Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.5 HIGH
CVE-2019-25307 — WorkgroupMail 7.5.1 - 'WorkgroupMail' Unquoted Service Path

WorkgroupMail 7.5.1 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the u…

| Misconfiguration
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
8.5 HIGH
CVE-2019-25306 — BlackMoon FTP Server 3.1.2.1731 - 'BMFTP-RELEASE' Unquoted Serive Path

BlackMoon FTP Server 3.1.2.1731 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted…

| Misconfiguration
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
6.4 MEDIUM
CVE-2018-25157 — Phraseanet 4.0.3 Stored XSS via Document Upload

Phraseanet 4.0.3 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through crafted file names during document uploads. Attackers can upl…

Remote | Cross-Site Scripting
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
8.7 HIGH
CVE-2026-2337 — Refleccted XSS on Plunet BusinessManager

A vulnerability in Plunet Plunet BusinessManager allows session hijacking, data theft, unauthorized actions on behalf of the user.This issue affects Plunet BusinessManager: 10.15.1.

Remote | Authentication
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
7.0 HIGH
CVE-2026-1227 — EBO XML External Entity Reference Vulnerability

CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized disclosure of local files, interaction within the EBO system, or denial of service co…

| XML External Entity
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
7.0 HIGH
CVE-2026-1226 — CorelDRAW Code Injection Vulnerability

CWE‑94: Improper Control of Generation of Code vulnerability exists that could cause execution of untrusted or unintended code within the application when maliciously crafted design content is proces…

| Injection
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
8.8 HIGH
CVE-2026-0910 — wpForo Forum <= 2.4.13 - Authenticated (Subscriber+) PHP Object Injection

The wpForo Forum plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.13 via deserialization of untrusted input in the 'wpforo_display_array_data' func…

wpforo_forum | Remote | Injection
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
9.4 CRITICAL
CVE-2025-8668 — Reflected XSS in E-Kalite Software Hardware Engineering's Turboard

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd…

Remote | Cross-Site Scripting
Feb 11, 2026 Mar 04, 2026
Feb 11, 2026
Mar 04, 2026
6.5 MEDIUM
CVE-2026-22894 — File Station 5

A path traversal vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files …

file_station | Remote | Path Traversal
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
9.8 CRITICAL
CVE-2025-8025 — Improper Access Control in Dinosoft Business Solutions' Dinosoft ERP

Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Business Solutions Dinosoft ERP allows Accessing Functionality Not Properly Constrained by ACLs.This is…

Remote | Authentication
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
6.5 MEDIUM
CVE-2025-68406 — Qsync Central

A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files o…

qsync_central | Remote | Path Traversal
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
6.5 MEDIUM
CVE-2025-66278 — File Station 5

A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files …

file_station | Remote | Path Traversal
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
9.8 CRITICAL
CVE-2025-66277 — QTS, QuTS hero

A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to traverse the file system to unintended lo…

quts_hero qts | Remote | Path Traversal
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
4.9 MEDIUM
CVE-2025-66274 — QuTS hero

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerabili…

quts_hero | Remote | Denial of Service
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
4.4 MEDIUM
CVE-2025-62856 — File Station 5

A path traversal vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpect…

file_station | Path Traversal
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
4.4 MEDIUM
CVE-2025-62855 — File Station 5

A path traversal vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpect…

file_station | Path Traversal
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
6.5 MEDIUM
CVE-2025-62854 — File Station 5

An uncontrolled resource consumption vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of…

file_station | Remote | Denial of Service
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
6.5 MEDIUM
CVE-2025-62853 — File Station 5

A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files …

file_station | Remote | Path Traversal
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
4.9 MEDIUM
CVE-2025-59386 — QuTS hero

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerabili…

quts_hero | Remote | Memory Corruption
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
4.9 MEDIUM
CVE-2025-58472 — Qsync Central

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-…

qsync_central | Remote | Memory Corruption
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
Showing 20 of 5071 Results