Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
10.0 CRITICAL
CVE-2025-69770 — MojoPortal CMS Zip Slip Remote Command Execution Vulnerability

A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execute arbitrary commands via uploading a crafted zip file.

Remote | Path Traversal
Feb 13, 2026 Feb 13, 2026
Feb 13, 2026
Feb 13, 2026
6.2 MEDIUM
CVE-2025-66676 — IObit Unlocker Denial of Service Vulnerability

An issue in IObit Unlocker v1.3.0.11 allows attackers to cause a Denial of Service (DoS) via a crafted request.

| Denial of Service
Feb 13, 2026 Feb 13, 2026
Feb 13, 2026
Feb 13, 2026
6.1 MEDIUM
CVE-2026-2026 — Improper Access Control Allows Denial of Service

A vulnerability has been identified where weak file permissions in the Nessus Agent directory on Windows hosts could allow unauthorized access, potentially permitting Denial of Service (DoS) attacks.

windows nessus_agent agent | Misconfiguration
Feb 13, 2026 Feb 24, 2026
Feb 13, 2026
Feb 24, 2026
9.9 CRITICAL
CVE-2026-26268 — Cursor sandbox escape via Git hooks

Cursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in versions prior to 2.5. A malicious agent (ie prompt injection) could write to impr…

cursor | Remote | Misconfiguration
Feb 13, 2026 Feb 18, 2026
Feb 13, 2026
Feb 18, 2026
5.3 MEDIUM
CVE-2026-26226 — beautiful-mermaid < 0.1.3 SVG Attribute Injection

beautiful-mermaid versions prior to 0.1.3 contain an SVG attribute injection issue that can lead to cross-site scripting (XSS) when rendering attacker-controlled Mermaid diagrams. User-controlled val…

Remote | Cross-Site Scripting
Feb 13, 2026 Feb 13, 2026
Feb 13, 2026
Feb 13, 2026
7.5 HIGH
CVE-2025-70123 — Free5GC UPF Denial of Service Protocol Compliance Vulnerability

An improper input validation and protocol compliance vulnerability in free5GC v4.0.1 allows remote attackers to cause a denial of service. The UPF incorrectly accepts a malformed PFCP Association Set…

free5gc | Remote | Denial of Service
Feb 13, 2026 Feb 18, 2026
Feb 13, 2026
Feb 18, 2026
7.5 HIGH
CVE-2025-70122 — Free5GC UPF Heap Buffer Overflow

A heap buffer overflow vulnerability in the UPF component of free5GC v4.0.1 allows remote attackers to cause a denial of service via a crafted PFCP Session Modification Request. The issue occurs in t…

free5gc | Remote | Memory Corruption
Feb 13, 2026 Feb 18, 2026
Feb 13, 2026
Feb 18, 2026
7.5 HIGH
CVE-2025-70121 — Free5GC AMF Array Index Out of Bounds Denial of Service

An array index out of bounds vulnerability in the AMF component of free5GC v4.0.1 allows remote attackers to cause a denial of service via a crafted 5GS Mobile Identity in a NAS Registration Request …

free5gc | Remote | Denial of Service
Feb 13, 2026 Feb 18, 2026
Feb 13, 2026
Feb 18, 2026
5.8 MEDIUM
CVE-2025-1790 — Genetec Sipelia Plugin Privilege Escalation Vulnerability

Local privilege escalation in Genetec Sipelia Plugin. An authenticated low-privileged Windows user could exploit this vulnerability to gain elevated privileges on the affected system.

| Authorization
Feb 13, 2026 Feb 13, 2026
Feb 13, 2026
Feb 13, 2026
10.0 CRITICAL
CVE-2026-26221 — Hyland OnBase Timer Services Unauthenticated .NET Remoting RCE

Hyland OnBase contains an unauthenticated .NET Remoting exposure in the OnBase Workflow Timer Service (Hyland.Core.Workflow.NTService.exe). An attacker who can reach the service can send crafted .NET…

onbase | Remote | Information Disclosure
Feb 13, 2026 Feb 13, 2026
Feb 13, 2026
Feb 13, 2026
6.5 MEDIUM
CVE-2025-70095 — OpenSourcePOS Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted …

open_source_point_of_sale | Remote | Cross-Site Scripting
Feb 13, 2026 Feb 17, 2026
Feb 13, 2026
Feb 17, 2026
6.5 MEDIUM
CVE-2025-70094 — OpenSourcePOS Cross-Site Scripting (XSS) Vulnerability

A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into…

open_source_point_of_sale | Remote | Cross-Site Scripting
Feb 13, 2026 Feb 17, 2026
Feb 13, 2026
Feb 17, 2026
7.4 HIGH
CVE-2025-70093 — OpenSourcePOS Remote Code Execution (RCE)

An issue in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code via returning a crafted AJAX response.

open_source_point_of_sale | Remote | Injection
Feb 13, 2026 Feb 17, 2026
Feb 13, 2026
Feb 17, 2026
6.5 MEDIUM
CVE-2025-70091 — OpenSourcePOS XSS Vulnerability

A cross-site scripting (XSS) vulnerability in the Customers function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Phone N…

open_source_point_of_sale | Remote | Cross-Site Scripting
Feb 13, 2026 Feb 17, 2026
Feb 13, 2026
Feb 17, 2026
4.3 MEDIUM
CVE-2026-25531 — Kanboard TaskCreationController::duplicateProjects() endpoint does not validate user perm…

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, The fix for CVE-2023-33968 is incomplete. The TaskCreationController::duplicateProjects() endpoint does not val…

kanboard | Remote | Authorization
Feb 13, 2026 Feb 13, 2026
Feb 13, 2026
Feb 13, 2026
5.1 MEDIUM
CVE-2026-1578 — HP App – Potential Cross-Site Scripting

HP App for Android is potentially vulnerable to cross-site scripting (XSS) when using an outdated version of the application via mobile devices. HP is releasing updates to mitigate these potential vu…

| Cross-Site Scripting
Feb 13, 2026 Feb 13, 2026
Feb 13, 2026
Feb 13, 2026
0.0 NA
CVE-2026-23112 — nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec nvmet_tcp_build_pdu_iovec() could walk past cmd->req.sg when a PDU leng…

linux_kernel | Memory Corruption
Feb 13, 2026 Feb 13, 2026
Feb 13, 2026
Feb 13, 2026
0.0 NA
CVE-2026-23111 — netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate()

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate() nft_map_catchall_activate() has an inverted eleme…

linux_kernel | Memory Corruption
Feb 13, 2026 Feb 13, 2026
Feb 13, 2026
Feb 13, 2026
8.3 HIGH
CVE-2026-1619 — IDOR in Universal Sotware's FlexCity/Kiosk

Authorization Bypass Through User-Controlled Key vulnerability in Universal Software Inc. FlexCity/Kiosk allows Exploitation of Trusted Identifiers.This issue affects FlexCity/Kiosk: from 1.0 before …

flexcity | Remote | Authorization
Feb 13, 2026 Mar 02, 2026
Feb 13, 2026
Mar 02, 2026
8.8 HIGH
CVE-2026-1618 — Admin Account Takeover in Universal Sotware's FlexCity/Kiosk

Authentication Bypass Using an Alternate Path or Channel vulnerability in Universal Software Inc. FlexCity/Kiosk allows Privilege Escalation.This issue affects FlexCity/Kiosk: from 1.0 before 1.0.36.

flexcity | Remote | Authentication
Feb 13, 2026 Mar 02, 2026
Feb 13, 2026
Mar 02, 2026
Showing 20 of 5051 Results