Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.6 MEDIUM
CVE-2025-11563 — wcurl path traversal with percent-encoded slashes

URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects th…

curl wcurl | Remote | Path Traversal
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
9.0 HIGH
CVE-2026-3168 — Tenda F453 httpd NatStaticSetting fromNatStaticSetting buffer overflow

A weakness has been identified in Tenda F453 1.0.0.3. This affects the function fromNatStaticSetting of the file /goform/NatStaticSetting of the component httpd. Executing a manipulation of the argum…

f453_firmware f453 | Remote | Memory Corruption
Feb 25, 2026 Feb 25, 2026
Feb 25, 2026
Feb 25, 2026
9.0 HIGH
CVE-2026-3167 — Tenda F453 httpd webtypelibrary formWebTypeLibrary buffer overflow

A security flaw has been discovered in Tenda F453 1.0.0.3. The impacted element is the function formWebTypeLibrary of the file /goform/webtypelibrary of the component httpd. Performing a manipulation…

f453_firmware f453 | Remote | Memory Corruption
Feb 25, 2026 Feb 25, 2026
Feb 25, 2026
Feb 25, 2026
9.0 HIGH
CVE-2026-3166 — Tenda F453 httpd RouteStatic fromRouteStatic buffer overflow

A vulnerability was identified in Tenda F453 1.0.0.3. The affected element is the function fromRouteStatic of the file /goform/RouteStatic of the component httpd. Such manipulation of the argument pa…

f453_firmware f453 | Remote | Memory Corruption
Feb 25, 2026 Feb 25, 2026
Feb 25, 2026
Feb 25, 2026
6.4 MEDIUM
CVE-2026-1614 — Rise Blocks – A Complete Gutenberg Page Builder <= 3.7 - Authenticated (Contributor+) Sto…

The Rise Blocks – A Complete Gutenberg Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘logoTag’ Site Identity block attribute in all versions up to, and includ…

rise_blocks | Remote | Cross-Site Scripting
Feb 25, 2026 Feb 25, 2026
Feb 25, 2026
Feb 25, 2026
9.2 CRITICAL
CVE-2026-3179 — A path traversal vulnerability was found in the FTP Backup on the ADM.

The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MITM attacker can craft filenames containing path tr…

data_master | Remote | Path Traversal
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
9.0 HIGH
CVE-2026-3165 — Tenda F453 httpd AdvSetWrlsafeset fromSetWifiGusetBasic buffer overflow

A vulnerability was determined in Tenda F453 1.0.0.3. Impacted is the function fromSetWifiGusetBasic of the file /goform/AdvSetWrlsafeset of the component httpd. This manipulation of the argument mit…

f453_firmware f453 | Remote | Memory Corruption
Feb 25, 2026 Feb 25, 2026
Feb 25, 2026
Feb 25, 2026
9.8 CRITICAL
CVE-2026-3164 — itsourcecode News Portal Project contactus.php sql injection

A vulnerability was found in itsourcecode News Portal Project 1.0. This issue affects some unknown processing of the file /admin/contactus.php. The manipulation of the argument pagetitle results in s…

news_portal_project | Remote | Injection
Feb 25, 2026 Feb 25, 2026
Feb 25, 2026
Feb 25, 2026
7.5 HIGH
CVE-2026-3163 — SourceCodester Website Link Extractor URL file_get_contents server-side request forgery

A vulnerability has been found in SourceCodester Website Link Extractor 1.0. This vulnerability affects the function file_get_contents of the component URL Handler. The manipulation leads to server-s…

website_link_extractor | Remote | Server-Side Request Forgery
Feb 25, 2026 Feb 25, 2026
Feb 25, 2026
Feb 25, 2026
9.8 CRITICAL
CVE-2026-3153 — itsourcecode Document Management System register.php sql injection

A vulnerability has been found in itsourcecode Document Management System 1.0. Impacted is an unknown function of the file /register.php. Such manipulation of the argument Username leads to sql injec…

document_management_system | Remote | Injection
Feb 25, 2026 Feb 25, 2026
Feb 25, 2026
Feb 25, 2026
9.8 CRITICAL
CVE-2026-3152 — itsourcecode College Management System teacher-salary.php sql injection

A flaw has been found in itsourcecode College Management System 1.0. This issue affects some unknown processing of the file /admin/teacher-salary.php. This manipulation of the argument teacher_id cau…

college_management_system | Remote | Injection
Feb 25, 2026 Feb 25, 2026
Feb 25, 2026
Feb 25, 2026
9.8 CRITICAL
CVE-2026-3151 — itsourcecode College Management System login.php sql injection

A vulnerability was detected in itsourcecode College Management System 1.0. This vulnerability affects unknown code of the file /login/login.php. The manipulation of the argument email results in sql…

college_management_system | Remote | Injection
Feb 25, 2026 Feb 25, 2026
Feb 25, 2026
Feb 25, 2026
8.3 HIGH
CVE-2026-3100 — An improper certificate validation vulnerability was found in the FTP Backup on the ADM.

The FTP Backup on the ADM will not properly strictly enforce TLS certificate verification while connecting to an FTP server using FTPES/FTPS. An improper validated TLS/SSL certificates allows a remot…

data_master | Remote | Cryptography
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-25785 — Lanscope Endpoint Manager (On-Premises) Path Traversal Remote Code Execution

Path traversal vulnerability exists in Lanscope Endpoint Manager (On-Premises) Sub-Manager Server Ver.9.4.7.3 and earlier, which may allow an attacker to tamper with arbitrary files and execute arbit…

lanscope_endpoint_manager | Path Traversal
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
8.8 HIGH
CVE-2026-3150 — itsourcecode College Management System display-teacher.php sql injection

A security vulnerability has been detected in itsourcecode College Management System 1.0. This affects an unknown part of the file /admin/display-teacher.php. The manipulation of the argument teacher…

college_management_system | Remote | Injection
Feb 25, 2026 Feb 25, 2026
Feb 25, 2026
Feb 25, 2026
8.8 HIGH
CVE-2026-3149 — itsourcecode College Management System asign-single-student-subjects.php sql injection

A weakness has been identified in itsourcecode College Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/asign-single-student-subjects.php. Executing a ma…

college_management_system | Remote | Injection
Feb 25, 2026 Feb 25, 2026
Feb 25, 2026
Feb 25, 2026
9.8 CRITICAL
CVE-2026-3148 — SourceCodester Simple and Nice Shopping Cart Script signup.php sql injection

A vulnerability was determined in SourceCodester Simple and Nice Shopping Cart Script 1.0. This impacts an unknown function of the file /signup.php. This manipulation of the argument Username causes …

Feb 25, 2026 Feb 25, 2026
Feb 25, 2026
Feb 25, 2026
8.6 HIGH
CVE-2026-27696 — changedetection.io Vulnerable to Server-Side Request Forgery (SSRF) via Watch URLs

changedetection.io is a free open source web page change detection tool. In versions prior to 0.54.1, changedetection.io is vulnerable to Server-Side Request Forgery (SSRF) because the URL validation…

changedetection | Remote | Server-Side Request Forgery
Feb 25, 2026 Feb 26, 2026
Feb 25, 2026
Feb 26, 2026
6.1 MEDIUM
CVE-2026-27645 — changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response

changedetection.io is a free open source web page change detection tool. In versions prior to 0.54.1, the RSS single-watch endpoint reflects the UUID path parameter directly in the HTTP response body…

changedetection | Remote | Cross-Site Scripting
Feb 25, 2026 Feb 25, 2026
Feb 25, 2026
Feb 25, 2026
7.2 HIGH
CVE-2026-27624 — Coturn: IPv4-mapped IPv6 (::ffff:0:0/96) bypasses denied-peer-ip ACL

Coturn is a free open source implementation of TURN and STUN Server. Coturn is commonly configured to block loopback and internal ranges using "denied-peer-ip" and/or default loopback restrictions. C…

coturn | Remote | Misconfiguration
Feb 25, 2026 Feb 27, 2026
Feb 25, 2026
Feb 27, 2026
Showing 20 of 5386 Results