Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-2561 — JingDong JD Cloud Box AX6600 jdcweb_rpc jdcapi web_get_ddns_uptime privileges management

A vulnerability was found in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. This affects the function web_get_ddns_uptime of the file /jdcapi of the component jdcweb_rpc. Performing a manipulation r…

ax6600_firmware ax6600 | Remote | Authentication
Feb 16, 2026 Feb 23, 2026
Feb 16, 2026
Feb 23, 2026
8.8 HIGH
CVE-2026-2447 — Heap buffer overflow in libvpx

Heap buffer overflow in libvpx. This vulnerability affects Firefox < 147.0.4, Firefox ESR < 140.7.1, Firefox ESR < 115.32.1, Thunderbird < 140.7.2, and Thunderbird < 147.0.2.

firefox firefox_esr thunderbird | Remote | Memory Corruption
Feb 16, 2026 Feb 22, 2026
Feb 16, 2026
Feb 22, 2026
4.3 MEDIUM
CVE-2026-2032 — Interrupted page loads in new tabs could allow website spoofing under trusted domains in …

Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page content, allowing the attacker to spoof arbitrary HTML under a trusted domain. Thi…

firefox | Remote | Cross-Site Scripting
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
6.5 MEDIUM
CVE-2026-2560 — kalcaddle kodbox Media File Preview Plugin VideoResize.class.php run os command injection

A vulnerability has been found in kalcaddle kodbox up to 1.64.05. The impacted element is the function run of the file plugins/fileThumb/lib/VideoResize.class.php of the component Media File Preview …

kodbox | Remote | Injection
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
6.5 MEDIUM
CVE-2026-2558 — GeekAI net_handler.go Download server-side request forgery

A flaw has been found in GeekAI up to 4.2.4. The affected element is the function Download of the file api/handler/net_handler.go. This manipulation of the argument url causes server-side request for…

Remote | Server-Side Request Forgery
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
5.4 MEDIUM
CVE-2026-2557 — cskefu File Upload MediaController.java upload cross site scripting

A vulnerability was detected in cskefu up to 8.0.1. Impacted is the function Upload of the file com/cskefu/cc/controller/resource/MediaController.java of the component File Upload. The manipulation r…

cskefu | Remote | Cross-Site Scripting
Feb 16, 2026 Feb 20, 2026
Feb 16, 2026
Feb 20, 2026
7.8 HIGH
CVE-2026-1335 — Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS…

An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an atta…

solidworks_edrawings | Memory Corruption
Feb 16, 2026 Feb 26, 2026
Feb 16, 2026
Feb 26, 2026
7.8 HIGH
CVE-2026-1334 — Out-Of-Bounds Read vulnerability affecting the EPRT file reading procedure in SOLIDWORKS …

An Out-Of-Bounds Read vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attac…

solidworks_edrawings | Memory Corruption
Feb 16, 2026 Feb 26, 2026
Feb 16, 2026
Feb 26, 2026
7.8 HIGH
CVE-2026-1333 — Use of Uninitialized Variable vulnerability affecting the EPRT file reading procedure in …

A Use of Uninitialized Variable vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allo…

solidworks_edrawings | Memory Corruption
Feb 16, 2026 Feb 26, 2026
Feb 16, 2026
Feb 26, 2026
6.5 MEDIUM
CVE-2026-2556 — cskefu Endpoint MediaController.java server-side request forgery

A security vulnerability has been detected in cskefu up to 8.0.1. This issue affects some unknown processing of the file com/cskefu/cc/controller/resource/MediaController.java of the component Endpoi…

cskefu | Remote | Server-Side Request Forgery
Feb 16, 2026 Feb 20, 2026
Feb 16, 2026
Feb 20, 2026
7.6 HIGH
CVE-2026-1046 — Arbitrary application execution via unvalidated server-controlled URLs in Help menu

Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via the user clicking o…

mattermost_server | Remote | Path Traversal
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
3.8 LOW
CVE-2025-14573 — Team Admin Bypass of Invite Permissions via allow_open_invite Field

Mattermost versions 10.11.x <= 10.11.9 fail to enforce invite permissions when updating team settings, which allows team administrators without proper permissions to bypass restrictions and add users…

mattermost_server | Remote | Authorization
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
4.3 MEDIUM
CVE-2025-14350 — Information disclosure via channel mentions in posts

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate team membership when processing channel mentions which allows authenticated users to determine the…

mattermost_server | Remote | Information Disclosure
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
7.5 HIGH
CVE-2026-2555 — JeecgBoot Retrieval-Augmented Generation AiragKnowledgeController.java importDocumentFrom…

A weakness has been identified in JeecgBoot 3.9.1. This vulnerability affects the function importDocumentFromZip of the file org/jeecg/modules/airag/llm/controller/AiragKnowledgeController.java of th…

jeecg_boot | Remote | Injection
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
6.5 MEDIUM
CVE-2026-2553 — tushar-2223 Hotel-Management-System HTTP POST Request home.php sql injection

A security flaw has been discovered in tushar-2223 Hotel-Management-System up to bb1f3b3666124b888f1e4bcf51b6fba9fbb01d15. This affects an unknown part of the file /home.php of the component HTTP POS…

Remote | Injection
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
5.5 MEDIUM
CVE-2026-2552 — ZenTao Editor control.php delete path traversal

A vulnerability was identified in ZenTao up to 21.7.8. Affected by this issue is the function delete of the file editor/control.php of the component Committer. Such manipulation of the argument fileP…

zentao | Path Traversal
Feb 16, 2026 Feb 20, 2026
Feb 16, 2026
Feb 20, 2026
4.3 MEDIUM
CVE-2025-2418 — Open Redirect in TR7's Web Application Firewall

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in TR7 Cyber ​​Defense Inc. Web Application Firewall allows Phishing.This issue affects Web Application Firewall: from 4.30 through 1…

| Misconfiguration
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
5.7 MEDIUM
CVE-2025-13821 — User profile update exposes password hash and MFA secrets

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to sanitize sensitive data in WebSocket messages which allows authenticated users to exfiltrate password hashes and MFA…

mattermost_server | Remote | Information Disclosure
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
5.5 MEDIUM
CVE-2026-2551 — ZenTao Backup control.php delete path traversal

A vulnerability was determined in ZenTao up to 21.7.8. Affected by this vulnerability is the function delete of the file editor/control.php of the component Backup Handler. This manipulation of the a…

zentao | Remote | Path Traversal
Feb 16, 2026 Feb 20, 2026
Feb 16, 2026
Feb 20, 2026
7.5 HIGH
CVE-2026-2452 — Unsafe variable evaluation in email templates

Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's name for the fina…

pretix | Remote | Information Disclosure
Feb 16, 2026 Mar 02, 2026
Feb 16, 2026
Mar 02, 2026
Showing 20 of 5064 Results