Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.0 MEDIUM
CVE-2026-0619 — Integer Wraparound DoS in Silicon Labs Matter Implementation

A reachable infinite loop via an integer wraparound is present in Silicon Labs' Matter SDK which allows an attacker to trigger a denial of service. A hard reset is required to recover the device.

Remote | Denial of Service
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
7.5 HIGH
CVE-2026-25949 — Traefik: TCP readTimeout bypass via STARTTLS on Postgres

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.8, there is a potential vulnerability in Traefik managing STARTTLS requests. An unauthenticated client can bypass Traefik entrypoint r…

traefik | Remote | Denial of Service
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
6.8 MEDIUM
CVE-2026-25933 — Arduino App Lab has Improper Data Validation in Internal Terminal Interface

Arduino App Lab is a cross-platform IDE for developing Arduino Apps. Prior to 0.4.0, a vulnerability was identified in the Terminal component of the arduino-app-lab application. The issue stems from …

app_lab | Injection
Feb 12, 2026 Feb 19, 2026
Feb 12, 2026
Feb 19, 2026
8.8 HIGH
CVE-2026-25922 — authentik has a Signature Verification Bypass via SAML Assertion Wrapping

authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Assertion Signature under Verification Certificate enab…

authentik | Remote | Authentication
Feb 12, 2026 Feb 18, 2026
Feb 12, 2026
Feb 18, 2026
7.1 HIGH
CVE-2026-25768 — LavinMQ is missing vhost access control

LavinMQ is a high-performance message queue & streaming server. Before 2.6.6, an authenticated user could access metadata in the broker they should not have access to. This vulnerability is fixed in …

lavinmq | Remote | Authorization
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
8.6 HIGH
CVE-2026-25767 — LavinMQ has incomplete shovel configuration validation

LavinMQ is a high-performance message queue & streaming server. Before 2.6.8, an authenticated user, with the “Policymaker” tag, could create shovels bypassing access controls. an authenticated user …

lavinmq | Remote | Authorization
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
8.6 HIGH
CVE-2026-25748 — authentik has a forward authentication bypass with broken cookie

authentik is an open-source identity provider. Prior to 2025.10.4 and 2025.12.4, with a malformed cookie it was possible to bypass authentication when using forward authentication in the authentik Pr…

authentik | Remote | Authentication
Feb 12, 2026 Feb 19, 2026
Feb 12, 2026
Feb 19, 2026
9.1 CRITICAL
CVE-2026-25227 — authentik affected by Remote Code Execution via Context Key Injection in PropertyMapping …

authentik is an open-source identity provider. From 2021.3.1 to before 2025.8.6, 2025.10.4, and 2025.12.4, when using delegated permissions, a User that has the permission Can view * Property Mapping…

authentik | Remote | Authorization
Feb 12, 2026 Feb 19, 2026
Feb 12, 2026
Feb 19, 2026
9.8 CRITICAL
CVE-2026-24895 — FrankenPHP affected by Path Confusion via Unicode casing in CGI path splitting allows exe…

FrankenPHP is a modern application server for PHP. Prior to 1.11.2, FrankenPHP’s CGI path splitting logic improperly handles Unicode characters during case conversion. The logic computes the split in…

frankenphp | Remote | Path Traversal
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
8.7 HIGH
CVE-2026-24894 — FrankenPHP leaks session data between requests in worker mode

FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSION superglobal is not correctly reset between requests. This allows a subsequent…

frankenphp | Remote | Information Disclosure
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
9.2 CRITICAL
CVE-2026-24044 — ESS Community Helm Chart has a weak server key generation method

Element Server Suite Community Edition (ESS Community) deploys a Matrix stack using the provided Helm charts and Kubernetes distribution. The ESS Community Helm Chart secrets initialization hook (usi…

Remote | Cryptography
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
9.8 CRITICAL
CVE-2025-70314 — Webfsd Buffer Overflow Vulnerability

webfsd 1.21 is vulnerable to a Buffer Overflow via a crafted request. This is due to the filename variable

webfsd | Remote | Memory Corruption
Feb 12, 2026 Feb 18, 2026
Feb 12, 2026
Feb 18, 2026
7.5 HIGH
CVE-2025-67433 — Open TFTP Server MultiThreaded Heap Buffer Overflow

A heap buffer overflow in the processRequest function of Open TFTP Server MultiThreaded v1.7 allows attackers to cause a Denial of Service (DoS) via a crafted DATA packet.

Remote | Memory Corruption
Feb 12, 2026 Feb 26, 2026
Feb 12, 2026
Feb 26, 2026
7.5 HIGH
CVE-2025-67432 — Monkeybread Software MBS DynaPDF Plugin Stack Overflow DoS

A stack overflow in the ZBarcode_Encode function of Monkeybread Software MBS DynaPDF Plugin v21.3.1.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

Remote | Memory Corruption
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
7.5 HIGH
CVE-2019-25347 — thesystem App 1.0 - 'username' SQL Injection

thesystem App 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating the username parameter. Attackers can inject malicious SQL code like ' or '1=1 …

password_management_application | Remote | Injection
Feb 12, 2026 Mar 02, 2026
Feb 12, 2026
Mar 02, 2026
7.5 HIGH
CVE-2019-25346 — thesystem 1.0 - 'server_name' SQL Injection

TheSystem 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating the 'server_name' parameter. Attackers can inject malicious SQL code like ' or '1=1…

password_management_application | Remote | Injection
Feb 12, 2026 Mar 02, 2026
Feb 12, 2026
Mar 02, 2026
8.5 HIGH
CVE-2019-25345 — RTK IIS Codec Service 6.4.10041.133 - 'RtkI2SCodec' Unquote Service Path

Realtek IIS Codec Service 6.4.10041.133 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in t…

| Misconfiguration
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
8.5 HIGH
CVE-2019-25344 — MobileGo 8.5.0 - Insecure File Permissions

Wondershare MobileGo 8.5.0 contains an insecure file permissions vulnerability that allows local users to modify executable files in the application directory. Attackers can replace the original Mobi…

mobiletrans mobilego | Misconfiguration
Feb 12, 2026 Feb 26, 2026
Feb 12, 2026
Feb 26, 2026
8.5 HIGH
CVE-2019-25343 — NextVPN 4.10 - Insecure File Permissions

NextVPN 4.10 contains an insecure file permissions vulnerability that allows local users to modify executable files with full access rights. Attackers can replace system executables with malicious fi…

| Misconfiguration
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
9.3 CRITICAL
CVE-2026-26219 — newbee-mall Unsalted MD5 Password Hashing Enables Offline Credential Cracking

newbee-mall stores and verifies user passwords using an unsalted MD5 hashing algorithm. The implementation does not incorporate per-user salts or computational cost controls, enabling attackers who o…

newbee-mall | Remote | Cryptography
Feb 12, 2026 Feb 25, 2026
Feb 12, 2026
Feb 25, 2026
Showing 20 of 4997 Results