Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.5 MEDIUM
CVE-2025-15564 — Mapnik value.cpp operator divide by zero

A vulnerability has been found in Mapnik up to 4.2.0. This vulnerability affects the function mapnik::detail::mod<...>::operator of the file src/value.cpp. The manipulation leads to divide by zero. T…

mapnik | Denial of Service
Feb 07, 2026 Feb 28, 2026
Feb 07, 2026
Feb 28, 2026
9.8 CRITICAL
CVE-2026-2113 — yuan1994 tpadmin WebUploader preview.php deserialization

A security vulnerability has been detected in yuan1994 tpadmin up to 1.3.12. This affects an unknown part in the library /public/static/admin/lib/webuploader/0.1.5/server/preview.php of the component…

tpadmin | Remote | Injection
Feb 07, 2026 Mar 05, 2026
Feb 07, 2026
Mar 05, 2026
5.3 MEDIUM
CVE-2026-2111 — JeecgBoot Retrieval-Augmented Generation edit path traversal

A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this issue is some unknown functionality of the file /airag/knowledge/doc/edit of the component Retrieval-Augmented Generation Mod…

jeecg_boot | Remote | Path Traversal
Feb 07, 2026 Mar 03, 2026
Feb 07, 2026
Mar 03, 2026
8.1 HIGH
CVE-2026-2110 — Tasin1025 SwiftBuy login.php excessive authentication

A security flaw has been discovered in Tasin1025 SwiftBuy up to 0f5011372e8d1d7edfd642d57d721c9fadc54ec7. Affected by this vulnerability is an unknown functionality of the file /login.php. Performing…

swiftbuy | Remote | Authentication
Feb 07, 2026 Mar 05, 2026
Feb 07, 2026
Mar 05, 2026
8.1 HIGH
CVE-2026-2109 — jsbroks COCO Annotator Delete Category undo improper authorization

A vulnerability was identified in jsbroks COCO Annotator up to 0.11.1. Affected is an unknown function of the file /api/undo/ of the component Delete Category Handler. Such manipulation of the argume…

coco_annotator | Remote | Authorization
Feb 07, 2026 Feb 27, 2026
Feb 07, 2026
Feb 27, 2026
7.5 HIGH
CVE-2026-2108 — jsbroks COCO Annotator Endpoint long_task denial of service

A vulnerability was determined in jsbroks COCO Annotator up to 0.11.1. This impacts an unknown function of the file /api/info/long_task of the component Endpoint. This manipulation causes denial of s…

coco_annotator | Remote | Denial of Service
Feb 07, 2026 Feb 27, 2026
Feb 07, 2026
Feb 27, 2026
8.8 HIGH
CVE-2026-2107 — yeqifu warehouse Log Info LoginfoController.java batchDeleteLoginfo improper authorization

A vulnerability was found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function loadAllLoginfo/deleteLoginfo/batchDeleteLoginfo of the file dataset\repos\wareh…

warehouse | Remote | Authorization
Feb 07, 2026 Feb 10, 2026
Feb 07, 2026
Feb 10, 2026
8.8 HIGH
CVE-2026-2106 — yeqifu warehouse Notice Management NoticeController.java batchDeleteNotice improper autho…

A vulnerability has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. The impacted element is the function addNotice/updateNotice/deleteNotice/batchDeleteNotice of the fi…

warehouse | Remote | Authorization
Feb 07, 2026 Feb 10, 2026
Feb 07, 2026
Feb 10, 2026
8.8 HIGH
CVE-2026-2105 — yeqifu warehouse Department Management DeptController.java deleteDept improper authorizat…

A flaw has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. The affected element is the function addDept/updateDept/deleteDept of the file dataset\repos\warehouse\src\ma…

warehouse | Remote | Authorization
Feb 07, 2026 Feb 10, 2026
Feb 07, 2026
Feb 10, 2026
9.8 CRITICAL
CVE-2026-2090 — SourceCodester Online Class Record System search.php sql injection

A vulnerability was determined in SourceCodester Online Class Record System 1.0. This issue affects some unknown processing of the file /admin/message/search.php. Executing a manipulation of the argu…

online_class_record_system | Remote | Injection
Feb 07, 2026 Feb 10, 2026
Feb 07, 2026
Feb 10, 2026
9.8 CRITICAL
CVE-2026-2089 — SourceCodester Online Class Record System controller.php sql injection

A vulnerability was found in SourceCodester Online Class Record System 1.0. This vulnerability affects unknown code of the file /admin/subject/controller.php. Performing a manipulation of the argumen…

online_class_record_system | Remote | Injection
Feb 07, 2026 Feb 10, 2026
Feb 07, 2026
Feb 10, 2026
9.8 CRITICAL
CVE-2026-2088 — PHPGurukul Beauty Parlour Management System accepted-appointment.php sql injection

A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of the file /admin/accepted-appointment.php. Such manipulation of the argument delid le…

beauty_parlour_management_system | Remote | Injection
Feb 07, 2026 Feb 10, 2026
Feb 07, 2026
Feb 10, 2026
9.8 CRITICAL
CVE-2026-2087 — SourceCodester Online Class Record System login.php sql injection

A flaw has been found in SourceCodester Online Class Record System 1.0. Affected by this issue is some unknown functionality of the file /admin/login.php. This manipulation of the argument user_email…

online_class_record_system | Remote | Injection
Feb 07, 2026 Feb 10, 2026
Feb 07, 2026
Feb 10, 2026
9.0 HIGH
CVE-2026-2086 — UTT HiPER 810G Management formFireWall strcpy buffer overflow

A vulnerability was detected in UTT HiPER 810G up to 1.7.7-171114. Affected by this vulnerability is the function strcpy of the file /goform/formFireWall of the component Management Interface. The ma…

810g_firmware 810g | Remote | Memory Corruption
Feb 07, 2026 Feb 24, 2026
Feb 07, 2026
Feb 24, 2026
8.3 HIGH
CVE-2026-2085 — D-Link DWR-M921 USSD Configuration Endpoint formUSSDSetup sub_419F20 command injection

A security vulnerability has been detected in D-Link DWR-M921 1.1.50. Affected is the function sub_419F20 of the file /boafrm/formUSSDSetup of the component USSD Configuration Endpoint. The manipulat…

dwr-m921_firmware dwr-m921 | Remote | Injection
Feb 07, 2026 Feb 12, 2026
Feb 07, 2026
Feb 12, 2026
8.3 HIGH
CVE-2026-2084 — D-Link DIR-823X set_language os command injection

A weakness has been identified in D-Link DIR-823X 250416. This impacts an unknown function of the file /goform/set_language. Executing a manipulation of the argument langSelection can lead to os comm…

dir-823x_firmware dir-823x | Remote | Injection
Feb 07, 2026 Feb 10, 2026
Feb 07, 2026
Feb 10, 2026
9.8 CRITICAL
CVE-2026-2083 — code-projects Social Networking Site delete_post.php sql injection

A security flaw has been discovered in code-projects Social Networking Site 1.0. This affects an unknown function of the file /delete_post.php. Performing a manipulation of the argument ID results in…

social_networking_site | Remote | Injection
Feb 07, 2026 Feb 12, 2026
Feb 07, 2026
Feb 12, 2026
7.2 HIGH
CVE-2026-2082 — D-Link DIR-823X set_mac_clone os command injection

A vulnerability was identified in D-Link DIR-823X 250416. The impacted element is an unknown function of the file /goform/set_mac_clone. Such manipulation of the argument mac leads to os command inje…

dir-823x_firmware dir-823x | Remote | Injection
Feb 07, 2026 Feb 10, 2026
Feb 07, 2026
Feb 10, 2026
7.2 HIGH
CVE-2026-2081 — D-Link DIR-823X set_password os command injection

A vulnerability was determined in D-Link DIR-823X 250416. The affected element is an unknown function of the file /goform/set_password. This manipulation of the argument http_passwd causes os command…

dir-823x_firmware dir-823x | Remote | Injection
Feb 07, 2026 Feb 10, 2026
Feb 07, 2026
Feb 10, 2026
8.3 HIGH
CVE-2026-2080 — UTT HiPER 810 formUser setSysAdm command injection

A vulnerability has been found in UTT HiPER 810 1.7.4-141218. This issue affects the function setSysAdm of the file /goform/formUser. The manipulation of the argument passwd1 leads to command injecti…

810_firmware 810 | Remote | Injection
Feb 07, 2026 Feb 13, 2026
Feb 07, 2026
Feb 13, 2026
Showing 20 of 5067 Results