Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.9 MEDIUM
CVE-2025-15551 — LAN Code Execution on TP-Link Archer MR200, Archer C20, TL-WR850N and TL-WR845N

The response coming from TP-Link Archer MR200 v5.2, C20 v6, TL-WR850N v3, and TL-WR845N v4 for any request is getting executed by the JavaScript function like eval directly without any check. Attacke…

Feb 05, 2026 Feb 12, 2026
Feb 05, 2026
Feb 12, 2026
7.0 HIGH
CVE-2026-0715 — Moxa Arm-based Industrial Computers Bootloader Access Vulnerability

Moxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloader password provided on the device. An attacker with physical access to the device could use this …

Feb 05, 2026 Feb 18, 2026
Feb 05, 2026
Feb 18, 2026
7.0 HIGH
CVE-2026-0714 — Moxa Industrial Computers TPM SPI Bus Physical Attack Vulnerability

A physical attack vulnerability exists in certain Moxa industrial computers using TPM-backed LUKS full-disk encryption on Moxa Industrial Linux 3, where the discrete TPM is connected to the CPU via a…

Feb 05, 2026 Feb 18, 2026
Feb 05, 2026
Feb 18, 2026
6.1 MEDIUM
CVE-2025-70792 — Microweber Cross Site Scripting Vulnerability

Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipulate the "rel_id" parameter in a crafted URL and lure a user with admin privile…

microweber | Remote | Cross-Site Scripting
Feb 05, 2026 Feb 10, 2026
Feb 05, 2026
Feb 10, 2026
6.1 MEDIUM
CVE-2025-70791 — Microweber Cross Site Scripting (XSS) in Admin Order Abandoned Endpoint

Cross Site Scripting vulnerability in the "/admin/order/abandoned" endpoint of Microweber 2.0.19. An attacker can manipulate the "orderDirection" parameter in a crafted URL and lure a user with admin…

microweber | Remote | Cross-Site Scripting
Feb 05, 2026 Feb 10, 2026
Feb 05, 2026
Feb 10, 2026
8.8 HIGH
CVE-2025-69906 — Monstra CMS Remote Code Execution (RCE) via File Upload

Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies on blacklist-based file extension validation and stores uploaded files directly …

monstra_cms | Remote | Misconfiguration
Feb 05, 2026 Feb 11, 2026
Feb 05, 2026
Feb 11, 2026
7.5 HIGH
CVE-2025-69619 — My Text Editor Path Traversal Denial of Service

A path traversal in My Text Editor v1.6.2 allows attackers to cause a Denial of Service (DoS) via writing files to the internal storage.

my_teditor | Remote | Path Traversal
Feb 05, 2026 Feb 11, 2026
Feb 05, 2026
Feb 11, 2026
9.0 CRITICAL
CVE-2025-68723 — Axigen Mail Server WebAdmin Cross-Site Scripting (XSS) Vulnerability

Axigen Mail Server before 10.5.57 contains multiple stored Cross-Site Scripting (XSS) vulnerabilities in the WebAdmin interface. Three instances exist: (1) the log file name parameter in the Local Se…

axigen_mail_server | Remote | Cross-Site Scripting
Feb 05, 2026 Feb 13, 2026
Feb 05, 2026
Feb 13, 2026
6.1 MEDIUM
CVE-2025-68643 — Axigen Mail Server Cross-Site Scripting (XSS)

Axigen Mail Server before 10.5.57 allows stored Cross-Site Scripting (XSS) in the handling of the timeFormat account preference parameter. Attackers can exploit this by deploying a multi-stage attack…

axigen_mail_server | Remote | Cross-Site Scripting
Feb 05, 2026 Feb 11, 2026
Feb 05, 2026
Feb 11, 2026
6.1 MEDIUM
CVE-2020-37152 — PHP-Fusion 9.03.50 panels.php - Cross-Site Scripting (XSS)

PHP-Fusion 9.03.50 panels.php is vulnerable to cross-site scripting (XSS) via the 'panel_content' POST parameter. The application fails to properly sanitize user input before rendering it in the brow…

phpfusion php-fusion | Remote | Cross-Site Scripting
Feb 05, 2026 Feb 09, 2026
Feb 05, 2026
Feb 09, 2026
8.7 HIGH
CVE-2020-37150 — Edimax Technology EW-7438RPn-v3 Mini 1.27 - Unauthorized Access: Wi-Fi Password Disclosure

Edimax EW-7438RPn-v3 Mini 1.27 allows unauthenticated attackers to access the /wizard_reboot.asp page in unsetup mode, which discloses the Wi-Fi SSID and security key. Attackers can retrieve the wire…

ew-7438rpn_mini_firmware ew-7438rpn_mini | Remote | Information Disclosure
Feb 05, 2026 Feb 18, 2026
Feb 05, 2026
Feb 18, 2026
8.8 HIGH
CVE-2020-37149 — Edimax Technology EW-7438RPn-v3 Mini 1.27 - Cross-Site Request Forgery (CSRF) to Command …

Edimax EW-7438RPn-v3 Mini 1.27 is vulnerable to cross-site request forgery (CSRF) that can lead to command execution. An attacker can trick an authenticated user into submitting a crafted form to the…

ew-7438rpn_mini_firmware ew-7438rpn_mini | Remote | Cross-Site Request Forgery
Feb 05, 2026 Feb 18, 2026
Feb 05, 2026
Feb 18, 2026
5.1 MEDIUM
CVE-2020-37148 — P5 FNIP-8x16A/FNIP-4xSH 1.0.20, 1.0.11 - Stored Cross-Site Scripting (XSS)

P5 FNIP-8x16A/FNIP-4xSH versions 1.0.20 and 1.0.11 suffer from a stored cross-site scripting vulnerability. Input passed to several GET/POST parameters is not properly sanitized before being returned…

Remote | Cross-Site Scripting
Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
5.1 MEDIUM
CVE-2020-37145 — HRSALE 1.1.8 - Cross-Site Request Forgery (Add Admin)

HRSALE 1.1.8 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized administrative users through the employee registration form. Attackers can craft a malicious…

hrsale | Remote | Cross-Site Request Forgery
Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
5.3 MEDIUM
CVE-2020-37144 — Exagate Sysguard 6001 - Cross-Site Request Forgery (Add Admin)

Exagate SYSGuard 6001 contains a cross-site request forgery vulnerability that allows attackers to create unauthorized admin accounts through a crafted HTML form. Attackers can trick users into submi…

sysguard_3001_firmware | Remote | Cross-Site Request Forgery
Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
7.5 HIGH
CVE-2020-37143 — ProficySCADA for iOS 5.0.25920 - 'Password' Denial of Service

ProficySCADA for iOS 5.0.25920 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the password input field. Attackers can overwrite the password…

Remote | Denial of Service
Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
8.4 HIGH
CVE-2020-37142 — 10-Strike Network Inventory Explorer 8.54 - 'Add' Local Buffer Overflow (SEH)

10-Strike Network Inventory Explorer 8.54 contains a structured exception handler buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting SEH records. Attackers c…

network_inventory_explorer | Memory Corruption
Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
5.5 MEDIUM
CVE-2020-37140 — Everest 5.50.2100 - 'Open File' Denial of Service

Everest, later referred to as AIDA64, 5.50.2100 contains a denial of service vulnerability that allows local attackers to crash the application by manipulating file open functionality. Attackers can …

everest | Denial of Service
Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
8.4 HIGH
CVE-2020-37139 — Odin Secure FTP Expert 7.6.3 - 'Site Info' Denial of Service

Odin Secure FTP Expert 7.6.3 contains a local denial of service vulnerability that allows attackers to crash the application by manipulating site information fields. Attackers can generate a buffer o…

| Denial of Service
Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
9.8 CRITICAL
CVE-2020-37138 — 10-Strike Network Inventory Explorer 9.03 - 'Read from File' Buffer Overflow (SEH)(ROP)

10-Strike Network Inventory Explorer 9.03 contains a buffer overflow vulnerability in the file import functionality that allows remote attackers to execute arbitrary code. Attackers can craft a malic…

network_inventory_explorer | Remote | Memory Corruption
Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
Showing 20 of 5105 Results