Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.5 MEDIUM
CVE-2026-1979 — mruby JMPNOT-to-JMPIF Optimization vm.c mrb_vm_exec use after free

A flaw has been found in mruby up to 3.4.0. This affects the function mrb_vm_exec of the file src/vm.c of the component JMPNOT-to-JMPIF Optimization. Executing a manipulation can lead to use after fr…

mruby | Memory Corruption
Feb 06, 2026 Feb 28, 2026
Feb 06, 2026
Feb 28, 2026
7.5 HIGH
CVE-2026-1978 — kalyan02 NanoCMS User Information pagesdata.txt direct request

A vulnerability was detected in kalyan02 NanoCMS up to 0.4. Affected by this issue is some unknown functionality of the file /data/pagesdata.txt of the component User Information Handler. Performing …

nanocms | Remote | Misconfiguration
Feb 06, 2026 Feb 27, 2026
Feb 06, 2026
Feb 27, 2026
6.5 MEDIUM
CVE-2026-1977 — isaacwasserman mcp-vegalite-server visualize_data eval code injection

A security vulnerability has been detected in isaacwasserman mcp-vegalite-server up to 16aefed598b8cd897b78e99b907f6e2984572c61. Affected by this vulnerability is the function eval of the component v…

Remote | Injection
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
8.8 HIGH
CVE-2025-15566 — ingress-nginx auth-proxy-set-headers nginx configuration injection

A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-proxy-set-headers` Ingress annotation can be used to inject configuration into nginx. This can lead to arb…

ingress-nginx | Remote | Injection
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
7.5 HIGH
CVE-2026-1976 — Free5GC SMF SessionDeletionResponse null pointer dereference

A weakness has been identified in Free5GC up to 4.1.0. Affected is the function SessionDeletionResponse of the component SMF. This manipulation causes null pointer dereference. The attack is possible…

free5gc | Remote | Memory Corruption
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
7.5 HIGH
CVE-2026-1975 — Free5GC pfcp_reports.go identityTriggerType null pointer dereference

A security flaw has been discovered in Free5GC up to 4.1.0. This impacts the function identityTriggerType of the file pfcp_reports.go. The manipulation results in null pointer dereference. The attack…

free5gc | Remote | Memory Corruption
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
4.3 MEDIUM
CVE-2026-1228 — Timeline Block <= 1.3.3 - Insecure Direct Object Reference to Authenticated (Author+) Pri…

The Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inclu…

Remote | Information Disclosure
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
7.5 HIGH
CVE-2026-1974 — Free5GC SMF datapath.go ResolveNodeIdToIp denial of service

A vulnerability was identified in Free5GC up to 4.1.0. This affects the function ResolveNodeIdToIp of the file internal/sbi/processor/datapath.go of the component SMF. The manipulation leads to denia…

free5gc | Remote | Denial of Service
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
7.5 HIGH
CVE-2026-1973 — Free5GC SMF establishPfcpSession null pointer dereference

A vulnerability was determined in Free5GC up to 4.1.0. The impacted element is the function establishPfcpSession of the component SMF. Executing a manipulation can lead to null pointer dereference. T…

free5gc | Remote | Memory Corruption
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
7.5 HIGH
CVE-2026-1972 — Edimax BR-6208AC auth_check_userpass2 default credentials

A vulnerability was found in Edimax BR-6208AC 2_1.02. The affected element is the function auth_check_userpass2. Performing a manipulation of the argument Username/Password results in use of default …

br-6208ac_firmware br-6208ac | Remote | Authentication
Feb 06, 2026 Feb 20, 2026
Feb 06, 2026
Feb 20, 2026
4.8 MEDIUM
CVE-2026-1971 — Edimax BR-6288ACL wiz_WISP24gmanual.asp wiz_WISP24gmanual cross site scripting

A vulnerability has been found in Edimax BR-6288ACL up to 1.12. Impacted is the function wiz_WISP24gmanual of the file wiz_WISP24gmanual.asp. Such manipulation of the argument manualssid leads to cro…

br-6288acl_firmware br-6288acl | Remote | Cross-Site Scripting
Feb 06, 2026 Feb 20, 2026
Feb 06, 2026
Feb 20, 2026
5.3 MEDIUM
CVE-2026-23623 — Collabora Online vulnerable to Authorization Bypass

Collabora Online is a collaborative online office suite based on LibreOffice technology. Prior to Collabora Online Development Edition version 25.04.08.2 and prior to Collabora Online versions 23.05.…

online | Remote | Authorization
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
9.8 CRITICAL
CVE-2026-24302 — Azure Arc Elevation of Privilege Vulnerability

Azure Arc Elevation of Privilege Vulnerability

azure_arc | Remote
Feb 05, 2026 Feb 12, 2026
Feb 05, 2026
Feb 12, 2026
9.8 CRITICAL
CVE-2026-24300 — Azure Front Door Elevation of Privilege Vulnerability

Azure Front Door Elevation of Privilege Vulnerability

Feb 05, 2026 Feb 12, 2026
Feb 05, 2026
Feb 12, 2026
8.2 HIGH
CVE-2026-21532 — Azure Function Information Disclosure Vulnerability

Azure Function Information Disclosure Vulnerability

Feb 05, 2026 Feb 12, 2026
Feb 05, 2026
Feb 12, 2026
6.5 MEDIUM
CVE-2026-0391 — Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability

User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.

Feb 05, 2026 Feb 18, 2026
Feb 05, 2026
Feb 18, 2026
3.7 LOW
CVE-2025-68458 — webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-ti…

Webpack is a module bundler. From version 5.49.0 to before 5.104.1, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) can be bypassed to fetch resources from hosts out…

webpack | Remote | Server-Side Request Forgery
Feb 05, 2026 Feb 13, 2026
Feb 05, 2026
Feb 13, 2026
3.7 LOW
CVE-2025-68157 — webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects

Webpack is a module bundler. From version 5.49.0 to before 5.104.0, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) enforces allowedUris only for the initial URL, bu…

webpack | Remote | Server-Side Request Forgery
Feb 05, 2026 Feb 13, 2026
Feb 05, 2026
Feb 13, 2026
8.7 HIGH
CVE-2025-32393 — AutoGPT has a DoS vulnerability in ReadRSSFeedBlock

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6.32, there is a DoS…

autogpt_platform | Remote | Denial of Service
Feb 05, 2026 Feb 17, 2026
Feb 05, 2026
Feb 17, 2026
3.2 LOW
CVE-2026-25815 — Fortinet FortiOS LDAP Credentials Decryption Vulnerability

Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exploited in the wild from 2025-12-16 through 2026 (by default, the encryption key…

fortios | Cryptography
Feb 05, 2026 Feb 06, 2026
Feb 05, 2026
Feb 06, 2026
Showing 20 of 5125 Results