Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
2.3 LOW
CVE-2026-21620 — TFTP Path Traversal

Relative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erlang/otp (tftp_file modules), erlang otp inets (tftp_file modules), erlang otp tftp (tftp_file module…

erlang\/otp otp | Remote | Path Traversal
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
8.4 HIGH
CVE-2026-26050 — RICOH Joblog Analysis Tool DLL Search Path Loading Vulnerability

The installer for ジョブログ集計/分析ソフトウェア RICOHジョブログ集計ツール versions prior to Ver.1.3.7 contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, ar…

| Misconfiguration
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
6.1 MEDIUM
CVE-2026-26370 — WordPress Survey Maker Cross-Site Scripting Vulnerability

WordPress Plugin "Survey Maker" versions 5.1.7.7 and prior contain a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in the user's web brow…

survey_maker | Cross-Site Scripting
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
6.5 MEDIUM
CVE-2025-59819 — Authenticated Arbitrary File Read via filepath parameter

This vulnerability allows authenticated attackers to read an arbitrary file by changing a filepath parameter into an internal system path.

Remote | Path Traversal
Feb 20, 2026 Feb 23, 2026
Feb 20, 2026
Feb 23, 2026
5.1 MEDIUM
CVE-2026-2825 — rachelos WeRSS we-mp-rss Article fix.py fix_html cross site scripting

A vulnerability has been found in rachelos WeRSS we-mp-rss up to 1.4.8. This impacts the function fix_html of the file tools/fix.py of the component Article Module. The manipulation leads to cross si…

Remote | Cross-Site Scripting
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
8.8 HIGH
CVE-2026-2824 — Comfast CF-E7 webmggnt mbox-config sub_441CF4 command injection

A flaw has been found in Comfast CF-E7 2.6.0.9. This affects the function sub_441CF4 of the file /cgi-bin/mbox-config?method=SET&section=ping_config of the component webmggnt. Executing a manipulatio…

cf-e7_firmware cf-e7 | Remote | Injection
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
8.8 HIGH
CVE-2026-2823 — Comfast CF-E7 webmggnt mbox-config sub_41ACCC command injection

A vulnerability was detected in Comfast CF-E7 2.6.0.9. The impacted element is the function sub_41ACCC of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone of the component webmggnt. Perf…

cf-e7_firmware cf-e7 | Remote | Injection
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
8.8 HIGH
CVE-2026-2822 — JeecgBoot Backend airag_app,1,create_by sql injection

A security vulnerability has been detected in JeecgBoot up to 3.9.1. The affected element is an unknown function of the file /jeecgboot/sys/dict/loadDict/airag_app,1,create_by of the component Backen…

jeecg_boot | Remote | Injection
Feb 20, 2026 Feb 24, 2026
Feb 20, 2026
Feb 24, 2026
5.5 MEDIUM
CVE-2026-2739 — Bouncy Castle BN JavaScript Infinite Loop Vulnerability

This affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, ha…

Remote | Denial of Service
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
7.5 HIGH
CVE-2026-2821 — Fujian Smart Integrated Management Platform System XCamera.ashx sql injection

A weakness has been identified in Fujian Smart Integrated Management Platform System up to 7.5. Impacted is an unknown function of the file /Module/CRXT/Controller/XCamera.ashx. This manipulation of …

Remote | Injection
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
6.4 MEDIUM
CVE-2026-2384 — Quiz Maker <= 6.7.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shor…

The Quiz Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `vc_quizmaker` shortcode in all versions up to, and including, 6.7.1.7 due to insufficient input sani…

quiz_maker | Remote | Cross-Site Scripting
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
5.3 MEDIUM
CVE-2026-27017 — uTLS has a Chrome Parrot Fingerprint Vulnerability due to GREASE ECH Cipher Suite Mismatch

uTLS is a fork of crypto/tls, created to customize ClientHello for fingerprinting resistance while still using it for the handshake. Versions 1.6.0 through 1.8.0 contain a fingerprint mismatch with C…

utls | Remote | Cryptography
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
8.7 HIGH
CVE-2026-26996 — minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern

minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a…

minimatch | Remote | Denial of Service
Feb 20, 2026 Mar 06, 2026
Feb 20, 2026
Mar 06, 2026
6.5 MEDIUM
CVE-2026-26994 — uTLS ServerHellos are accepted without checking TLS 1.3 downgrade canaries

uTLS is a fork of crypto/tls, created to customize ClientHello for fingerprinting resistance while still using it for the handshake. In versions 1.6.7 and below, uTLS did not implement the TLS 1.3 do…

utls | Remote | Cryptography
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
5.4 MEDIUM
CVE-2026-26993 — Flare has XSS vulnerability in Raw File Preview

Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Versions 1.7.0 and below allow users to upload files without proper content validation or sanitiza…

flare | Remote | Cross-Site Scripting
Feb 20, 2026 Mar 03, 2026
Feb 20, 2026
Mar 03, 2026
5.1 MEDIUM
CVE-2026-26992 — LibreNMS has Stored Cross-Site Scripting via unsanitized /port-groups name

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. In versions 26.1.1 and below, the port group name is not sanitized, allowing attackers with admin privileges to perform S…

librenms | Remote | Cross-Site Scripting
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
5.1 MEDIUM
CVE-2026-26991 — LibreNMS vulnerable to Stored Cross-site Scripting through unsanitized /device-groups name

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. In versions 26.1.1 and below, the device group name is not sanitized, allowing attackers with admin privileges to perform…

librenms | Remote | Cross-Site Scripting
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
7.5 HIGH
CVE-2026-2820 — Fujian Smart Integrated Management Platform System XAccessPermissionPlus.ashx sql injecti…

A security flaw has been discovered in Fujian Smart Integrated Management Platform System up to 7.5. This issue affects some unknown processing of the file /Module/CRXT/Controller/XAccessPermissionPl…

Remote | Injection
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
6.5 MEDIUM
CVE-2026-2819 — Dromara RuoYi-Vue-Plus Workflow deleteByInstanceIds SaServletFilter authorization

A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.5.3. This vulnerability affects the function SaServletFilter of the file /workflow/instance/deleteByInstanceIds of the component Workf…

ruoyi-vue-plus | Remote | Authorization
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
5.4 MEDIUM
CVE-2026-27016 — LibreNMS has Stored XSS in Custom OID - unit parameter missing strip_tags()

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 24.10.0 through 26.1.1 are vulnerable to Stored XSS via the unit parameter in Custom OID. The Custom OID functio…

librenms | Remote | Cross-Site Scripting
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
Showing 20 of 5327 Results