Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-23632 — Gogs user can update repository content with read-only permission

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, the endpoint "PUT /repos/:owner/:repo/contents/*" does not require write permissions and allows access with read permissio…

gogs | Remote | Authorization
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
6.5 MEDIUM
CVE-2026-22592 — Gogs is Vulnerable to Denial of Service

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, an authenticated user can cause a DOS attack. If one of the repo files is deleted before synchronization, it will cause th…

gogs | Remote | Denial of Service
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
5.4 MEDIUM
CVE-2026-1769 — Stored XSS on Xerox CentreWare Web 7.0.6

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Xerox CentreWare on Windows allows Stored XSS.This issue affects CentreWare: through 7.0.6…

windows centreware_web | Remote | Cross-Site Scripting
Feb 06, 2026 Feb 24, 2026
Feb 06, 2026
Feb 24, 2026
7.6 HIGH
CVE-2025-70963 — Gophish Insecure API Key Exposure

Gophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived API key directly inside the rendered HTML/JavaScript of the page on every login…

gophish | Remote | Authorization
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
8.8 HIGH
CVE-2025-64175 — Gogs Vulnerable to 2FA Bypass via Recovery Code

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, Gogs’ 2FA recovery code validation does not scope codes by user, enabling cross-account bypass. If an attacker knows a vic…

gogs | Remote | Authentication
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
7.8 HIGH
CVE-2026-2103 — Use of Hard-Coded Cryptographic Key for Password Storage

Infor SyteLine ERP uses hard-coded static cryptographic keys to encrypt stored credentials, including user passwords, database connection strings, and API keys. The encryption keys are identical acro…

syteline_erp | Cryptography
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
9.8 CRITICAL
CVE-2026-2059 — SourceCodester Medical Center Portal Management System emp_edit1.php sql injection

A vulnerability has been found in SourceCodester Medical Center Portal Management System 1.0. Affected is an unknown function of the file /emp_edit1.php. Such manipulation of the argument ID leads to…

Feb 06, 2026 Feb 12, 2026
Feb 06, 2026
Feb 12, 2026
9.8 CRITICAL
CVE-2026-2058 — mathurvishal CloudClassroom-PHP-Project Post Query Details postquerypublic.php sql inject…

A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file /postquerypublic.php of the component Pos…

cloudclassroom-php-project | Remote | Injection
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
7.5 HIGH
CVE-2026-25556 — MuPDF <= 1.27.0 Barcode Decoding Double Free

MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_display_list() when an exception occurs during display list rendering. The function accepts a caller-ow…

mupdf | Remote | Memory Corruption
Feb 06, 2026 Feb 24, 2026
Feb 06, 2026
Feb 24, 2026
8.8 HIGH
CVE-2026-23741 — ast_coredumper running as root sources ast_debug_tools.conf from /etc/asterisk; potential…

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the asterisk/contrib/scripts/ast_coredumper runs as root,…

asterisk asterisk certified_asterisk | Remote | Authentication
Feb 06, 2026 Feb 18, 2026
Feb 06, 2026
Feb 18, 2026
7.8 HIGH
CVE-2026-23740 — Asterisk vulnerable to potential privilege escalation

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, when ast_coredumper writes its gdb init and output files …

asterisk asterisk certified_asterisk | Misconfiguration
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
6.5 MEDIUM
CVE-2026-23739 — Asterisk xml.c uses unsafe XML_PARSE_NOENT leading to potential XXE Injection

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the ast_xml_open() function in xml.c parses XML documents…

asterisk asterisk certified_asterisk | Remote | XML External Entity
Feb 06, 2026 Feb 18, 2026
Feb 06, 2026
Feb 18, 2026
6.1 MEDIUM
CVE-2026-23738 — The Asterisk embedded web server 's /httpstatus page echos user supplied values(cookie an…

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, user supplied/control values for Cookies and any GET vari…

asterisk asterisk certified_asterisk | Remote | Cross-Site Scripting
Feb 06, 2026 Feb 18, 2026
Feb 06, 2026
Feb 18, 2026
9.8 CRITICAL
CVE-2025-64111 — Gogs's update .git/config file allows remote command execution

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, due to the insufficient patch for CVE-2024-56731, it's still possible to update files in the .git directory and achieve re…

gogs | Remote | Injection
Feb 06, 2026 Feb 18, 2026
Feb 06, 2026
Feb 18, 2026
8.5 HIGH
CVE-2019-25305 — JumpStart 0.6.0.0 - 'jswpbapi' Unquoted Service Path

JumpStart 0.6.0.0 contains an unquoted service path vulnerability in the jswpbapi service running with LocalSystem privileges. Attackers can exploit the unquoted path containing spaces to inject and …

jumpstart | Misconfiguration
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
8.5 HIGH
CVE-2019-25304 — Intelligent Security System SecurOS Enterprise 10.2 - 'SecurosCtrlService' Unquoted Servi…

SecurOS Enterprise 10.2 contains an unquoted service path vulnerability in the SecurosCtrlService that allows local users to potentially execute code with elevated privileges. Attackers can exploit t…

| Misconfiguration
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
7.1 HIGH
CVE-2019-25303 — TheJshen contentManagementSystem 1.04 - 'id' SQL Injection

TheJshen ContentManagementSystem 1.04 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'id' GET parameter. Attackers can exploit boolean-based, …

Remote | Injection
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
8.5 HIGH
CVE-2019-25302 — Acer Launch Manager 6.1.7600.16385 - 'DsiWMIService' Unquoted Service Path

Acer Launch Manager 6.1.7600.16385 contains an unquoted service path vulnerability in the DsiWMIService that allows local users to potentially execute code with elevated privileges. Attackers can exp…

| Misconfiguration
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
6.4 MEDIUM
CVE-2019-25301 — thrsrossi Millhouse-Project 1.414 - 'content' Persistent Cross-Site Scripting

Millhouse-Project 1.414 contains a persistent cross-site scripting vulnerability in the comment submission functionality that allows attackers to inject malicious scripts. Attackers can post comments…

Remote | Cross-Site Scripting
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
7.1 HIGH
CVE-2019-25300 — thejshen Globitek CMS 1.4 - 'id' SQL Injection

thejshen Globitek CMS 1.4 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'id' GET parameter. Attackers can exploit boolean-based, time-based, …

Remote | Injection
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
Showing 20 of 5125 Results