Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.1 HIGH
CVE-2026-0508 — Open Redirect vulnerability in SAP BusinessObjects Business Intelligence Platform

The SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker with high privileges to insert malicious URL within the application. Upon successful exploitation, the victim m…

businessobjects_business_intelligence_platform | Remote | Server-Side Request Forgery
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
6.1 MEDIUM
CVE-2026-0505 — Multiple vulnerabilities in BSP Applications of SAP Document Management System

The BSP applications allow an unauthenticated user to manipulate user-controlled URL parameters that are not sufficiently validated. This could result in unvalidated redirection to attacker-controlle…

s4core erp document_management_system | Remote | Authentication
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
7.5 HIGH
CVE-2026-0490 — Denial of service (DOS) in SAP BusinessObjects BI Platform

SAP BusinessObjects BI Platform allows an unauthenticated attacker to craft a specific network request to the trusted endpoint that breaks the authentication, which prevents the legitimate users from…

Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
9.9 CRITICAL
CVE-2026-0488 — Code Injection vulnerability in SAP CRM and SAP S/4HANA (Scripting Editor)

An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ab…

Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
5.0 MEDIUM
CVE-2026-0486 — Missing Authorization Check in ABAP based SAP systems

In ABAP based SAP systems a remote enabled function module does not perform necessary authorization checks for an authenticated user resulting in disclosure of system information.This has low impact …

solution_tools_plug-in | Remote | Authorization
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
7.5 HIGH
CVE-2026-0485 — Denial of service (DOS) vulnerability in SAP BusinessObjects BI Platform

SAP BusinessObjects BI Platform allows an unauthenticated attacker to send specially crafted requests that could cause the Content Management Server (CMS) to crash and automatically restart. By repea…

businessobjects_business_intelligence_platform | Remote | Denial of Service
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
6.5 MEDIUM
CVE-2026-0484 — Missing Authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA

Due to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an authenticated attacker could access a specific transaction code and modify the text data in the system.…

sap_basis | Remote | Authorization
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
5.5 MEDIUM
CVE-2026-2258 — aardappel lobster wfc.h WaveFunctionCollapse memory corruption

A flaw has been found in aardappel lobster up to 2025.4. Affected by this vulnerability is the function WaveFunctionCollapse in the library dev/src/lobster/wfc.h. Executing a manipulation can lead to…

lobster | Memory Corruption
Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
7.2 HIGH
CVE-2026-0845 — WCFM - WooCommerce Frontend Manager <= 6.7.24 - Authenticated (Shop Manager+) Arbitrary O…

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege esc…

Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
8.1 HIGH
CVE-2025-15314 — Tanium addressed an arbitrary file deletion vulnerability in end-user-cx.

Tanium addressed an arbitrary file deletion vulnerability in end-user-cx.

Feb 10, 2026 Feb 20, 2026
Feb 10, 2026
Feb 20, 2026
7.1 HIGH
CVE-2025-15313 — Tanium addressed an arbitrary file deletion vulnerability in Tanium EUSS.

Tanium addressed an arbitrary file deletion vulnerability in Tanium EUSS.

endpoint_euss euss | Path Traversal
Feb 10, 2026 Feb 24, 2026
Feb 10, 2026
Feb 24, 2026
7.8 HIGH
CVE-2025-15310 — Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.

Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.

Feb 10, 2026 Feb 24, 2026
Feb 10, 2026
Feb 24, 2026
4.3 MEDIUM
CVE-2025-15147 — WCFM Membership – WooCommerce Memberships for Multivendor Marketplace <= 2.11.8 - Insecur…

The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.11.8 via the '…

wcfm_membership | Remote | Authorization
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
7.7 HIGH
CVE-2026-25958 — Cube privilege escalation via a specially crafted request

Cube is a semantic layer for building data applications. From 0.27.19 to before 1.5.13, 1.4.2, and 1.0.14, it is possible to make a specially crafted request with a valid API token that leads to priv…

cube.js | Remote | Authorization
Feb 09, 2026 Feb 19, 2026
Feb 09, 2026
Feb 19, 2026
6.5 MEDIUM
CVE-2026-25957 — Cube Denial of Service (DoS) - An authenticated attacker can crash the server by sending …

Cube is a semantic layer for building data applications. From 1.1.17 to before 1.5.13 and 1.4.2, it is possible to make the entire Cube API unavailable by submitting a specially crafted request to a …

cube.js | Remote | Denial of Service
Feb 09, 2026 Feb 24, 2026
Feb 09, 2026
Feb 24, 2026
8.6 HIGH
CVE-2026-25951 — FUXA has a Path Traversal Sanitization Bypass

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.11, there is a flaw in the path sanitization logic allows an authenticated attacker with administrative privileg…

fuxa | Remote | Path Traversal
Feb 09, 2026 Feb 13, 2026
Feb 09, 2026
Feb 13, 2026
9.3 CRITICAL
CVE-2026-25939 — FUXA Unauthenticated Remote Arbitrary Scheduler Write

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10, an authorization bypass vulnerability in the FUXA allows an unauthenticated, remote attac…

fuxa | Remote | Authorization
Feb 09, 2026 Feb 13, 2026
Feb 09, 2026
Feb 13, 2026
9.8 CRITICAL
CVE-2026-25938 — FUXA Unauthenticated Remote Code Execution in Node-RED Integration

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to execu…

fuxa | Remote | Authentication
Feb 09, 2026 Feb 13, 2026
Feb 09, 2026
Feb 13, 2026
4.3 MEDIUM
CVE-2026-25934 — go-git improperly verifies data integrity values for .idx and .pack files

go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not …

go-git | Remote | Misconfiguration
Feb 09, 2026 Feb 20, 2026
Feb 09, 2026
Feb 20, 2026
7.8 HIGH
CVE-2026-25931 — vscode-spell-checker has a workspace-trust bypass Code Execution

vscode-spell-checker is a basic spell checker that works well with code and documents. Prior to v4.5.4, DocumentSettings._determineIsTrusted treats the configuration value cSpell.trustedWorkspace as …

| Misconfiguration
Feb 09, 2026 Feb 10, 2026
Feb 09, 2026
Feb 10, 2026
Showing 20 of 5086 Results