Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-2212 — code-projects Online Music Site AdminEditCategory.php sql injection

A vulnerability was identified in code-projects Online Music Site 1.0. Affected by this vulnerability is an unknown functionality of the file /Administrator/PHP/AdminEditCategory.php. The manipulatio…

online_music_site | Remote | Injection
Feb 09, 2026 Feb 10, 2026
Feb 09, 2026
Feb 10, 2026
9.8 CRITICAL
CVE-2026-2211 — code-projects Online Music Site AdminDeleteCategory.php sql injection

A vulnerability was determined in code-projects Online Music Site 1.0. Affected is an unknown function of the file /Administrator/PHP/AdminDeleteCategory.php. Executing a manipulation of the argument…

online_music_site | Remote | Injection
Feb 09, 2026 Feb 10, 2026
Feb 09, 2026
Feb 10, 2026
8.7 HIGH
CVE-2025-66608 — Yokogawa Electric Corporation FAST/TOOLS URL Validation Remote File Disclosure

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly validate URLs. An attacker could send specially crafted requests to steal fil…

fast\/tools | Remote | Server-Side Request Forgery
Feb 09, 2026 Mar 06, 2026
Feb 09, 2026
Mar 06, 2026
6.3 MEDIUM
CVE-2025-66607 — Yokogawa Electric Corporation FAST/TOOLS Open Redirect Vulnerability

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The response header contains an insecure setting. Users could be redirected to malicious sites by an attacke…

fast\/tools | Remote | Misconfiguration
Feb 09, 2026 Mar 06, 2026
Feb 09, 2026
Mar 06, 2026
9.6 CRITICAL
CVE-2025-66606 — Yokogawa Electric Corporation FAST/TOOLS URL Encoding Vulnerability (Cross-Site Scripting)

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly encode URLs. An attacker could tamper with web pages or execute malicious scr…

fast\/tools | Remote | Cross-Site Scripting
Feb 09, 2026 Mar 05, 2026
Feb 09, 2026
Mar 05, 2026
5.3 MEDIUM
CVE-2025-66605 — Yokogawa Electric Corporation FAST/TOOLS Autocomplete Stored XSS

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. Since there are input fields on this webpage with the autocomplete attribute enabled, the input content coul…

fast\/tools | Remote | Information Disclosure
Feb 09, 2026 Mar 05, 2026
Feb 09, 2026
Mar 05, 2026
5.3 MEDIUM
CVE-2025-66604 — Yokogawa Electric Corporation FAST/TOOLS Information Disclosure Vulnerability

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The library version could be displayed on the web page. This information could be exploited by an attacker f…

fast\/tools | Remote | Information Disclosure
Feb 09, 2026 Mar 05, 2026
Feb 09, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2025-66603 — Yokogawa Electric Corporation FAST/TOOLS OPTIONS Method Vulnerability

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The web server accepts the OPTIONS method. An attacker could potentially use this information to carry out o…

fast\/tools | Remote | Information Disclosure
Feb 09, 2026 Mar 05, 2026
Feb 09, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2025-66602 — Yokogawa Electric Corporation FAST/TOOLS Remote IP Address Guessing Vulnerability

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The web server accepts access by IP address. When a worm that randomly searches for IP addresses intrudes in…

fast\/tools | Remote | Misconfiguration
Feb 09, 2026 Mar 05, 2026
Feb 09, 2026
Mar 05, 2026
6.3 MEDIUM
CVE-2025-66601 — Yokogawa Electric Corporation FAST/TOOLS MIME Type Vulnerability (Remote Code Execution)

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not specify MIME types. When an attacker performs a content sniffing attack, malicious scr…

fast\/tools | Remote | Misconfiguration
Feb 09, 2026 Mar 05, 2026
Feb 09, 2026
Mar 05, 2026
8.8 HIGH
CVE-2025-66600 — Yokogawa Electric Corporation FAST/TOOLS HTTP Strict Transport Security (HSTS) Misconfigu…

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product lacks HSTS (HTTP Strict Transport Security) configuration. When an attacker performs a Man in t…

fast\/tools | Remote | Misconfiguration
Feb 09, 2026 Feb 09, 2026
Feb 09, 2026
Feb 09, 2026
6.9 MEDIUM
CVE-2025-66599 — Yokogawa Electric Corporation FAST/TOOLS Path Disclosure Vulnerability

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. Physical paths could be displayed on web pages. This information could be exploited by an attacker for other…

fast\/tools | Remote | Information Disclosure
Feb 09, 2026 Feb 09, 2026
Feb 09, 2026
Feb 09, 2026
8.3 HIGH
CVE-2026-2210 — D-Link DIR-823X set_filtering sub_4211C8 os command injection

A vulnerability has been found in D-Link DIR-823X 250416. This affects the function sub_4211C8 of the file /goform/set_filtering. Such manipulation leads to os command injection. The attack may be la…

dir-823x_firmware dir-823x | Remote | Injection
Feb 09, 2026 Feb 11, 2026
Feb 09, 2026
Feb 11, 2026
9.0 HIGH
CVE-2026-2203 — Tenda AC8 Embedded Httpd Service fast_setting_wifi_set buffer overflow

A flaw has been found in Tenda AC8 16.03.33.05. Affected by this vulnerability is an unknown functionality of the file /goform/fast_setting_wifi_set of the component Embedded Httpd Service. This mani…

ac8_firmware ac8 | Remote | Memory Corruption
Feb 09, 2026 Feb 10, 2026
Feb 09, 2026
Feb 10, 2026
9.0 HIGH
CVE-2026-2202 — Tenda AC8 httpd WifiGuestSet fromSetWifiGusetBasic buffer overflow

A vulnerability was detected in Tenda AC8 16.03.33.05. Affected is the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet of the component httpd. The manipulation of the argument shareSp…

ac8_firmware ac8 | Remote | Memory Corruption
Feb 09, 2026 Feb 10, 2026
Feb 09, 2026
Feb 10, 2026
5.4 MEDIUM
CVE-2026-2201 — ZeroWdd studentmanager LeaveController.java addLeave cross site scripting

A security vulnerability has been detected in ZeroWdd studentmanager up to 2151560fc0a50ec00426785ec1e01a3763b380d9. This impacts the function addLeave of the file src/main/java/com/wdd/studentmanage…

studentmanager | Remote | Cross-Site Scripting
Feb 09, 2026 Mar 05, 2026
Feb 09, 2026
Mar 05, 2026
4.8 MEDIUM
CVE-2026-2200 — heyewei JFinalCMS API Endpoint save cross site scripting

A weakness has been identified in heyewei JFinalCMS 5.0.0. This affects an unknown function of the file /admin/admin/save of the component API Endpoint. Executing a manipulation can lead to cross sit…

jfinalcms | Remote | Cross-Site Scripting
Feb 09, 2026 Feb 17, 2026
Feb 09, 2026
Feb 17, 2026
9.8 CRITICAL
CVE-2026-2199 — code-projects Online Reviewer System user-delete.php sql injection

A security flaw has been discovered in code-projects Online Reviewer System 1.0. The impacted element is an unknown function of the file /reviewer/system/system/admins/manage/users/user-delete.php. P…

online_reviewer_system | Remote | Injection
Feb 09, 2026 Feb 10, 2026
Feb 09, 2026
Feb 10, 2026
9.8 CRITICAL
CVE-2026-2198 — code-projects Online Reviewer System loaddata.php sql injection

A vulnerability was identified in code-projects Online Reviewer System 1.0. The affected element is an unknown function of the file /system/system/admins/assessments/pretest/loaddata.php. Such manipu…

online_reviewer_system | Remote | Injection
Feb 09, 2026 Feb 10, 2026
Feb 09, 2026
Feb 10, 2026
9.8 CRITICAL
CVE-2026-2197 — code-projects Online Reviewer System exam-delete.php sql injection

A vulnerability was determined in code-projects Online Reviewer System 1.0. Impacted is an unknown function of the file /system/system/admins/assessments/pretest/exam-delete.php. This manipulation of…

online_reviewer_system | Remote | Injection
Feb 09, 2026 Feb 10, 2026
Feb 09, 2026
Feb 10, 2026
Showing 20 of 5141 Results