Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-2451 — Unsafe variable evaluation in email templates

Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's name for the fina…

Remote | Information Disclosure
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
7.5 HIGH
CVE-2026-2415 — Unsafe variable evaluation in email templates

Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's name for the fina…

pretix | Remote | Information Disclosure
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
10.0 CRITICAL
CVE-2026-2577 — Nanobot Unauthenticated WhatsApp Session Hijack via WebSocket Bridge

The WhatsApp bridge component in Nanobot binds the WebSocket server to all network interfaces (0.0.0.0) on port 3001 by default and does not require authentication for incoming connections. An unauth…

Remote | Authentication
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
10.0 HIGH
CVE-2026-2550 — EFM iptime A6004MX timepro.cgi commit_vpncli_file_upload unrestricted upload

A vulnerability was found in EFM iptime A6004MX 14.18.2. Affected is the function commit_vpncli_file_upload of the file /cgi/timepro.cgi. The manipulation results in unrestricted upload. The attack m…

Remote | Misconfiguration
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
7.5 HIGH
CVE-2026-2549 — zhanghuanhao LibrarySystem 图书馆管理系统 BookController.java access control

A vulnerability has been found in zhanghuanhao LibrarySystem 图书馆管理系统 up to 1.1.1. This impacts an unknown function of the file BookController.java. The manipulation leads to improper access controls.…

Remote | Authorization
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
5.4 MEDIUM
CVE-2026-0999 — Authentication bypass via userID login when email and username login are disabled

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate login method restrictions which allows an authenticated user to bypass SSO-only login requirements…

mattermost_server | Remote | Authentication
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
4.3 MEDIUM
CVE-2026-0998 — Mattermost Zoom Plugin allows unauthorized meeting creation and post modification via ins…

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 fail to validate user identity and post ownership in the {{/api/v1/askPMI}} end…

mattermost_server zoom | Remote | Authentication
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
4.3 MEDIUM
CVE-2026-0997 — Mattermost Zoom Plugin channel preference API lacks authorization checks

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 fail to validate the authenticated user when processing {{/plugins/zoom/api/v1/…

mattermost_server zoom | Remote | Authentication
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
6.1 MEDIUM
CVE-2025-59905 — Reflected Cross-Site Scripting (XSS) in Kubysoft

Cross-Site Scripting (XSS) vulnerability reflected in Kubysoft, which occurs through multiple parameters within the endpoint ‘/node/kudaby/nodeFN/procedure’. This flaw allows the injection of arbitra…

kubysoft | Remote | Cross-Site Scripting
Feb 16, 2026 Mar 09, 2026
Feb 16, 2026
Mar 09, 2026
5.4 MEDIUM
CVE-2025-59904 — Stored Cross-Site Scripting vulnerability in Kubysoft

Stored Cross-Site Scripting (XSS) vulnerability in Kubysoft, which is triggered through multiple parameters in the '/kForms/app' endpoint. This issue allows malicious scripts to be injected and execu…

kubysoft | Remote | Cross-Site Scripting
Feb 16, 2026 Mar 09, 2026
Feb 16, 2026
Mar 09, 2026
5.4 MEDIUM
CVE-2025-59903 — Stored Cross-Site Scripting (XSS) in Kubysoft

Stored Cross-Site Scripting (XSS) vulnerability in Kubysoft, where uploaded SVG images are not properly sanitized. This allows attackers to embed malicious scripts within SVG files as visual content,…

kubysoft | Remote | Cross-Site Scripting
Feb 16, 2026 Mar 09, 2026
Feb 16, 2026
Mar 09, 2026
6.5 MEDIUM
CVE-2026-2548 — WAYOS FBM-220G rc sub_40F820 command injection

A flaw has been found in WAYOS FBM-220G 24.10.19. This affects the function sub_40F820 of the file rc. Executing a manipulation of the argument upnp_waniface/upnp_ssdp_interval/upnp_max_age can lead …

Remote | Injection
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
6.1 MEDIUM
CVE-2026-2547 — LigeroSmart index.pl AgentDashboard cross site scripting

A vulnerability was detected in LigeroSmart up to 6.1.26. The impacted element is the function AgentDashboard of the file /otrs/index.pl. Performing a manipulation of the argument Subaction results i…

ligerosmart | Remote | Cross-Site Scripting
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
6.1 MEDIUM
CVE-2026-2546 — LigeroSmart index.pl cross site scripting

A security vulnerability has been detected in LigeroSmart up to 6.1.26. The affected element is an unknown function of the file /otrs/index.pl. Such manipulation of the argument SortBy leads to cross…

ligerosmart | Remote | Cross-Site Scripting
Feb 16, 2026 Feb 19, 2026
Feb 16, 2026
Feb 19, 2026
6.1 MEDIUM
CVE-2026-2545 — LigeroSmart index.pl cross site scripting

A weakness has been identified in LigeroSmart up to 6.1.26. Impacted is an unknown function of the file /otrs/index.pl?Action=AgentTicketSearch. This manipulation of the argument Profile causes cross…

ligerosmart | Remote | Cross-Site Scripting
Feb 16, 2026 Feb 19, 2026
Feb 16, 2026
Feb 19, 2026
7.5 HIGH
CVE-2026-2544 — yued-fe LuLu UI run.js child_process.exec os command injection

A security flaw has been discovered in yued-fe LuLu UI up to 3.0.0. This issue affects the function child_process.exec of the file run.js. The manipulation results in os command injection. The attack…

Remote | Injection
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
5.1 MEDIUM
CVE-2026-2543 — vichan-devel vichan Password Change pages.php unverified password change

A vulnerability was identified in vichan-devel vichan up to 5.1.5. This vulnerability affects unknown code of the file inc/mod/pages.php of the component Password Change Handler. The manipulation of …

Remote | Authentication
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
7.3 HIGH
CVE-2026-2542 — Total VPN win-service.exe unquoted search path

A weakness has been identified in Total VPN 0.5.29.0 on Windows. Affected by this vulnerability is an unknown functionality of the file C:\Program Files\Total VPN\win-service.exe. Executing a manipul…

| Misconfiguration
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
7.3 HIGH
CVE-2026-2538 — Flos Freeware Notepad2 Msimg32.dll uncontrolled search path

A security flaw has been discovered in Flos Freeware Notepad2 4.2.22/4.2.23/4.2.24/4.2.25. Affected is an unknown function in the library Msimg32.dll. Performing a manipulation results in uncontrolle…

| Path Traversal
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
7.5 HIGH
CVE-2026-0929 — RegistrationMagic < 6.0.7.2 - Subscriber+ Form Creation

The RegistrationMagic WordPress plugin before 6.0.7.2 does not have proper capability checks, allowing subscribers and above to create forms on the site.

registrationmagic | Remote | Authorization
Feb 16, 2026 Feb 18, 2026
Feb 16, 2026
Feb 18, 2026
Showing 20 of 5064 Results