Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-24416 — OpenSTAManager has a Time-Based Blind SQL Injection in Article Pricing Module

OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contain a critical Time-Based Blind SQL Injection vulnerability in the a…

openstamanager | Remote | Injection
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
5.4 MEDIUM
CVE-2026-24050 — Zulip affected by Stored XSS in user profile modal

Zulip is an open-source team collaboration tool. From 5.0 to before 11.5, some administrative actions on the user profile were susceptible to stored XSS in group names or channel names. Exploiting th…

zulip zulip_server | Remote | Cross-Site Scripting
Feb 06, 2026 Feb 23, 2026
Feb 06, 2026
Feb 23, 2026
8.2 HIGH
CVE-2026-23989 — REVA Public Link Exploit

REVA is an interoperability platform. Prior to 2.42.3 and 2.40.3, a bug in the GRPC authorization middleware of the "Reva" component of OpenCloud allows a malicious user to bypass the scope verificat…

opencloud_reva | Remote | Authorization
Feb 06, 2026 Feb 24, 2026
Feb 06, 2026
Feb 24, 2026
8.7 HIGH
CVE-2025-69216 — OpenSTAManager has an SQL Injection in Scadenzario Print Template

OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an authenticated SQL injection vulnerability in OpenSTAManager's Scadenzario (Paymen…

openstamanager | Remote | Injection
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
8.8 HIGH
CVE-2025-69214 — OpenSTAManager has a SQL Injection in ajax_select.php (componenti endpoint)

OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an SQL Injection vulnerability exists in the ajax_select.php endpoint when handling …

openstamanager | Remote | Injection
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
9.4 CRITICAL
CVE-2025-69212 — OpenSTAManager has an OS Command Injection in P7M File Processing

OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a critical OS Command Injection vulnerability exists in the P7M (signed XML) file de…

openstamanager | Remote | Injection
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
7.2 HIGH
CVE-2026-2061 — D-Link DIR-823X set_ipv6 sub_424D20 os command injection

A vulnerability was determined in D-Link DIR-823X 250416. Affected by this issue is the function sub_424D20 of the file /goform/set_ipv6. Executing a manipulation can lead to os command injection. It…

dir-823x_firmware dir-832x | Remote | Injection
Feb 06, 2026 Feb 11, 2026
Feb 06, 2026
Feb 11, 2026
9.8 CRITICAL
CVE-2026-2060 — code-projects Simple Blood Donor Management System editcampaignform.php sql injection

A vulnerability was found in code-projects Simple Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /simpleblooddonor/editcampaignform.php. Per…

Feb 06, 2026 Feb 11, 2026
Feb 06, 2026
Feb 11, 2026
10.0 CRITICAL
CVE-2026-25725 — Claude Code Has Sandbox Escape via Persistent Configuration Injection in settings.json

Claude Code is an agentic coding tool. Prior to version 2.1.2, Claude Code's bubblewrap sandboxing mechanism failed to properly protect the .claude/settings.json configuration file when it did not ex…

claude_code | Remote | Misconfiguration
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
7.5 HIGH
CVE-2026-25724 — Claude Code Has Permission Deny Bypass Through Symbolic Links

Claude Code is an agentic coding tool. Prior to version 2.1.7, Claude Code failed to strictly enforce deny rules configured in settings.json when accessing files through symbolic links. If a user exp…

claude_code | Remote | Misconfiguration
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
7.7 HIGH
CVE-2026-25723 — Claude Code Vulnerable to Command Injection via Piped sed Command Bypasses File Write Res…

Claude Code is an agentic coding tool. Prior to version 2.0.55, Claude Code failed to properly validate commands using piped sed operations with the echo command, allowing attackers to bypass file wr…

claude_code | Remote | Injection
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
9.1 CRITICAL
CVE-2026-25722 — Claude Code Vulnerable to Command Injection via Directory Change Bypasses Write Protection

Claude Code is an agentic coding tool. Prior to version 2.0.57, Claude Code failed to properly validate directory changes when combined with write operations to protected folders. By using the cd com…

claude_code | Remote | Path Traversal
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
5.4 MEDIUM
CVE-2026-24903 — OrcaStatLLM Researcher Stored Cross-Site Scripting (XSS) via Log Message Injection in Ses…

OrcaStatLLM Researcher is an LLM Based Research Paper Generator. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Log Message in the Session Page in OrcaStatLLM-Researcher tha…

orcastatllm_researcher | Remote | Cross-Site Scripting
Feb 06, 2026 Feb 24, 2026
Feb 06, 2026
Feb 24, 2026
8.8 HIGH
CVE-2026-24851 — OpenFGA Improper Policy Enforcement

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.5 to v1.11.2 ( openfga-0.2.22<= Helm chart <= openfga-0.2…

openfga helm_charts | Remote | Authorization
Feb 06, 2026 Feb 24, 2026
Feb 06, 2026
Feb 24, 2026
4.3 MEDIUM
CVE-2026-24776 — OpenProject has an IDOR on MeetingAgendaItems allows cross-project meeting agenda item tr…

OpenProject is an open-source, web-based project management software. Prior to 17.0.2, the drag&drop handler moving an agenda item to a different section was not properly checking if the target meeti…

openproject | Remote | Authorization
Feb 06, 2026 Feb 23, 2026
Feb 06, 2026
Feb 23, 2026
8.7 HIGH
CVE-2026-24419 — OpenSTAManager has an SQL Injection in the Prima Nota module

OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contain a critical Error-Based SQL Injection vulnerability in the Prima …

openstamanager | Remote | Injection
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
8.1 HIGH
CVE-2026-24135 — Gogs vulnerable to arbitrary file deletion via path traversal in wiki page update

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, a path traversal vulnerability exists in the updateWikiPage function of Gogs. The vulnerability allows an authenticated us…

gogs | Remote | Path Traversal
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
6.5 MEDIUM
CVE-2026-23633 — Gogs has arbitrary file read/write via path traversal in Git hook editing

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, there is an arbitrary file read/write via path traversal in Git hook editing. This issue has been patched in versions 0.13…

gogs | Remote | Path Traversal
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
6.5 MEDIUM
CVE-2026-23632 — Gogs user can update repository content with read-only permission

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, the endpoint "PUT /repos/:owner/:repo/contents/*" does not require write permissions and allows access with read permissio…

gogs | Remote | Authorization
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
6.5 MEDIUM
CVE-2026-22592 — Gogs is Vulnerable to Denial of Service

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, an authenticated user can cause a DOS attack. If one of the repo files is deleted before synchronization, it will cause th…

gogs | Remote | Denial of Service
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
Showing 20 of 5132 Results