Authenticated (Author+) Stored Cross-Site Scripting via …

The Robin Image Optimizer – Unlimited Image Optimization & WebP Converter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Alternative Text' field of a Media Library image i…

Remote | Cross-Site Scripting
Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
4.3 MEDIUM
CVE-2025-13416 — ProfileGrid – User Profiles, Groups and Communities <= 5.9.7.2 - Missing Authorization to…

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized user suspension due to a missing capability check on the pm_deactivate_user_from_group() fun…

profilegrid | Remote | Authorization
Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
5.1 MEDIUM
CVE-2026-25198 — Web2py Open Redirect Vulnerability

web2py versions 2.27.1-stable+timestamp.2023.11.16.08.03.57 and prior contain an open redirect vulnerability. If this vulnerability is exploited, the user may be redirected to an arbitrary website wh…

web2py | Misconfiguration
Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
6.3 MEDIUM
CVE-2025-10258 — A time-based SQL Injection vulnerability in Infinera DNA

Infinera DNA is vulnerable to a time-based SQL injection vulnerability due to insufficient input validation, which may result in leaking of sensitive information.

infinera_dna | Injection
Feb 05, 2026 Feb 26, 2026
Feb 05, 2026
Feb 26, 2026
8.2 HIGH
CVE-2026-1953 — Stored Cross Site Scripting(XSS) in Nukegraphic CMS V3.1.2

Nukegraphic CMS v3.1.2 contains a stored cross-site scripting (XSS) vulnerability in the user profile edit functionality at /ngc-cms/user-edit-profile.php. The application fails to properly sanitize …

Remote | Cross-Site Scripting
Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
6.4 MEDIUM
CVE-2026-1268 — Dynamic Widget Content <= 1.3.6 - Authenticated (Contributor+) Stored Cross-Site Scriptin…

The Dynamic Widget Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget content field in the Gutenberg editor sidebar in all versions up to, and including, 1.3.6 d…

Remote | Cross-Site Scripting
Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
4.9 MEDIUM
CVE-2026-1246 — ShortPixel Image Optimizer <= 6.4.2 - Authenticated (Editor+) Arbitrary File Read via 'lo…

The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Arbitrary File Read via path traversal in the 'loadFile' parameter in all versions up to, and including, 6.4.2 due to insufficient…

image_optimizer | Remote | Path Traversal
Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
6.4 MEDIUM
CVE-2026-0867 — Essential Widgets <= 3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via M…

The Essential Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ew-author, ew-archive, ew-category, ew-page, and ew-menu shortcodes in all versions up to, and…

essential_widgets | Remote | Cross-Site Scripting
Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
8.8 HIGH
CVE-2025-15080 — Information Disclosure, Information Tampering, and Denial of Service (DoS) Vulnerability …

Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric MELSEC iQ-R Series R08PCPU, R16PCPU, R32PCPU, and R120PCPU allows an unauthenticated attacker to read device da…

melsec_iq-r_firmware | Remote | Information Disclosure
Feb 05, 2026 Feb 06, 2026
Feb 05, 2026
Feb 06, 2026
8.6 HIGH
CVE-2025-61732 — Potential code smuggling via doc comments in cmd/cgo

A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.

go | Supply Chain
Feb 05, 2026 Feb 10, 2026
Feb 05, 2026
Feb 10, 2026
8.8 HIGH
CVE-2025-10314 — Malicious Code Execution Vulnerability in Mitsubishi Small-Capacity UPS Shutdown Software…

Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation FREQSHIP-mini for Windows versions 8.0.0 to 8.0.2 allows a local attacker to execute arbitrary code with system privileg…

| Misconfiguration
Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
7.2 HIGH
CVE-2025-11730 — Zyxel ATP/USG FLEX/USG20-W Command Injection Vulnerability

A post‑authentication command injection vulnerability in the Dynamic DNS (DDNS) configuration CLI command in Zyxel ATP series firmware versions from V5.35 through V5.41, USG FLEX series firmware vers…

Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
6.5 MEDIUM
CVE-2026-1898 — WeKan LDAP User Sync syncUser.js SyncLDAPBleed access control

A vulnerability was determined in WeKan up to 8.20. This affects an unknown part of the file packages/wekan-ldap/server/syncUser.js of the component LDAP User Sync. This manipulation causes improper …

wekan | Remote | Authorization
Feb 05, 2026 Feb 10, 2026
Feb 05, 2026
Feb 10, 2026
5.3 MEDIUM
CVE-2026-1897 — WeKan Position-History Tracking positionHistory.js PositionHistoryBleed authorization

A vulnerability was found in WeKan up to 8.20. Affected by this issue is some unknown functionality of the file server/methods/positionHistory.js of the component Position-History Tracking. The manip…

wekan | Remote | Authorization
Feb 05, 2026 Feb 10, 2026
Feb 05, 2026
Feb 10, 2026
6.5 MEDIUM
CVE-2026-1896 — WeKan Migration Operation comprehensiveBoardMigration.js ComprehensiveBoardMigration Migr…

A vulnerability has been found in WeKan up to 8.20. Affected by this vulnerability is the function ComprehensiveBoardMigration of the file server/migrations/comprehensiveBoardMigration.js of the comp…

wekan | Remote | Authorization
Feb 05, 2026 Feb 10, 2026
Feb 05, 2026
Feb 10, 2026
8.2 HIGH
CVE-2025-13192 — Popup builder with Gamification <= 2.2.0 - Unauthenticated SQL Injection via Multiple RES…

The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPress is vulnerable to generic SQL Injection via the multiple REST API endpoints …

Remote | Injection
Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
8.5 HIGH
CVE-2019-25288 — Wacom WTabletService 6.6.7-3 - 'WTabletServicePro' Unquoted Service Path

Wacom WTabletService 6.6.7-3 contains an unquoted service path vulnerability that allows local attackers to execute malicious code with elevated privileges. Attackers can insert an executable file in…

| Misconfiguration
Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
8.5 HIGH
CVE-2019-25287 — Adaware Web Companion version 4.8.2078.3950 - 'WCAssistantService' Unquoted Service Path

Adaware Web Companion version 4.8.2078.3950 contains an unquoted service path vulnerability in the WCAssistantService that allows local users to potentially execute code with elevated privileges. Att…

| Misconfiguration
Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
8.5 HIGH
CVE-2019-25286 — _GCafé 3.0 - 'gbClienService' Unquoted Service Path

GCafé 3.0 contains an unquoted service path vulnerability in the gbClientService that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the …

| Path Traversal
Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
8.5 HIGH
CVE-2019-25285 — Alps Pointing-device Controller 8.1202.1711.04 - 'ApHidMonitorService' Unquoted Service P…

Alps Pointing-device Controller 8.1202.1711.04 contains an unquoted service path vulnerability in the ApHidMonitorService that allows local attackers to execute code with elevated privileges. Attacke…

| Misconfiguration
Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
Showing 20 of 5110 Results