Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.1 MEDIUM
CVE-2026-2547 — LigeroSmart index.pl AgentDashboard cross site scripting

A vulnerability was detected in LigeroSmart up to 6.1.26. The impacted element is the function AgentDashboard of the file /otrs/index.pl. Performing a manipulation of the argument Subaction results i…

ligerosmart | Remote | Cross-Site Scripting
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
6.1 MEDIUM
CVE-2026-2546 — LigeroSmart index.pl cross site scripting

A security vulnerability has been detected in LigeroSmart up to 6.1.26. The affected element is an unknown function of the file /otrs/index.pl. Such manipulation of the argument SortBy leads to cross…

ligerosmart | Remote | Cross-Site Scripting
Feb 16, 2026 Feb 19, 2026
Feb 16, 2026
Feb 19, 2026
6.1 MEDIUM
CVE-2026-2545 — LigeroSmart index.pl cross site scripting

A weakness has been identified in LigeroSmart up to 6.1.26. Impacted is an unknown function of the file /otrs/index.pl?Action=AgentTicketSearch. This manipulation of the argument Profile causes cross…

ligerosmart | Remote | Cross-Site Scripting
Feb 16, 2026 Feb 19, 2026
Feb 16, 2026
Feb 19, 2026
7.5 HIGH
CVE-2026-2544 — yued-fe LuLu UI run.js child_process.exec os command injection

A security flaw has been discovered in yued-fe LuLu UI up to 3.0.0. This issue affects the function child_process.exec of the file run.js. The manipulation results in os command injection. The attack…

Remote | Injection
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
5.1 MEDIUM
CVE-2026-2543 — vichan-devel vichan Password Change pages.php unverified password change

A vulnerability was identified in vichan-devel vichan up to 5.1.5. This vulnerability affects unknown code of the file inc/mod/pages.php of the component Password Change Handler. The manipulation of …

Remote | Authentication
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
7.3 HIGH
CVE-2026-2542 — Total VPN win-service.exe unquoted search path

A weakness has been identified in Total VPN 0.5.29.0 on Windows. Affected by this vulnerability is an unknown functionality of the file C:\Program Files\Total VPN\win-service.exe. Executing a manipul…

| Misconfiguration
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
7.3 HIGH
CVE-2026-2538 — Flos Freeware Notepad2 Msimg32.dll uncontrolled search path

A security flaw has been discovered in Flos Freeware Notepad2 4.2.22/4.2.23/4.2.24/4.2.25. Affected is an unknown function in the library Msimg32.dll. Performing a manipulation results in uncontrolle…

| Path Traversal
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
7.5 HIGH
CVE-2026-0929 — RegistrationMagic < 6.0.7.2 - Subscriber+ Form Creation

The RegistrationMagic WordPress plugin before 6.0.7.2 does not have proper capability checks, allowing subscribers and above to create forms on the site.

registrationmagic | Remote | Authorization
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
7.2 HIGH
CVE-2026-2537 — Comfast CF-E4 HTTP POST Request mbox-config command injection

A vulnerability was identified in Comfast CF-E4 2.6.0.1. This impacts an unknown function of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone of the component HTTP POST Request Handler. …

cf-e4_firmware cf-e4 | Remote | Injection
Feb 16, 2026 Feb 25, 2026
Feb 16, 2026
Feb 25, 2026
6.5 MEDIUM
CVE-2026-2536 — opencc JFlow Workflow WF_Admin_AttrFlow.java Imp_Done xml external entity reference

A vulnerability was determined in opencc JFlow up to 20260129. This affects the function Imp_Done of the file src/main/java/bp/wf/httphandler/WF_Admin_AttrFlow.java of the component Workflow Engine. …

Remote | XML External Entity
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
8.8 HIGH
CVE-2026-2535 — Comfast CF-N1 V2 mbox-config sub_44AB9C command injection

A vulnerability was found in Comfast CF-N1 V2 2.6.0.2. The impacted element is the function sub_44AB9C of the file /cgi-bin/mbox-config?method=SET&section=ptest_channel. The manipulation of the argum…

cf-n1_firmware cf-n1 | Remote | Injection
Feb 16, 2026 Feb 19, 2026
Feb 16, 2026
Feb 19, 2026
8.8 HIGH
CVE-2026-2534 — Comfast CF-N1 V2 mbox-config sub_44AC4C command injection

A vulnerability has been found in Comfast CF-N1 V2 2.6.0.2. The affected element is the function sub_44AC4C of the file /cgi-bin/mbox-config?method=SET&section=ptest_bandwidth. The manipulation of th…

cf-n1_firmware cf-n1 | Remote | Injection
Feb 16, 2026 Feb 19, 2026
Feb 16, 2026
Feb 19, 2026
7.5 HIGH
CVE-2026-2533 — Tosei Self-service Washing Machine tosei_datasend.php command injection

A flaw has been found in Tosei Self-service Washing Machine 4.02. Impacted is an unknown function of the file /cgi-bin/tosei_datasend.php. Executing a manipulation of the argument adr_txt_1 can lead …

Remote | Injection
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
9.8 CRITICAL
CVE-2026-2532 — lintsinghua DeepAudit IP Address embedding_config.py server-side request forgery

A vulnerability was detected in lintsinghua DeepAudit up to 3.0.3. This issue affects some unknown processing of the file backend/app/api/v1/endpoints/embedding_config.py of the component IP Address …

deepaudit | Remote | Server-Side Request Forgery
Feb 16, 2026 Feb 28, 2026
Feb 16, 2026
Feb 28, 2026
7.3 HIGH
CVE-2026-2531 — MindsDB File Upload security.py clear_filename server-side request forgery

A security vulnerability has been detected in MindsDB up to 25.14.1. This vulnerability affects the function clear_filename of the file mindsdb/utilities/security.py of the component File Upload. Suc…

mindsdb | Remote | Server-Side Request Forgery
Feb 16, 2026 Feb 19, 2026
Feb 16, 2026
Feb 19, 2026
8.8 HIGH
CVE-2026-2530 — Wavlink WL-WN579A3 wireless.cgi AddMac command injection

A weakness has been identified in Wavlink WL-WN579A3 up to 20210219. This affects the function AddMac of the file /cgi-bin/wireless.cgi. This manipulation of the argument macAddr causes command injec…

wl-wn579a3_firmware wl-wn579a3 | Remote | Injection
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
9.8 CRITICAL
CVE-2026-2529 — Wavlink WL-WN579A3 wireless.cgi DeleteMac command injection

A security flaw has been discovered in Wavlink WL-WN579A3 up to 20210219. Affected by this issue is the function DeleteMac of the file /cgi-bin/wireless.cgi. The manipulation of the argument delete_l…

wl-wn579a3_firmware wl-wn579a3 | Remote | Injection
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
9.8 CRITICAL
CVE-2026-2528 — Wavlink WL-WN579A3 wireless.cgi Delete_Mac_list command injection

A vulnerability was identified in Wavlink WL-WN579A3 up to 20210219. Affected by this vulnerability is the function Delete_Mac_list of the file /cgi-bin/wireless.cgi. The manipulation of the argument…

wl-wn579a3_firmware wl-wn579a3 | Remote | Injection
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
9.8 CRITICAL
CVE-2026-2527 — Wavlink WL-WN579A3 login.cgi command injection

A vulnerability was determined in Wavlink WL-WN579A3 up to 20210219. Affected is an unknown function of the file /cgi-bin/login.cgi. Executing a manipulation of the argument key can lead to command i…

wl-wn579a3_firmware wl-wn579a3 | Remote | Injection
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
8.8 HIGH
CVE-2026-2526 — Wavlink WL-WN579A3 wireless.cgi multi_ssid command injection

A vulnerability was found in Wavlink WL-WN579A3 up to 20210219. This impacts the function multi_ssid of the file /cgi-bin/wireless.cgi. Performing a manipulation of the argument SSID2G2 results in co…

wl-wn579a3_firmware wl-wn579a3 | Remote | Injection
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
Showing 20 of 5046 Results