Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-1658 — Content spoofing vulnerability discovered in OpenText™ Directory Services

User Interface (UI) Misrepresentation of Critical Information vulnerability in OpenText™ Directory Services allows Cache Poisoning.  The vulnerability could be exploited by a bad actor to inject man…

directory_services | Remote | Misconfiguration
Feb 19, 2026 Feb 26, 2026
Feb 19, 2026
Feb 26, 2026
7.5 HIGH
CVE-2025-9208 — Stored-XSS vulnerability discovered in OpenText WSM Management Server.

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Web Site Management Server allows Stored XSS. The vulnerability could execute ma…

web_site_management_server | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 27, 2026
Feb 19, 2026
Feb 27, 2026
5.3 MEDIUM
CVE-2025-8055 — SSRF vulnerability have been discovered in OpenText™ XM Fax

Server-Side Request Forgery (SSRF) vulnerability in OpenText™ XM Fax allows Server Side Request Forgery.  The vulnerability could allow an attacker to perform blind SSRF to other systems accessib…

xm_fax | Remote | Server-Side Request Forgery
Feb 19, 2026 Feb 27, 2026
Feb 19, 2026
Feb 27, 2026
7.5 HIGH
CVE-2025-8054 — Path Traversal vulnerability have been discovered in OpenText™ XM Fax.

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText™ XM Fax allows Path Traversal.  The vulnerability could allow an attacker to arbitrarily disc…

xm_fax | Remote | Path Traversal
Feb 19, 2026 Feb 27, 2026
Feb 19, 2026
Feb 27, 2026
7.0 HIGH
CVE-2025-13672 — Reflected Cross-Site Scripting discovered in OpenText WSM Management Server.

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Web Site Management Server allows Reflected XSS. The vulnerability could allow i…

web_site_management_server | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 27, 2026
Feb 19, 2026
Feb 27, 2026
6.5 MEDIUM
CVE-2025-13671 — Cross Site request forgery vulnerability discovered in OpenText WSM Management Server.

Cross-Site Request Forgery (CSRF) vulnerability in OpenText™ Web Site Management Server allows Cross Site Request Forgery. The vulnerability could make a user, with active session inside the product,…

web_site_management_server | Remote | Cross-Site Request Forgery
Feb 19, 2026 Feb 27, 2026
Feb 19, 2026
Feb 27, 2026
5.3 MEDIUM
CVE-2026-26744 — FormaLMS User Enumeration Vulnerability

A user enumeration vulnerability exists in FormaLMS 4.1.18 and below in the password recovery functionality accessible via the /lostpwd endpoint. The application returns different error messages for …

formalms | Remote | Information Disclosure
Feb 19, 2026 Feb 26, 2026
Feb 19, 2026
Feb 26, 2026
7.1 HIGH
CVE-2026-26317 — OpenClaw affected by cross-site request forgery (CSRF) through loopback browser mutation …

OpenClaw is a personal AI assistant. Prior to 2026.2.14, browser-facing localhost mutation routes accepted cross-origin browser requests without explicit Origin/Referer validation. Loopback binding r…

openclaw | Remote | Cross-Site Request Forgery
Feb 19, 2026 Feb 26, 2026
Feb 19, 2026
Feb 26, 2026
7.5 HIGH
CVE-2026-26316 — OpenClaw has BlueBubbles webhook auth bypass via loopback proxy trust

OpenClaw is a personal AI assistant. Prior to 2026.2.13, the optional BlueBubbles iMessage channel plugin could accept webhook requests as authenticated based only on the TCP peer address being loopb…

openclaw | Remote | Authentication
Feb 19, 2026 Feb 24, 2026
Feb 19, 2026
Feb 24, 2026
7.5 HIGH
CVE-2026-26315 — Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake

go-ethereum (Geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, through a flaw in the ECIES cryptography implementation, an attacker may be able to ex…

go_ethereum | Remote | Cryptography
Feb 19, 2026 Feb 23, 2026
Feb 19, 2026
Feb 23, 2026
8.7 HIGH
CVE-2026-26314 — Go Ethereum affected by DoS via malicious p2p message

go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, a vulnerable node can be forced to shutdown/crash using a specially crafted message. T…

go_ethereum | Remote | Denial of Service
Feb 19, 2026 Feb 23, 2026
Feb 19, 2026
Feb 23, 2026
7.5 HIGH
CVE-2026-26275 — httpsig-hyper has Improper Digest Verification that May Allow Message Integrity Bypass

httpsig-hyper is a hyper extension for http message signatures. An issue was discovered in `httpsig-hyper` prior to version 0.0.23 where Digest header verification could incorrectly succeed due to mi…

httpsig-hyper | Remote | Cryptography
Feb 19, 2026 Mar 03, 2026
Feb 19, 2026
Mar 03, 2026
5.6 MEDIUM
CVE-2026-2738 — OpenVPN Buffer Overflow Denial of Service

Buffer overflow in ovpn‑dco‑win version 2.8.0 allows local attackers to cause a system crash by sending too large packets to the remote peer when the AEAD tag appears at the end of the encrypted pack…

ovpn-dco-win | Memory Corruption
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
9.8 CRITICAL
CVE-2026-27476 — RustFly 2.0.0 Command Injection via UDP Remote Control

RustFly 2.0.0 contains a command injection vulnerability in its remote UI control mechanism that accepts hex-encoded instructions over UDP port 5005 without proper sanitization. Attackers can send cr…

Remote | Injection
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
6.5 MEDIUM
CVE-2026-27440 — WordPress myCred plugin <= 2.9.7.6 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal myCred mycred allows Stored XSS.This issue affects myCred: from n/a through <= 2.9.7.6.

Remote | Cross-Site Scripting
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
5.4 MEDIUM
CVE-2026-27387 — WordPress DirectoryPress plugin <= 3.6.26 - Broken Access Control vulnerability

Missing Authorization vulnerability in designinvento DirectoryPress directorypress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DirectoryPress: from n/a …

directorypress | Remote | Authorization
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
5.9 MEDIUM
CVE-2026-27368 — WordPress Coming Soon Page, Under Construction & Maintenance Mode by SeedProd plugin <= 6…

Missing Authorization vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd coming-soon allows Exploiting Incorrectly Configured Access Control Security Levels…

Remote | Authorization
Feb 19, 2026 Feb 25, 2026
Feb 19, 2026
Feb 25, 2026
5.9 MEDIUM
CVE-2026-27360 — WordPress Photo Gallery by 10Web plugin <= 1.8.37 - Cross Site Scripting (XSS) vulnerabil…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Photo Gallery by 10Web photo-gallery allows Stored XSS.This issue affects Photo Gallery by …

photo_gallery | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
7.5 HIGH
CVE-2026-27343 — WordPress Airtifact theme <= 1.2.91 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in VanKarWai Airtifact airtifact allows PHP Local File Inclusion.This issue affec…

Remote | Path Traversal
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
5.3 MEDIUM
CVE-2026-27328 — WordPress EduBlink theme <= 2.0.7 - Broken Access Control vulnerability

Missing Authorization vulnerability in DevsBlink EduBlink edublink allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EduBlink: from n/a through <= 2.0.7.

Remote | Authorization
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
Showing 20 of 5064 Results