Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-24851 — OpenFGA Improper Policy Enforcement

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.5 to v1.11.2 ( openfga-0.2.22<= Helm chart <= openfga-0.2…

openfga helm_charts | Remote | Authorization
Feb 06, 2026 Feb 24, 2026
Feb 06, 2026
Feb 24, 2026
4.3 MEDIUM
CVE-2026-24776 — OpenProject has an IDOR on MeetingAgendaItems allows cross-project meeting agenda item tr…

OpenProject is an open-source, web-based project management software. Prior to 17.0.2, the drag&drop handler moving an agenda item to a different section was not properly checking if the target meeti…

openproject | Remote | Authorization
Feb 06, 2026 Feb 23, 2026
Feb 06, 2026
Feb 23, 2026
8.7 HIGH
CVE-2026-24419 — OpenSTAManager has an SQL Injection in the Prima Nota module

OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contain a critical Error-Based SQL Injection vulnerability in the Prima …

openstamanager | Remote | Injection
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
8.1 HIGH
CVE-2026-24135 — Gogs vulnerable to arbitrary file deletion via path traversal in wiki page update

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, a path traversal vulnerability exists in the updateWikiPage function of Gogs. The vulnerability allows an authenticated us…

gogs | Remote | Path Traversal
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
6.5 MEDIUM
CVE-2026-23633 — Gogs has arbitrary file read/write via path traversal in Git hook editing

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, there is an arbitrary file read/write via path traversal in Git hook editing. This issue has been patched in versions 0.13…

gogs | Remote | Path Traversal
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
6.5 MEDIUM
CVE-2026-23632 — Gogs user can update repository content with read-only permission

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, the endpoint "PUT /repos/:owner/:repo/contents/*" does not require write permissions and allows access with read permissio…

gogs | Remote | Authorization
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
6.5 MEDIUM
CVE-2026-22592 — Gogs is Vulnerable to Denial of Service

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, an authenticated user can cause a DOS attack. If one of the repo files is deleted before synchronization, it will cause th…

gogs | Remote | Denial of Service
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
5.4 MEDIUM
CVE-2026-1769 — Stored XSS on Xerox CentreWare Web 7.0.6

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Xerox CentreWare on Windows allows Stored XSS.This issue affects CentreWare: through 7.0.6…

windows centreware_web | Remote | Cross-Site Scripting
Feb 06, 2026 Feb 24, 2026
Feb 06, 2026
Feb 24, 2026
7.6 HIGH
CVE-2025-70963 — Gophish Insecure API Key Exposure

Gophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived API key directly inside the rendered HTML/JavaScript of the page on every login…

gophish | Remote | Authorization
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
8.8 HIGH
CVE-2025-64175 — Gogs Vulnerable to 2FA Bypass via Recovery Code

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, Gogs’ 2FA recovery code validation does not scope codes by user, enabling cross-account bypass. If an attacker knows a vic…

gogs | Remote | Authentication
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
7.8 HIGH
CVE-2026-2103 — Use of Hard-Coded Cryptographic Key for Password Storage

Infor SyteLine ERP uses hard-coded static cryptographic keys to encrypt stored credentials, including user passwords, database connection strings, and API keys. The encryption keys are identical acro…

syteline_erp | Cryptography
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
9.8 CRITICAL
CVE-2026-2059 — SourceCodester Medical Center Portal Management System emp_edit1.php sql injection

A vulnerability has been found in SourceCodester Medical Center Portal Management System 1.0. Affected is an unknown function of the file /emp_edit1.php. Such manipulation of the argument ID leads to…

Feb 06, 2026 Feb 12, 2026
Feb 06, 2026
Feb 12, 2026
9.8 CRITICAL
CVE-2026-2058 — mathurvishal CloudClassroom-PHP-Project Post Query Details postquerypublic.php sql inject…

A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file /postquerypublic.php of the component Pos…

cloudclassroom-php-project | Remote | Injection
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
7.5 HIGH
CVE-2026-25556 — MuPDF <= 1.27.0 Barcode Decoding Double Free

MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_display_list() when an exception occurs during display list rendering. The function accepts a caller-ow…

mupdf | Remote | Memory Corruption
Feb 06, 2026 Feb 24, 2026
Feb 06, 2026
Feb 24, 2026
8.8 HIGH
CVE-2026-23741 — ast_coredumper running as root sources ast_debug_tools.conf from /etc/asterisk; potential…

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the asterisk/contrib/scripts/ast_coredumper runs as root,…

asterisk asterisk certified_asterisk | Remote | Authentication
Feb 06, 2026 Feb 18, 2026
Feb 06, 2026
Feb 18, 2026
7.8 HIGH
CVE-2026-23740 — Asterisk vulnerable to potential privilege escalation

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, when ast_coredumper writes its gdb init and output files …

asterisk asterisk certified_asterisk | Misconfiguration
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
6.5 MEDIUM
CVE-2026-23739 — Asterisk xml.c uses unsafe XML_PARSE_NOENT leading to potential XXE Injection

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the ast_xml_open() function in xml.c parses XML documents…

asterisk asterisk certified_asterisk | Remote | XML External Entity
Feb 06, 2026 Feb 18, 2026
Feb 06, 2026
Feb 18, 2026
6.1 MEDIUM
CVE-2026-23738 — The Asterisk embedded web server 's /httpstatus page echos user supplied values(cookie an…

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, user supplied/control values for Cookies and any GET vari…

asterisk asterisk certified_asterisk | Remote | Cross-Site Scripting
Feb 06, 2026 Feb 18, 2026
Feb 06, 2026
Feb 18, 2026
9.8 CRITICAL
CVE-2025-64111 — Gogs's update .git/config file allows remote command execution

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, due to the insufficient patch for CVE-2024-56731, it's still possible to update files in the .git directory and achieve re…

gogs | Remote | Injection
Feb 06, 2026 Feb 18, 2026
Feb 06, 2026
Feb 18, 2026
8.5 HIGH
CVE-2019-25305 — JumpStart 0.6.0.0 - 'jswpbapi' Unquoted Service Path

JumpStart 0.6.0.0 contains an unquoted service path vulnerability in the jswpbapi service running with LocalSystem privileges. Attackers can exploit the unquoted path containing spaces to inject and …

jumpstart | Misconfiguration
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
Showing 20 of 5090 Results