Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.1 MEDIUM
CVE-2026-27511 — Tenda F3 Clickjacking in Web Management Interface

Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a clickjacking vulnerability in the web-based administrative interface. The interface does not set the X-Frame-Options header, a…

f3_firmware f3 | Remote | Cross-Site Request Forgery
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
5.5 MEDIUM
CVE-2026-22568 — Unauthorized information retrieval in ZIA Admin UI

Improper neutralization of special elements in user-supplied input within the ZIA Admin UI could allow an authenticated administrator to access or retrieve unauthorized internal information in rare c…

zscaler_internet_access_admin_portal | Remote | Information Disclosure
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
7.6 HIGH
CVE-2026-22567 — ZIA Admin UI Input Validation Bug

Improper validation of user-supplied input in the ZIA Admin UI could allow an authenticated administrator to initiate backend functions through specific input fields in limited scenarios.

Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
9.0 HIGH
CVE-2026-3016 — UTT HiPER 810G formP2PLimitConfig strcpy buffer overflow

A vulnerability was identified in UTT HiPER 810G up to 1.7.7-171114. The affected element is the function strcpy of the file /goform/formP2PLimitConfig. The manipulation of the argument except leads …

810g_firmware 810g | Remote | Memory Corruption
Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
9.0 HIGH
CVE-2026-3015 — UTT HiPER 810G formPolicyRouteConf strcpy buffer overflow

A vulnerability was determined in UTT HiPER 810G up to 1.7.7-171114. Impacted is the function strcpy of the file /goform/formPolicyRouteConf. Executing a manipulation of the argument GroupName can le…

810g_firmware 810g | Remote | Memory Corruption
Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
8.8 HIGH
CVE-2026-2697 — Indirect Object Reference (IDOR) in Security Center

An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter.

security_center | Remote | Authorization
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
7.4 HIGH
CVE-2025-70058 — "YMFE yapi TLS/SSL Certificate Validation Bypass"

An issue pertaining to CWE-295: Improper Certificate Validation was discovered in YMFE yapi v1.12.0. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in …

yapi | Remote | Cryptography
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
7.4 HIGH
CVE-2025-70045 — Jxcore JXM TLS/SSL Certificate Validation Bypass

An issue pertaining to CWE-295: Improper Certificate Validation was discovered in jxcore jxm master. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in …

jxm | Remote | Misconfiguration
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
6.5 MEDIUM
CVE-2025-70044 — uTools-quickcommand SSL Certificate Validation Weakness

An issue pertaining to CWE-295: Improper Certificate Validation was discovered in fofolee uTools-quickcommand 5.0.3.

utools-quickcommand | Remote | Misconfiguration
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
9.1 CRITICAL
CVE-2025-70043 — Ayms TLS Certificate Validation Bypass

An issue pertaining to CWE-295: Improper Certificate Validation was discovered in Ayms node-To master. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false i…

Remote | Misconfiguration
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
7.2 HIGH
CVE-2025-14905 — 389-ds-base: 389-ds-base: remote code execution and denial of service via heap buffer ove…

A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callback` function within the `schema.c` file. This occurs because the code incorrectl…

enterprise_linux libssh gix-date | Remote | Memory Corruption
Feb 23, 2026 Mar 02, 2026
Feb 23, 2026
Mar 02, 2026
7.8 HIGH
CVE-2026-21420 — Dell Repository Manager Uncontrolled Search Path Element Remote Code Execution Vulnerabil…

Dell Repository Manager (DRM), versions prior to 3.4.8, contains an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerab…

repository_manager | Path Traversal
Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
7.5 HIGH
CVE-2025-69700 — Tenda FH1203 Stack-Based Buffer Overflow

Tenda FH1203 V2.0.1.6 contains a stack-based buffer overflow vulnerability in the modify_add_client_prio function, which is reachable via the formSetClientPrio CGI handler.

fh1203_firmware fh1203 | Remote | Memory Corruption
Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
6.5 MEDIUM
CVE-2026-2985 — Tiandy Video Surveillance System 视频监控平台 CLSBODownLoad.java downloadImage server-side requ…

A security flaw has been discovered in Tiandy Video Surveillance System 视频监控平台 7.17.0. This impacts the function downloadImage of the file /com/tiandy/easy7/core/bo/CLSBODownLoad.java. Performing a m…

Remote | Server-Side Request Forgery
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
6.9 MEDIUM
CVE-2026-2984 — SourceCodester Student Result Management System drop_user.php denial of service

A vulnerability was identified in SourceCodester Student Result Management System 1.0. This affects an unknown function of the file /admin/core/drop_user.php. Such manipulation of the argument ID lea…

Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
5.9 MEDIUM
CVE-2025-59873 — Session Token Exposure via URL Query Parameters

An information exposure vulnerability exists in Vulnerability in HCL Software ZIE for Web. The application transmits sensitive session tokens and authentication identifiers within the URL query par…

Remote | Information Disclosure
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
5.1 MEDIUM
CVE-2025-40986 — Reflected Cross-Site Scripting in PideTuCita

Reflected Cross-Site Scripting (XSS) vulnerability in PideTuCita. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL using the…

Remote | Cross-Site Scripting
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
5.1 MEDIUM
CVE-2025-40701 — Reflected Cross-Site scripting (XSS) in SOTE's SOTESHOP

Reflected Cross-Site Scripting vulnerability in SOTESHOP, version 8.3.4. THis vulnerability allows an attacker execute JavaScript code in the victim's browser when a malicious URL with the 'id' param…

soteshop | Remote | Cross-Site Scripting
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
9.8 CRITICAL
CVE-2026-2983 — SourceCodester Student Result Management System Bulk Import import_users.php access contr…

A vulnerability was determined in SourceCodester Student Result Management System 1.0. The impacted element is an unknown function of the file /admin/core/import_users.php of the component Bulk Impor…

Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
9.3 CRITICAL
CVE-2025-41002 — SQL injection in Infoticketing

SQL injection vulnerability in Infoticketing. This vulnerability allows an unauthenticated attacker to retrieve, create, update, and delete the database by sending a POST request using the 'code' p…

Remote | Injection
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
Showing 20 of 5265 Results