Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-2064 — Portabilis i-Educar User Data meusdadod.php cross site scripting

A vulnerability was identified in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/meusdadod.php of the component User Data Page. Such …

i-educar | Remote | Cross-Site Scripting
Feb 06, 2026 Feb 11, 2026
Feb 06, 2026
Feb 11, 2026
6.8 MEDIUM
CVE-2026-25727 — time affected by a stack exhaustion denial of service attack

time provides date and time handling in Rust. From 0.3.6 to before 0.3.47, when user-provided input is provided to any type that parses with the RFC 2822 format, a denial of service attack via stack …

time | Remote | Denial of Service
Feb 06, 2026 Feb 24, 2026
Feb 06, 2026
Feb 24, 2026
9.1 CRITICAL
CVE-2026-25643 — Frigate Affected by Authenticated Remote Command Execution (RCE) and Container Escape

Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.4, a critical Remote Command Execution (RCE) vulnerability has been identified in the Frig…

frigate | Remote | Injection
Feb 06, 2026 Feb 11, 2026
Feb 06, 2026
Feb 11, 2026
6.1 MEDIUM
CVE-2026-25642 — HedgeDoc security headers for uploaded files were not working

HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.6, files served below the /uploads/ endpoint did not use a more strict security-policy. This resulted i…

hedgedoc | Remote | Misconfiguration
Feb 06, 2026 Feb 25, 2026
Feb 06, 2026
Feb 25, 2026
10.0 CRITICAL
CVE-2026-25641 — SandboxJS has a sandbox escape via TOCTOU bug on keys in property accesses

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, there is a sandbox escape vulnerability due to a mismatch between the key on which the validation is performed and the key used for acce…

sandboxjs | Remote | Misconfiguration
Feb 06, 2026 Feb 18, 2026
Feb 06, 2026
Feb 18, 2026
7.1 HIGH
CVE-2026-25640 — Pydantic AI affected by Stored XSS via Path Traversal in Web UI CDN URL

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 to before 1.51.0, a path traversal vulnerability in the Pydantic AI web UI allows an a…

pydantic_ai | Remote | Path Traversal
Feb 06, 2026 Feb 20, 2026
Feb 06, 2026
Feb 20, 2026
10.0 CRITICAL
CVE-2026-25587 — SandboxJS has a Sandbox Escape

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, as Map is in SAFE_PROTOYPES, it's prototype can be obtained via Map.prototype. By overwriting Map.prototype.has the sandbox can be escap…

sandboxjs | Remote | Misconfiguration
Feb 06, 2026 Feb 18, 2026
Feb 06, 2026
Feb 18, 2026
10.0 CRITICAL
CVE-2026-25586 — SandboxJS has a Sandbox Escape via Prototype Whitelist Bypass and Host Prototype Pollution

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, a sandbox escape is possible by shadowing hasOwnProperty on a sandbox object, which disables prototype whitelist enforcement in the prop…

sandboxjs | Remote | Misconfiguration
Feb 06, 2026 Feb 18, 2026
Feb 06, 2026
Feb 18, 2026
10.0 CRITICAL
CVE-2026-25520 — SandboxJS has a Sandbox Escape

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, The return values of functions aren't wrapped. Object.values/Object.entries can be used to get an Array containing the host's Function c…

sandboxjs | Remote | Authentication
Feb 06, 2026 Feb 18, 2026
Feb 06, 2026
Feb 18, 2026
3.5 LOW
CVE-2026-22254 — Winter Affected by Stored Cross-Site Scripting (XSS) in Asset Manager

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Versions of Winter CMS before 1.2.10 allow users with access to the CMS Asset Manager were able to up…

winter | Remote | Injection
Feb 06, 2026 Feb 20, 2026
Feb 06, 2026
Feb 20, 2026
9.8 CRITICAL
CVE-2026-1709 — Keylime: keylime: authentication bypass allows unauthorized administrative operations due…

A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows u…

Feb 06, 2026 Mar 05, 2026
Feb 06, 2026
Mar 05, 2026
3.3 LOW
CVE-2025-15320 — Tanium addressed a denial of service vulnerability in Tanium Client.

Tanium addressed a denial of service vulnerability in Tanium Client.

client | Denial of Service
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
7.2 HIGH
CVE-2026-2063 — D-Link DIR-823X Web Management set_ac_server os command injection

A security flaw has been discovered in D-Link DIR-823X 250416. This vulnerability affects unknown code of the file /goform/set_ac_server of the component Web Management Interface. The manipulation of…

dir-823x_firmware dir-823x | Remote | Injection
Feb 06, 2026 Feb 11, 2026
Feb 06, 2026
Feb 11, 2026
7.5 HIGH
CVE-2026-2062 — Open5GS PGW S5U Address sgwc_sxa_handle_session_modification_response null pointer derefe…

A vulnerability was identified in Open5GS up to 2.7.6. This affects the function sgwc_s5c_handle_modify_bearer_response/sgwc_sxa_handle_session_modification_response of the component PGW S5U Address …

open5gs | Remote | Memory Corruption
Feb 06, 2026 Feb 11, 2026
Feb 06, 2026
Feb 11, 2026
9.8 CRITICAL
CVE-2026-25753 — PlaciPy has a Hard-Coded Default Password for All Student Accounts (Account Takeover)

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application uses a hard-coded, static default password for all newly created student accounts. Th…

placipy | Remote | Authentication
Feb 06, 2026 Feb 11, 2026
Feb 06, 2026
Feb 11, 2026
9.3 CRITICAL
CVE-2026-25752 — FUXA Unauthenticated Remote Arbitrary Device Tag Write

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An authorization bypass vulnerability in FUXA allows an unauthenticated, remote attacker to modify device tags via WebSockets…

fuxa | Remote | Authorization
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
9.1 CRITICAL
CVE-2026-25751 — FUXA Unauthenticated Exposure of Plaintext Database Credentials

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An information disclosure vulnerability in FUXA allows an unauthenticated, remote attacker to retrieve sensitive administrati…

fuxa | Remote | Information Disclosure
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
6.1 MEDIUM
CVE-2026-25651 — client-certificate-auth has an Open Redirect via Host Header Injection in HTTP-to-HTTPS r…

client-certificate-auth is middleware for Node.js implementing client SSL certificate authentication/authorization. Versions 0.2.1 and 0.3.0 of client-certificate-auth contain an open redirect vulner…

client-certificate-auth | Remote | Misconfiguration
Feb 06, 2026 Feb 24, 2026
Feb 06, 2026
Feb 24, 2026
7.5 HIGH
CVE-2026-25650 — MCP Salesforce Connector has arbitrary attribute access which leads to disclosure of Sale…

MCP Salesforce Connector is a Model Context Protocol (MCP) server implementation for Salesforce integration. Prior to 0.1.10, arbitrary attribute access leads to disclosure of Salesforce auth token. …

mcp_salesforce_connector | Remote | Information Disclosure
Feb 06, 2026 Feb 24, 2026
Feb 06, 2026
Feb 24, 2026
5.4 MEDIUM
CVE-2026-25647 — Lute has a Stored Cross-Site Scripting (XSS) via Markdown hyperlink

Lute is a structured Markdown engine supporting Go and JavaScript. Lute 1.7.6 and earlier (as used in SiYuan before) has a Stored Cross-Site Scripting (XSS) vulnerability in the Markdown rendering en…

siyuan | Remote | Cross-Site Scripting
Feb 06, 2026 Feb 24, 2026
Feb 06, 2026
Feb 24, 2026
Showing 20 of 5120 Results