Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-26207 — DIscourse's discourse-policy plugin lacks post access check

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, `discourse-policy` plugin allows any authenticated user to interact with policies on posts they d…

discourse | Remote | Authorization
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
7.5 HIGH
CVE-2026-26078 — Discourse has authentication bypass vulnerability in the Patreon plugin webhook endpoint

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, when the `patreon_webhook_secret` site setting is blank, an attacker can forge valid webhook sign…

discourse | Remote | Authentication
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
8.2 HIGH
CVE-2025-71057 — D-Link Wireless N 300 ADSL2+ Modem Router Session Hijacking Vulnerability

Improper session management in D-Link Wireless N 300 ADSL2+ Modem Router DSL-124 ME_1.00 allows attackers to execute a session hijacking attack via spoofing the IP address of an authenticated user.

Remote | Authentication
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
5.4 MEDIUM
CVE-2025-56605 — PuneethReddyHC Event Management System Reflected Cross-Site Scripting

A reflected Cross-Site Scripting (XSS) vulnerability exists in the register.php backend script of PuneethReddyHC Event Management System 1.0. The mobile POST parameter is improperly validated and ech…

Remote | Cross-Site Scripting
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
8.4 HIGH
CVE-2026-3071 — Flair LanguageModel Deserialization Remote Code Execution Vulnerability

Deserialization of untrusted data in the LanguageModel class of Flair from versions 0.4.1 to latest are vulnerable to arbitrary code execution when loading a malicious model.

| Injection
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
8.4 HIGH
CVE-2026-2244 — Sensitive Data Exposure in Google Cloud Vertex AI Workbench

A vulnerability in Google Cloud Vertex AI Workbench from 7/21/2025 to 01/30/2026 allows an attacker to exfiltrate valid Google Cloud access tokens of other users via abuse of a built-in startup scrip…

Remote | Information Disclosure
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
6.5 MEDIUM
CVE-2026-26077 — Discourse doesn't ensure webhooks require a token

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, several webhook endpoints (SendGrid, Mailjet, Mandrill, Postmark, SparkPost) in the `WebhooksCont…

discourse | Remote | Authentication
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
6.1 MEDIUM
CVE-2026-2680 — Multiple vulnerabilities in A3factura software

Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'customerVATNumber', in 'a3factura-app.wolterskluwer.es/#/incomes/salesDeliveryNotes' endpoint, which could allow an a…

a3factura a3factura | Remote | Cross-Site Scripting
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
6.1 MEDIUM
CVE-2026-2679 — Multiple vulnerabilities in A3factura software

Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'customerName', in 'a3factura-app.wolterskluwer.es/#/incomes/salesInvoices' endpoint, which could allow an attacker to…

a3factura a3factura | Remote | Cross-Site Scripting
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
6.1 MEDIUM
CVE-2026-2678 — Multiple vulnerabilities in A3factura software

Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'name', parameter 'name', in 'a3factura-app.wolterskluwer.es/#/incomes/customers' endpoint, which could allow an attac…

a3factura a3factura | Remote | Cross-Site Scripting
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
6.1 MEDIUM
CVE-2026-2677 — Multiple vulnerabilities in A3factura software

Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'name', in 'a3factura-app.wolterskluwer.es/#/incomes/representatives-management' endpoint, which could allow an attack…

a3factura a3factura | Remote | Cross-Site Scripting
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
7.6 HIGH
CVE-2025-14343 — Reflected XSS in Dokuzsoft Technology's E-Commerce Product

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dokuzsoft Technology Ltd. E-Commerce Product allows Reflected XSS.This issue affects E-Com…

Remote | Cross-Site Scripting
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
8.6 HIGH
CVE-2026-1198 — SQL Injection in SIMPLE.ERP

SIMPLE.ERP is vulnerable to the SQL Injection in search functionality in "Obroty na kontach" window. Lack of input validation allows an authenticated attacker to prepare a malicious query to the data…

Remote | Injection
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
7.3 HIGH
CVE-2025-64999 — Cross-site scripting in HTML logs of Synthetic Monitoring test services

Improper neutralization of input in Checkmk versions 2.4.0 before 2.4.0p22, and 2.3.0 before 2.3.0p43 allows an attacker that can manipulate a host's check output to inject malicious JavaScript into …

checkmk | Remote | Cross-Site Scripting
Feb 26, 2026 Mar 05, 2026
Feb 26, 2026
Mar 05, 2026
7.2 HIGH
CVE-2026-28138 — WordPress uListing plugin <= 2.2.0 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in Stylemix uListing ulisting allows Object Injection.This issue affects uListing: from n/a through <= 2.2.0.

ulisting | Remote | Injection
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
7.6 HIGH
CVE-2026-28136 — WordPress WP SMS plugin <= 6.9.12 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs WP SMS wp-sms allows SQL Injection.This issue affects WP SMS: from n/a through <= 6.9.…

wp_sms | Remote | Injection
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
5.3 MEDIUM
CVE-2026-28132 — WordPress WooCommerce Photo Reviews plugin <= 1.4.4 - Content Injection vulnerability

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in villatheme WooCommerce Photo Reviews woocommerce-photo-reviews allows Code Injection.This issue affects …

woocommerce_photo_reviews | Remote | Cross-Site Scripting
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
6.5 MEDIUM
CVE-2026-28131 — WordPress Elementor Addon Elements plugin <= 1.14.4 - Sensitive Data Exposure vulnerabili…

Insertion of Sensitive Information Into Sent Data vulnerability in WPVibes Elementor Addon Elements addon-elements-for-elementor-page-builder allows Retrieve Embedded Sensitive Data.This issue affect…

elementor_addon_elements | Remote | Information Disclosure
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
6.5 MEDIUM
CVE-2026-28083 — WordPress Flatsome theme <= 3.20.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UX-themes Flatsome flatsome allows Stored XSS.This issue affects Flatsome: from n/a through <= 3.…

flatsome | Remote | Cross-Site Scripting
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
5.3 MEDIUM
CVE-2026-1698 — HTTP Host header vulnerability in WebClient and WebScheduler web apps

A HTTP Host header attack vulnerability affects WebClient and the WebScheduler web apps of PcVue in version 15.0.0 through 16.3.3 included, allowing a remote attacker to inject harmful payloads that …

pcvue | Remote | Injection
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
Showing 20 of 5388 Results