Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.8 MEDIUM
CVE-2026-3041 — xingfuggz BaykeShop Article Sidebar custom.html cross site scripting

A security vulnerability has been detected in xingfuggz BaykeShop up to 1.3.20. Impacted is an unknown function of the file src/baykeshop/contrib/article/templates/baykeshop/sidebar/custom.html of th…

Remote | Cross-Site Scripting
Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
7.2 HIGH
CVE-2026-3040 — DrayTek Vigor 300B Web Management uploadlangs cgiGetFile os command injection

A vulnerability was identified in DrayTek Vigor 300B up to 1.5.1.6. This affects the function cgiGetFile of the file /cgi-bin/mainfunction.cgi/uploadlangs of the component Web Management Interface. T…

vigor300b_firmware vigor300b | Remote | Injection
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
6.1 MEDIUM
CVE-2026-3028 — erzhongxmu JEEWMS JeecgListDemoController.java doAdd cross site scripting

A vulnerability was determined in erzhongxmu JEEWMS up to 3.7. This vulnerability affects the function doAdd of the file src/main/java/com/jeecg/demo/controller/JeecgListDemoController.java. This man…

jeewms jeewms | Remote | Cross-Site Scripting
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
5.4 MEDIUM
CVE-2026-27742 — Bludit <= 3.16.2 Stored XSS in Post Content

Bludit version 3.16.2 contains a stored cross-site scripting (XSS) vulnerability in the post content functionality. The application performs client-side sanitation of content input but does not enfor…

bludit | Remote | Cross-Site Scripting
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
5.1 MEDIUM
CVE-2026-27741 — Bludit <= 3.16.1 CSRF in Plugin and Theme Management Endpoints

Bludit version 3.16.1 contains a cross-site request forgery (CSRF) vulnerability in the /admin/uninstall-plugin/ and /admin/install-theme/ endpoints. The application does not implement anti-CSRF toke…

bludit | Remote | Cross-Site Request Forgery
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
8.7 HIGH
CVE-2026-25649 — Traccar Vulnerable to Authorization Code Theft via Open Redirect in OIDC Provider Endpoin…

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users can steal OAuth 2.0 authorization codes by exploiting an open redirect…

traccar | Remote | Authentication
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
7.5 HIGH
CVE-2025-69248 — free5GC has Array Index Out of Bounds in AMF Leading to Denial of Service

free5GC is an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.1 of free5GC's AMF service have a Buffer Overflow vulnerability leading to Denial of S…

free5gc amf | Remote | Denial of Service
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
7.5 HIGH
CVE-2025-69247 — free5GC has Heap Buffer Overflow in UPF Leading to Denial of Service

free5GC go-upf is the User Plane Function (UPF) implementation for 5G networks that is part of the free5GC project. Versions prior to 1.2.8 have a Heap-based Buffer Overflow (CWE-122) vulnerability l…

free5gc go-upf | Remote | Memory Corruption
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
7.5 HIGH
CVE-2025-69232 — free5GC hasProtocol Compliance Violation in UPF Leading to SMF Service Disruption

free5GC is an open-source project for 5th generation (5G) mobile core networks. free5GC go-upf versions up to and including 1.2.6, corresponding to free5gc smf up to and including 1.4.0, have an Impr…

free5gc smf go-upf | Remote | Denial of Service
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
5.3 MEDIUM
CVE-2025-69208 — free5GC UDR's NEF incorrectly returns 500 for missing PFD data (UDR 404) in Nnef_PfdManag…

free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. Versions prior to 1.4.1 contain an Improper Error Handling vulnerabi…

free5gc udr | Remote | Information Disclosure
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
5.3 MEDIUM
CVE-2026-3075 — WordPress Simple Ajax Chat plugin <= 20251121 - Sensitive Data Exposure vulnerability

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Jeff Starr Simple Ajax Chat simple-ajax-chat allows Retrieve Embedded Sensitive Data.This issue affects Sim…

simple_ajax_chat | Remote | Information Disclosure
Feb 23, 2026 Feb 27, 2026
Feb 23, 2026
Feb 27, 2026
6.1 MEDIUM
CVE-2026-3027 — erzhongxmu JEEWMS UEditor getContent.jsp cross site scripting

A vulnerability was found in erzhongxmu JEEWMS up to 3.7. This affects an unknown part of the file src/main/webapp/plug-in/ueditor/jsp/getContent.jsp of the component UEditor. The manipulation of the…

jeewms | Remote | Cross-Site Scripting
Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
7.5 HIGH
CVE-2026-3026 — erzhongxmu JEEWMS UEditor getRemoteImage.jsp server-side request forgery

A vulnerability has been found in erzhongxmu JEEWMS 3.7. Affected by this issue is some unknown functionality of the file /plug-in/ueditor/jsp/getRemoteImage.jsp of the component UEditor. The manipul…

jeewms | Remote | Server-Side Request Forgery
Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
9.8 CRITICAL
CVE-2026-3025 — ShuoRen Smart Heating Integrated Management Platform ExampleNodeService.asmx unrestricted…

A flaw has been found in ShuoRen Smart Heating Integrated Management Platform 1.0.0. Affected by this vulnerability is an unknown functionality of the file /MP/Service/Webservice/ExampleNodeService.a…

smart_heating_integrated_management_platform | Remote | Misconfiguration
Feb 23, 2026 Mar 03, 2026
Feb 23, 2026
Mar 03, 2026
8.7 HIGH
CVE-2026-25648 — Traccar Vulnerable to Stored Cross-Site Scripting (XSS) via Malicious SVG File Upload

Versions of the Traccar open-source GPS tracking system starting with 6.11.1 contain an issue in which authenticated users can execute arbitrary JavaScript in the context of other users' browsers by …

traccar | Remote | Cross-Site Scripting
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
5.1 MEDIUM
CVE-2026-23694 — Aruba HiSpeed Cache < 3.0.5 CSRF in Multiple Administrative AJAX Actions

Aruba HiSpeed Cache (aruba-hispeed-cache) WordPress plugin versions prior to 3.0.5 contain a cross-site request forgery (CSRF) vulnerability affecting multiple administrative AJAX actions. The handle…

aruba_hispeed_cache | Remote | Cross-Site Request Forgery
Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
10.0 CRITICAL
CVE-2026-23693 — ElementsKit Elementor Addons < 3.7.9 Unauthenticated Mailchimp REST Endpoint

ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor (elementskit-lite) WordPress plugin versions prior to 3.7.9 expose the REST endpoint /wp-json/elementskit/v1/widget/ma…

Remote | Server-Side Request Forgery
Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
6.5 MEDIUM
CVE-2026-23521 — Traccar vulnerable to Path Traversal and External Control of File Name or Path

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users who can create or edit devices can set a device `uniqueId` to an absol…

traccar | Remote | Path Traversal
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
9.1 CRITICAL
CVE-2025-71056 — GCOM EPON Session Hijacking Vulnerability

Improper session management in GCOM EPON 1GE ONU version C00R371V00B01 allows attackers to execute a session hijacking attack via spoofing the IP address of an authenticated user.

Remote | Authentication
Feb 23, 2026 Feb 27, 2026
Feb 23, 2026
Feb 27, 2026
8.8 HIGH
CVE-2025-70328 — TOTOLINK X6000R OS Command Injection

TOTOLINK X6000R v9.4.0cu.1498_B20250826 contains an OS command injection vulnerability in the NTPSyncWithHost handler of the /usr/sbin/shttpd executable. The host_time parameter is retrieved via sub_…

x6000r_firmware x6000r | Remote | Injection
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
Showing 20 of 5392 Results