Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.2 HIGH
CVE-2026-0845 — WCFM - WooCommerce Frontend Manager <= 6.7.24 - Authenticated (Shop Manager+) Arbitrary O…

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege esc…

Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
8.1 HIGH
CVE-2025-15314 — Tanium addressed an arbitrary file deletion vulnerability in end-user-cx.

Tanium addressed an arbitrary file deletion vulnerability in end-user-cx.

Feb 10, 2026 Feb 20, 2026
Feb 10, 2026
Feb 20, 2026
7.1 HIGH
CVE-2025-15313 — Tanium addressed an arbitrary file deletion vulnerability in Tanium EUSS.

Tanium addressed an arbitrary file deletion vulnerability in Tanium EUSS.

endpoint_euss euss | Path Traversal
Feb 10, 2026 Feb 24, 2026
Feb 10, 2026
Feb 24, 2026
7.8 HIGH
CVE-2025-15310 — Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.

Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.

Feb 10, 2026 Feb 24, 2026
Feb 10, 2026
Feb 24, 2026
4.3 MEDIUM
CVE-2025-15147 — WCFM Membership – WooCommerce Memberships for Multivendor Marketplace <= 2.11.8 - Insecur…

The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.11.8 via the '…

wcfm_membership | Remote | Authorization
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
7.7 HIGH
CVE-2026-25958 — Cube privilege escalation via a specially crafted request

Cube is a semantic layer for building data applications. From 0.27.19 to before 1.5.13, 1.4.2, and 1.0.14, it is possible to make a specially crafted request with a valid API token that leads to priv…

cube.js | Remote | Authorization
Feb 09, 2026 Feb 19, 2026
Feb 09, 2026
Feb 19, 2026
6.5 MEDIUM
CVE-2026-25957 — Cube Denial of Service (DoS) - An authenticated attacker can crash the server by sending …

Cube is a semantic layer for building data applications. From 1.1.17 to before 1.5.13 and 1.4.2, it is possible to make the entire Cube API unavailable by submitting a specially crafted request to a …

cube.js | Remote | Denial of Service
Feb 09, 2026 Feb 24, 2026
Feb 09, 2026
Feb 24, 2026
8.6 HIGH
CVE-2026-25951 — FUXA has a Path Traversal Sanitization Bypass

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.11, there is a flaw in the path sanitization logic allows an authenticated attacker with administrative privileg…

fuxa | Remote | Path Traversal
Feb 09, 2026 Feb 13, 2026
Feb 09, 2026
Feb 13, 2026
9.3 CRITICAL
CVE-2026-25939 — FUXA Unauthenticated Remote Arbitrary Scheduler Write

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10, an authorization bypass vulnerability in the FUXA allows an unauthenticated, remote attac…

fuxa | Remote | Authorization
Feb 09, 2026 Feb 13, 2026
Feb 09, 2026
Feb 13, 2026
9.8 CRITICAL
CVE-2026-25938 — FUXA Unauthenticated Remote Code Execution in Node-RED Integration

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to execu…

fuxa | Remote | Authentication
Feb 09, 2026 Feb 13, 2026
Feb 09, 2026
Feb 13, 2026
4.3 MEDIUM
CVE-2026-25934 — go-git improperly verifies data integrity values for .idx and .pack files

go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not …

go-git | Remote | Misconfiguration
Feb 09, 2026 Feb 20, 2026
Feb 09, 2026
Feb 20, 2026
7.8 HIGH
CVE-2026-25931 — vscode-spell-checker has a workspace-trust bypass Code Execution

vscode-spell-checker is a basic spell checker that works well with code and documents. Prior to v4.5.4, DocumentSettings._determineIsTrusted treats the configuration value cSpell.trustedWorkspace as …

| Misconfiguration
Feb 09, 2026 Feb 10, 2026
Feb 09, 2026
Feb 10, 2026
9.8 CRITICAL
CVE-2026-25895 — FUXA Unauthenticated Remote Code Execution via Arbitrary File Write in Upload API

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary files to arbitrary locat…

fuxa | Remote | Path Traversal
Feb 09, 2026 Feb 13, 2026
Feb 09, 2026
Feb 13, 2026
9.8 CRITICAL
CVE-2026-25894 — FUXA Unauthenticated Remote Code Execution via Hardcoded JWT Secret in Default Configurat…

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An insecure default configuration in FUXA allows an unauthenticated, remote attacker to gain administrative access and execut…

fuxa | Remote | Authentication
Feb 09, 2026 Feb 13, 2026
Feb 09, 2026
Feb 13, 2026
10.0 CRITICAL
CVE-2026-25893 — FUXA Unauthenticated Remote Code Execution via Admin JWT Minting

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to gain administra…

fuxa | Remote | Authentication
Feb 09, 2026 Feb 13, 2026
Feb 09, 2026
Feb 13, 2026
7.8 HIGH
CVE-2025-15319 — Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.

Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.

endpoint_patch | Authorization
Feb 09, 2026 Feb 10, 2026
Feb 09, 2026
Feb 10, 2026
5.5 MEDIUM
CVE-2025-15318 — Tanium addressed an arbitrary file deletion vulnerability in End-User Notifications Endpo…

Tanium addressed an arbitrary file deletion vulnerability in End-User Notifications Endpoint Tools.

endpoint_end-user-notifications | Misconfiguration
Feb 09, 2026 Feb 10, 2026
Feb 09, 2026
Feb 10, 2026
7.5 HIGH
CVE-2026-25961 — SumatraPDF Update MITM -> Arbitrary Code Execution

SumatraPDF is a multi-format reader for Windows. In 3.5.0 through 3.5.2, SumatraPDF's update mechanism disables TLS hostname verification (INTERNET_FLAG_IGNORE_CERT_CN_INVALID) and executes installer…

sumatrapdf | Remote | Misconfiguration
Feb 09, 2026 Feb 20, 2026
Feb 09, 2026
Feb 20, 2026
7.8 HIGH
CVE-2026-25925 — PowerDocu Affected by Remote Code Execution via Insecure Deserialization

PowerDocu contains a Windows GUI executable to perform technical documentations. Prior to 2.4.0, PowerDocu contains a critical security vulnerability in how it parses JSON files within Flow or App pa…

powerdocu | Injection
Feb 09, 2026 Feb 28, 2026
Feb 09, 2026
Feb 28, 2026
8.7 HIGH
CVE-2026-25923 — Phar Deserialization leading to Arbitrary File Deletion in my little forum

my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to 20260208.1, the application fails to filter the phar:// protocol in URL validat…

Remote | Injection
Feb 09, 2026 Feb 10, 2026
Feb 09, 2026
Feb 10, 2026
Showing 20 of 5088 Results