Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2019-25300 — thejshen Globitek CMS 1.4 - 'id' SQL Injection

thejshen Globitek CMS 1.4 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'id' GET parameter. Attackers can exploit boolean-based, time-based, …

Remote | Injection
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
7.1 HIGH
CVE-2019-25299 — rimbalinux AhadPOS 1.11 - 'alamatCustomer' SQL Injection

RimbaLinux AhadPOS 1.11 contains a SQL injection vulnerability in the 'alamatCustomer' parameter that allows attackers to manipulate database queries through crafted POST requests. Attackers can expl…

Remote | Injection
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
9.1 CRITICAL
CVE-2019-25298 — html5_snmp 1.11 - 'Router_ID' SQL Injection

html5_snmp 1.11 contains multiple SQL injection vulnerabilities that allow attackers to manipulate database queries through Router_ID and Router_IP parameters. Attackers can exploit error-based, time…

html5_snmp | Remote | Injection
Feb 06, 2026 Mar 02, 2026
Feb 06, 2026
Mar 02, 2026
6.4 MEDIUM
CVE-2019-25294 — html5_snmp 1.11 - 'Remark' Persistent Cross-Site Scripting

html5_snmp 1.11 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through the 'Remark' parameter in add_router_operation.php. Attackers can cr…

html5_snmp | Remote | Cross-Site Scripting
Feb 06, 2026 Mar 02, 2026
Feb 06, 2026
Mar 02, 2026
8.5 HIGH
CVE-2019-25293 — Blue Stacks App Player 2.4.44.62.57 - "BstHdLogRotatorSvc" Unquote Service Path

BlueStacks App Player 2.4.44.62.57 contains an unquoted service path vulnerability in the BstHdLogRotatorSvc service that allows local attackers to potentially execute arbitrary code. Attackers can e…

bluestacks | Misconfiguration
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
8.5 HIGH
CVE-2019-25292 — Alps HID Monitor Service 8.1.0.10 - 'ApHidMonitorService' Unquote Service Path

Alps HID Monitor Service 8.1.0.10 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the…

| Misconfiguration
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
8.5 HIGH
CVE-2019-25266 — Wondershare Application Framework Service 2.4.3.231 - 'WsAppService' Unquote Service Path

Wondershare Application Framework Service 2.4.3.231 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attacke…

| Misconfiguration
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
9.8 CRITICAL
CVE-2026-2057 — SourceCodester Medical Center Portal Management System login.php sql injection

A vulnerability was detected in SourceCodester Medical Center Portal Management System 1.0. This affects an unknown function of the file /login.php. The manipulation of the argument User results in s…

Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
7.7 HIGH
CVE-2025-13523 — Cross-Site Scripting (XSS) via Unescaped Display Names in Mattermost Confluence Plugin OA…

Mattermost Confluence plugin version <1.7.0 fails to properly escape user-controlled display names in HTML template rendering which allows authenticated Confluence users with malicious display names …

confluence | Remote | Cross-Site Scripting
Feb 06, 2026 Feb 24, 2026
Feb 06, 2026
Feb 24, 2026
7.5 HIGH
CVE-2026-2056 — D-Link DIR-605L/DIR-619L DHCP Connection Status wan_connection_status.asp information dis…

A security vulnerability has been detected in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. The impacted element is an unknown function of the file /wan_connection_status.asp of the component DHCP Co…

dir-605l_firmware dir-619l_firmware dir-605l dir-619l | Remote | Information Disclosure
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
5.4 MEDIUM
CVE-2026-1337 — Insufficient escaping of unicode characters in query log

Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that treats them as HTML. The…

neo4j | Remote | Cross-Site Scripting
Feb 06, 2026 Feb 24, 2026
Feb 06, 2026
Feb 24, 2026
8.3 HIGH
CVE-2025-13818 — Local privilege escalation in ESET Management Agent for Windows

Local privilege escalation vulnerability via insecure temporary batch file execution in ESET Management Agent

management_agent | Misconfiguration
Feb 06, 2026 Feb 18, 2026
Feb 06, 2026
Feb 18, 2026
7.5 HIGH
CVE-2026-2055 — D-Link DIR-605L/DIR-619L DHCP Client Information information disclosure

A weakness has been identified in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. The affected element is an unknown function of the component DHCP Client Information Handler. Executing a manipulation …

dir-605l_firmware dir-619l_firmware dir-605l dir-619l | Remote | Information Disclosure
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
7.5 HIGH
CVE-2026-2054 — D-Link DIR-605L/DIR-619L Wifi Setting information disclosure

A security flaw has been discovered in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. Impacted is an unknown function of the component Wifi Setting Handler. Performing a manipulation results in inform…

dir-605l_firmware dir-619l_firmware dir-605l dir-619l | Remote | Information Disclosure
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
9.8 CRITICAL
CVE-2026-2018 — itsourcecode School Management System controller.php sql injection

A flaw has been found in itsourcecode School Management System 1.0. This affects an unknown part of the file /ramonsys/settings/controller.php. This manipulation of the argument ID causes sql injecti…

Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
10.0 HIGH
CVE-2026-2017 — IP-COM W30AP POST Request wx3auth R7WebsSecurityHandler stack-based overflow

A vulnerability was detected in IP-COM W30AP up to 1.0.0.11(1340). Affected by this issue is the function R7WebsSecurityHandler of the file /goform/wx3auth of the component POST Request Handler. The …

w30ap_firmware w30ap | Remote | Memory Corruption
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
7.8 HIGH
CVE-2026-2016 — happyfish100 libfastcommon base64.c base64_decode stack-based overflow

A security vulnerability has been detected in happyfish100 libfastcommon up to 1.0.84. Affected by this vulnerability is the function base64_decode of the file src/base64.c. The manipulation leads to…

libfastcommon | Memory Corruption
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
6.4 MEDIUM
CVE-2026-1293 — Yoast SEO <= 26.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'yoast-s…

The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the `yoast-schema` block attribute in all versions up to…

Remote | Cross-Site Scripting
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
8.8 HIGH
CVE-2026-2015 — Portabilis i-Educar Final Status Import FinalStatusImportService.php improper authorizati…

A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file FinalStatusImportService.php of the component Final Status Import. Executing a manipulati…

i-educar | Remote | Authorization
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
9.8 CRITICAL
CVE-2026-2014 — itsourcecode Student Management System index.php sql injection

A security flaw has been discovered in itsourcecode Student Management System 1.0. This impacts an unknown function of the file /ramonsys/billing/index.php. Performing a manipulation of the argument …

Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
Showing 20 of 5141 Results