Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2025-69248 — free5GC has Array Index Out of Bounds in AMF Leading to Denial of Service

free5GC is an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.1 of free5GC's AMF service have a Buffer Overflow vulnerability leading to Denial of S…

free5gc amf | Remote | Denial of Service
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
7.5 HIGH
CVE-2025-69247 — free5GC has Heap Buffer Overflow in UPF Leading to Denial of Service

free5GC go-upf is the User Plane Function (UPF) implementation for 5G networks that is part of the free5GC project. Versions prior to 1.2.8 have a Heap-based Buffer Overflow (CWE-122) vulnerability l…

free5gc go-upf | Remote | Memory Corruption
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
7.5 HIGH
CVE-2025-69232 — free5GC hasProtocol Compliance Violation in UPF Leading to SMF Service Disruption

free5GC is an open-source project for 5th generation (5G) mobile core networks. free5GC go-upf versions up to and including 1.2.6, corresponding to free5gc smf up to and including 1.4.0, have an Impr…

free5gc smf go-upf | Remote | Denial of Service
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
5.3 MEDIUM
CVE-2025-69208 — free5GC UDR's NEF incorrectly returns 500 for missing PFD data (UDR 404) in Nnef_PfdManag…

free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. Versions prior to 1.4.1 contain an Improper Error Handling vulnerabi…

free5gc udr | Remote | Information Disclosure
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
5.3 MEDIUM
CVE-2026-3075 — WordPress Simple Ajax Chat plugin <= 20251121 - Sensitive Data Exposure vulnerability

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Jeff Starr Simple Ajax Chat simple-ajax-chat allows Retrieve Embedded Sensitive Data.This issue affects Sim…

simple_ajax_chat | Remote | Information Disclosure
Feb 23, 2026 Feb 27, 2026
Feb 23, 2026
Feb 27, 2026
6.1 MEDIUM
CVE-2026-3027 — erzhongxmu JEEWMS UEditor getContent.jsp cross site scripting

A vulnerability was found in erzhongxmu JEEWMS up to 3.7. This affects an unknown part of the file src/main/webapp/plug-in/ueditor/jsp/getContent.jsp of the component UEditor. The manipulation of the…

jeewms | Remote | Cross-Site Scripting
Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
7.5 HIGH
CVE-2026-3026 — erzhongxmu JEEWMS UEditor getRemoteImage.jsp server-side request forgery

A vulnerability has been found in erzhongxmu JEEWMS 3.7. Affected by this issue is some unknown functionality of the file /plug-in/ueditor/jsp/getRemoteImage.jsp of the component UEditor. The manipul…

jeewms | Remote | Server-Side Request Forgery
Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
9.8 CRITICAL
CVE-2026-3025 — ShuoRen Smart Heating Integrated Management Platform ExampleNodeService.asmx unrestricted…

A flaw has been found in ShuoRen Smart Heating Integrated Management Platform 1.0.0. Affected by this vulnerability is an unknown functionality of the file /MP/Service/Webservice/ExampleNodeService.a…

smart_heating_integrated_management_platform | Remote | Misconfiguration
Feb 23, 2026 Mar 03, 2026
Feb 23, 2026
Mar 03, 2026
8.7 HIGH
CVE-2026-25648 — Traccar Vulnerable to Stored Cross-Site Scripting (XSS) via Malicious SVG File Upload

Versions of the Traccar open-source GPS tracking system starting with 6.11.1 contain an issue in which authenticated users can execute arbitrary JavaScript in the context of other users' browsers by …

traccar | Remote | Cross-Site Scripting
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
5.1 MEDIUM
CVE-2026-23694 — Aruba HiSpeed Cache < 3.0.5 CSRF in Multiple Administrative AJAX Actions

Aruba HiSpeed Cache (aruba-hispeed-cache) WordPress plugin versions prior to 3.0.5 contain a cross-site request forgery (CSRF) vulnerability affecting multiple administrative AJAX actions. The handle…

aruba_hispeed_cache | Remote | Cross-Site Request Forgery
Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
10.0 CRITICAL
CVE-2026-23693 — ElementsKit Elementor Addons < 3.7.9 Unauthenticated Mailchimp REST Endpoint

ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor (elementskit-lite) WordPress plugin versions prior to 3.7.9 expose the REST endpoint /wp-json/elementskit/v1/widget/ma…

Remote | Server-Side Request Forgery
Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
6.5 MEDIUM
CVE-2026-23521 — Traccar vulnerable to Path Traversal and External Control of File Name or Path

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users who can create or edit devices can set a device `uniqueId` to an absol…

traccar | Remote | Path Traversal
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
9.1 CRITICAL
CVE-2025-71056 — GCOM EPON Session Hijacking Vulnerability

Improper session management in GCOM EPON 1GE ONU version C00R371V00B01 allows attackers to execute a session hijacking attack via spoofing the IP address of an authenticated user.

Remote | Authentication
Feb 23, 2026 Feb 27, 2026
Feb 23, 2026
Feb 27, 2026
8.8 HIGH
CVE-2025-70328 — TOTOLINK X6000R OS Command Injection

TOTOLINK X6000R v9.4.0cu.1498_B20250826 contains an OS command injection vulnerability in the NTPSyncWithHost handler of the /usr/sbin/shttpd executable. The host_time parameter is retrieved via sub_…

x6000r_firmware x6000r | Remote | Injection
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2025-70327 — TOTOLINK X5000R Argument Injection Vulnerability

TOTOLINK X5000R v9.1.0cu_2415_B20250515 contains an argument injection vulnerability in the setDiagnosisCfg handler of the /usr/sbin/lighttpd executable. The ip parameter is retrieved via websGetVar …

x5000r_firmware x5000r | Remote | Injection
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
7.1 HIGH
CVE-2025-68930 — Traccar Missing Origin Validation in WebSockets

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability in the `/api/socket` endpoint. The application fails …

traccar | Remote | Authentication
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
7.5 HIGH
CVE-2026-27623 — Valkey has Pre-Authentication DOS from malformed RESP request

Valkey is a distributed key-value database. Starting in version 9.0.0 and prior to version 9.0.3, a malicious actor with network access to Valkey can cause the system to abort by triggering an assert…

valkey | Remote | Denial of Service
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
7.5 HIGH
CVE-2026-21863 — Malformed Valkey Cluster bus message can lead to Remote DoS

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus port can send an invalid packet that may cause an…

valkey | Remote | Denial of Service
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
8.0 HIGH
CVE-2025-70329 — TOTOLink X5000R OS Command Injection Vulnerability

TOTOLink X5000R v9.1.0cu_2415_B20250515 contains an OS command injection vulnerability in the setIptvCfg handler of the /usr/sbin/lighttpd executable. The vlanVidLan1 (and other vlanVidLanX) paramete…

x5000r_firmware x5000r | Injection
Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
8.5 HIGH
CVE-2025-67733 — Valkey Affected by RESP Protocol Injection via Lua error_reply

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary information into the response stream for…

valkey | Remote | Injection
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
Showing 20 of 5313 Results