Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.2 CRITICAL
CVE-2026-2564 — Intelbras VIP 3260 Z IA OutsideCmd password recovery

A security flaw has been discovered in Intelbras VIP 3260 Z IA 2.840.00IB005.0.T. Affected by this vulnerability is an unknown functionality of the file /OutsideCmd. The manipulation results in weak …

Remote | Authentication
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
8.7 HIGH
CVE-2026-2101 — Reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIAvpm Web Access from EN…

A Reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIAvpm Web Access from ENOVIAvpm Version 1 Release 16 through ENOVIAvpm Version 1 Release 19 allows an attacker to execute arbitrary …

Remote | Cross-Site Scripting
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
7.2 HIGH
CVE-2026-26930 — SmarterTools SmarterMail MAPI Cross-Site Scripting Vulnerability

SmarterTools SmarterMail before 9526 allows XSS via MAPI requests.

smartermail | Remote | Cross-Site Scripting
Feb 16, 2026 Feb 22, 2026
Feb 16, 2026
Feb 22, 2026
8.8 HIGH
CVE-2026-2563 — JingDong JD Cloud Box AX6600 jdcapp_rpc controlDevice get_status privileges management

A vulnerability was identified in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. Affected is the function set_stcreenen_deabled_status/get_status of the file /f/service/controlDevice of the componen…

ax6600_firmware ax6600 | Remote | Authentication
Feb 16, 2026 Feb 23, 2026
Feb 16, 2026
Feb 23, 2026
9.1 CRITICAL
CVE-2025-65717 — Visual Studio Code Extensions Live Server File Exfiltration Vulnerability

An issue in Visual Studio Code Extensions Live Server v5.7.9 allows attackers to exfiltrate files via user interaction with a crafted HTML page.

live_server | Remote | Path Traversal
Feb 16, 2026 Feb 25, 2026
Feb 16, 2026
Feb 25, 2026
8.8 HIGH
CVE-2025-65716 — Visual Studio Code Extensions Markdown Preview Enhanced Code Execution Vulnerability

An issue in Visual Studio Code Extensions Markdown Preview Enhanced v0.8.18 allows attackers to execute arbitrary code via uploading a crafted .Md file.

markdown_preview_enhanced | Remote | Injection
Feb 16, 2026 Feb 25, 2026
Feb 16, 2026
Feb 25, 2026
7.8 HIGH
CVE-2025-65715 — "Code Runner Code Execution Vulnerability"

An issue in the code-runner.executorMap setting of Visual Studio Code Extensions Code Runner v0.12.2 allows attackers to execute arbitrary code when opening a crafted workspace.

coderunner | Misconfiguration
Feb 16, 2026 Feb 25, 2026
Feb 16, 2026
Feb 25, 2026
8.8 HIGH
CVE-2026-2562 — JingDong JD Cloud Box AX6600 jdcweb_rpc jdcapi cast_streen privileges management

A vulnerability was determined in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. This impacts the function cast_streen of the file /jdcapi of the component jdcweb_rpc. Executing a manipulation of th…

ax6600_firmware ax6600 | Remote | Authorization
Feb 16, 2026 Feb 23, 2026
Feb 16, 2026
Feb 23, 2026
8.8 HIGH
CVE-2026-2561 — JingDong JD Cloud Box AX6600 jdcweb_rpc jdcapi web_get_ddns_uptime privileges management

A vulnerability was found in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. This affects the function web_get_ddns_uptime of the file /jdcapi of the component jdcweb_rpc. Performing a manipulation r…

ax6600_firmware ax6600 | Remote | Authentication
Feb 16, 2026 Feb 23, 2026
Feb 16, 2026
Feb 23, 2026
8.8 HIGH
CVE-2026-2447 — Heap buffer overflow in libvpx

Heap buffer overflow in libvpx. This vulnerability affects Firefox < 147.0.4, Firefox ESR < 140.7.1, Firefox ESR < 115.32.1, Thunderbird < 140.7.2, and Thunderbird < 147.0.2.

firefox firefox_esr thunderbird | Remote | Memory Corruption
Feb 16, 2026 Feb 22, 2026
Feb 16, 2026
Feb 22, 2026
4.3 MEDIUM
CVE-2026-2032 — Interrupted page loads in new tabs could allow website spoofing under trusted domains in …

Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page content, allowing the attacker to spoof arbitrary HTML under a trusted domain. Thi…

firefox | Remote | Cross-Site Scripting
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
6.5 MEDIUM
CVE-2026-2560 — kalcaddle kodbox Media File Preview Plugin VideoResize.class.php run os command injection

A vulnerability has been found in kalcaddle kodbox up to 1.64.05. The impacted element is the function run of the file plugins/fileThumb/lib/VideoResize.class.php of the component Media File Preview …

kodbox | Remote | Injection
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
6.5 MEDIUM
CVE-2026-2558 — GeekAI net_handler.go Download server-side request forgery

A flaw has been found in GeekAI up to 4.2.4. The affected element is the function Download of the file api/handler/net_handler.go. This manipulation of the argument url causes server-side request for…

Remote | Server-Side Request Forgery
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
5.4 MEDIUM
CVE-2026-2557 — cskefu File Upload MediaController.java upload cross site scripting

A vulnerability was detected in cskefu up to 8.0.1. Impacted is the function Upload of the file com/cskefu/cc/controller/resource/MediaController.java of the component File Upload. The manipulation r…

cskefu | Remote | Cross-Site Scripting
Feb 16, 2026 Feb 20, 2026
Feb 16, 2026
Feb 20, 2026
7.8 HIGH
CVE-2026-1335 — Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS…

An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an atta…

solidworks_edrawings | Memory Corruption
Feb 16, 2026 Feb 26, 2026
Feb 16, 2026
Feb 26, 2026
7.8 HIGH
CVE-2026-1334 — Out-Of-Bounds Read vulnerability affecting the EPRT file reading procedure in SOLIDWORKS …

An Out-Of-Bounds Read vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attac…

solidworks_edrawings | Memory Corruption
Feb 16, 2026 Feb 26, 2026
Feb 16, 2026
Feb 26, 2026
7.8 HIGH
CVE-2026-1333 — Use of Uninitialized Variable vulnerability affecting the EPRT file reading procedure in …

A Use of Uninitialized Variable vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allo…

solidworks_edrawings | Memory Corruption
Feb 16, 2026 Feb 26, 2026
Feb 16, 2026
Feb 26, 2026
6.5 MEDIUM
CVE-2026-2556 — cskefu Endpoint MediaController.java server-side request forgery

A security vulnerability has been detected in cskefu up to 8.0.1. This issue affects some unknown processing of the file com/cskefu/cc/controller/resource/MediaController.java of the component Endpoi…

cskefu | Remote | Server-Side Request Forgery
Feb 16, 2026 Feb 20, 2026
Feb 16, 2026
Feb 20, 2026
7.6 HIGH
CVE-2026-1046 — Arbitrary application execution via unvalidated server-controlled URLs in Help menu

Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via the user clicking o…

mattermost_server | Remote | Path Traversal
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
3.8 LOW
CVE-2025-14573 — Team Admin Bypass of Invite Permissions via allow_open_invite Field

Mattermost versions 10.11.x <= 10.11.9 fail to enforce invite permissions when updating team settings, which allows team administrators without proper permissions to bypass restrictions and add users…

mattermost_server | Remote | Authorization
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
Showing 20 of 5046 Results