Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.1 MEDIUM
CVE-2026-2546 — LigeroSmart index.pl cross site scripting

A security vulnerability has been detected in LigeroSmart up to 6.1.26. The affected element is an unknown function of the file /otrs/index.pl. Such manipulation of the argument SortBy leads to cross…

ligerosmart | Remote | Cross-Site Scripting
Feb 16, 2026 Feb 19, 2026
Feb 16, 2026
Feb 19, 2026
6.1 MEDIUM
CVE-2026-2545 — LigeroSmart index.pl cross site scripting

A weakness has been identified in LigeroSmart up to 6.1.26. Impacted is an unknown function of the file /otrs/index.pl?Action=AgentTicketSearch. This manipulation of the argument Profile causes cross…

ligerosmart | Remote | Cross-Site Scripting
Feb 16, 2026 Feb 19, 2026
Feb 16, 2026
Feb 19, 2026
7.5 HIGH
CVE-2026-2544 — yued-fe LuLu UI run.js child_process.exec os command injection

A security flaw has been discovered in yued-fe LuLu UI up to 3.0.0. This issue affects the function child_process.exec of the file run.js. The manipulation results in os command injection. The attack…

Remote | Injection
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
5.1 MEDIUM
CVE-2026-2543 — vichan-devel vichan Password Change pages.php unverified password change

A vulnerability was identified in vichan-devel vichan up to 5.1.5. This vulnerability affects unknown code of the file inc/mod/pages.php of the component Password Change Handler. The manipulation of …

Remote | Authentication
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
7.3 HIGH
CVE-2026-2542 — Total VPN win-service.exe unquoted search path

A weakness has been identified in Total VPN 0.5.29.0 on Windows. Affected by this vulnerability is an unknown functionality of the file C:\Program Files\Total VPN\win-service.exe. Executing a manipul…

| Misconfiguration
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
7.3 HIGH
CVE-2026-2538 — Flos Freeware Notepad2 Msimg32.dll uncontrolled search path

A security flaw has been discovered in Flos Freeware Notepad2 4.2.22/4.2.23/4.2.24/4.2.25. Affected is an unknown function in the library Msimg32.dll. Performing a manipulation results in uncontrolle…

| Path Traversal
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
7.5 HIGH
CVE-2026-0929 — RegistrationMagic < 6.0.7.2 - Subscriber+ Form Creation

The RegistrationMagic WordPress plugin before 6.0.7.2 does not have proper capability checks, allowing subscribers and above to create forms on the site.

registrationmagic | Remote | Authorization
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
7.2 HIGH
CVE-2026-2537 — Comfast CF-E4 HTTP POST Request mbox-config command injection

A vulnerability was identified in Comfast CF-E4 2.6.0.1. This impacts an unknown function of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone of the component HTTP POST Request Handler. …

cf-e4_firmware cf-e4 | Remote | Injection
Feb 16, 2026 Feb 25, 2026
Feb 16, 2026
Feb 25, 2026
6.5 MEDIUM
CVE-2026-2536 — opencc JFlow Workflow WF_Admin_AttrFlow.java Imp_Done xml external entity reference

A vulnerability was determined in opencc JFlow up to 20260129. This affects the function Imp_Done of the file src/main/java/bp/wf/httphandler/WF_Admin_AttrFlow.java of the component Workflow Engine. …

Remote | XML External Entity
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
8.8 HIGH
CVE-2026-2535 — Comfast CF-N1 V2 mbox-config sub_44AB9C command injection

A vulnerability was found in Comfast CF-N1 V2 2.6.0.2. The impacted element is the function sub_44AB9C of the file /cgi-bin/mbox-config?method=SET&section=ptest_channel. The manipulation of the argum…

cf-n1_firmware cf-n1 | Remote | Injection
Feb 16, 2026 Feb 19, 2026
Feb 16, 2026
Feb 19, 2026
8.8 HIGH
CVE-2026-2534 — Comfast CF-N1 V2 mbox-config sub_44AC4C command injection

A vulnerability has been found in Comfast CF-N1 V2 2.6.0.2. The affected element is the function sub_44AC4C of the file /cgi-bin/mbox-config?method=SET&section=ptest_bandwidth. The manipulation of th…

cf-n1_firmware cf-n1 | Remote | Injection
Feb 16, 2026 Feb 19, 2026
Feb 16, 2026
Feb 19, 2026
7.5 HIGH
CVE-2026-2533 — Tosei Self-service Washing Machine tosei_datasend.php command injection

A flaw has been found in Tosei Self-service Washing Machine 4.02. Impacted is an unknown function of the file /cgi-bin/tosei_datasend.php. Executing a manipulation of the argument adr_txt_1 can lead …

Remote | Injection
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
9.8 CRITICAL
CVE-2026-2532 — lintsinghua DeepAudit IP Address embedding_config.py server-side request forgery

A vulnerability was detected in lintsinghua DeepAudit up to 3.0.3. This issue affects some unknown processing of the file backend/app/api/v1/endpoints/embedding_config.py of the component IP Address …

deepaudit | Remote | Server-Side Request Forgery
Feb 16, 2026 Feb 28, 2026
Feb 16, 2026
Feb 28, 2026
7.3 HIGH
CVE-2026-2531 — MindsDB File Upload security.py clear_filename server-side request forgery

A security vulnerability has been detected in MindsDB up to 25.14.1. This vulnerability affects the function clear_filename of the file mindsdb/utilities/security.py of the component File Upload. Suc…

mindsdb | Remote | Server-Side Request Forgery
Feb 16, 2026 Feb 19, 2026
Feb 16, 2026
Feb 19, 2026
8.8 HIGH
CVE-2026-2530 — Wavlink WL-WN579A3 wireless.cgi AddMac command injection

A weakness has been identified in Wavlink WL-WN579A3 up to 20210219. This affects the function AddMac of the file /cgi-bin/wireless.cgi. This manipulation of the argument macAddr causes command injec…

wl-wn579a3_firmware wl-wn579a3 | Remote | Injection
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
9.8 CRITICAL
CVE-2026-2529 — Wavlink WL-WN579A3 wireless.cgi DeleteMac command injection

A security flaw has been discovered in Wavlink WL-WN579A3 up to 20210219. Affected by this issue is the function DeleteMac of the file /cgi-bin/wireless.cgi. The manipulation of the argument delete_l…

wl-wn579a3_firmware wl-wn579a3 | Remote | Injection
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
9.8 CRITICAL
CVE-2026-2528 — Wavlink WL-WN579A3 wireless.cgi Delete_Mac_list command injection

A vulnerability was identified in Wavlink WL-WN579A3 up to 20210219. Affected by this vulnerability is the function Delete_Mac_list of the file /cgi-bin/wireless.cgi. The manipulation of the argument…

wl-wn579a3_firmware wl-wn579a3 | Remote | Injection
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
9.8 CRITICAL
CVE-2026-2527 — Wavlink WL-WN579A3 login.cgi command injection

A vulnerability was determined in Wavlink WL-WN579A3 up to 20210219. Affected is an unknown function of the file /cgi-bin/login.cgi. Executing a manipulation of the argument key can lead to command i…

wl-wn579a3_firmware wl-wn579a3 | Remote | Injection
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
8.8 HIGH
CVE-2026-2526 — Wavlink WL-WN579A3 wireless.cgi multi_ssid command injection

A vulnerability was found in Wavlink WL-WN579A3 up to 20210219. This impacts the function multi_ssid of the file /cgi-bin/wireless.cgi. Performing a manipulation of the argument SSID2G2 results in co…

wl-wn579a3_firmware wl-wn579a3 | Remote | Injection
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
7.5 HIGH
CVE-2026-2525 — Free5GC PFCP UDP Endpoint denial of service

A vulnerability has been found in Free5GC up to 4.1.0. This affects an unknown function of the component PFCP UDP Endpoint. Such manipulation leads to denial of service. The attack can be launched re…

free5gc | Remote | Denial of Service
Feb 16, 2026 Feb 19, 2026
Feb 16, 2026
Feb 19, 2026
Showing 20 of 5070 Results