Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-1228 — Timeline Block <= 1.3.3 - Insecure Direct Object Reference to Authenticated (Author+) Pri…

The Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inclu…

Remote | Information Disclosure
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
7.5 HIGH
CVE-2026-1974 — Free5GC SMF datapath.go ResolveNodeIdToIp denial of service

A vulnerability was identified in Free5GC up to 4.1.0. This affects the function ResolveNodeIdToIp of the file internal/sbi/processor/datapath.go of the component SMF. The manipulation leads to denia…

free5gc | Remote | Denial of Service
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
7.5 HIGH
CVE-2026-1973 — Free5GC SMF establishPfcpSession null pointer dereference

A vulnerability was determined in Free5GC up to 4.1.0. The impacted element is the function establishPfcpSession of the component SMF. Executing a manipulation can lead to null pointer dereference. T…

free5gc | Remote | Memory Corruption
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
7.5 HIGH
CVE-2026-1972 — Edimax BR-6208AC auth_check_userpass2 default credentials

A vulnerability was found in Edimax BR-6208AC 2_1.02. The affected element is the function auth_check_userpass2. Performing a manipulation of the argument Username/Password results in use of default …

br-6208ac_firmware br-6208ac | Remote | Authentication
Feb 06, 2026 Feb 20, 2026
Feb 06, 2026
Feb 20, 2026
4.8 MEDIUM
CVE-2026-1971 — Edimax BR-6288ACL wiz_WISP24gmanual.asp wiz_WISP24gmanual cross site scripting

A vulnerability has been found in Edimax BR-6288ACL up to 1.12. Impacted is the function wiz_WISP24gmanual of the file wiz_WISP24gmanual.asp. Such manipulation of the argument manualssid leads to cro…

br-6288acl_firmware br-6288acl | Remote | Cross-Site Scripting
Feb 06, 2026 Feb 20, 2026
Feb 06, 2026
Feb 20, 2026
5.3 MEDIUM
CVE-2026-23623 — Collabora Online vulnerable to Authorization Bypass

Collabora Online is a collaborative online office suite based on LibreOffice technology. Prior to Collabora Online Development Edition version 25.04.08.2 and prior to Collabora Online versions 23.05.…

online | Remote | Authorization
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
9.8 CRITICAL
CVE-2026-24302 — Azure Arc Elevation of Privilege Vulnerability

Azure Arc Elevation of Privilege Vulnerability

azure_arc | Remote
Feb 05, 2026 Feb 12, 2026
Feb 05, 2026
Feb 12, 2026
9.8 CRITICAL
CVE-2026-24300 — Azure Front Door Elevation of Privilege Vulnerability

Azure Front Door Elevation of Privilege Vulnerability

Feb 05, 2026 Feb 12, 2026
Feb 05, 2026
Feb 12, 2026
8.2 HIGH
CVE-2026-21532 — Azure Function Information Disclosure Vulnerability

Azure Function Information Disclosure Vulnerability

Feb 05, 2026 Feb 12, 2026
Feb 05, 2026
Feb 12, 2026
6.5 MEDIUM
CVE-2026-0391 — Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability

User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.

Feb 05, 2026 Feb 18, 2026
Feb 05, 2026
Feb 18, 2026
3.7 LOW
CVE-2025-68458 — webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-ti…

Webpack is a module bundler. From version 5.49.0 to before 5.104.1, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) can be bypassed to fetch resources from hosts out…

webpack | Remote | Server-Side Request Forgery
Feb 05, 2026 Feb 13, 2026
Feb 05, 2026
Feb 13, 2026
3.7 LOW
CVE-2025-68157 — webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects

Webpack is a module bundler. From version 5.49.0 to before 5.104.0, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) enforces allowedUris only for the initial URL, bu…

webpack | Remote | Server-Side Request Forgery
Feb 05, 2026 Feb 13, 2026
Feb 05, 2026
Feb 13, 2026
8.7 HIGH
CVE-2025-32393 — AutoGPT has a DoS vulnerability in ReadRSSFeedBlock

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6.32, there is a DoS…

autogpt_platform | Remote | Denial of Service
Feb 05, 2026 Feb 17, 2026
Feb 05, 2026
Feb 17, 2026
3.2 LOW
CVE-2026-25815 — Fortinet FortiOS LDAP Credentials Decryption Vulnerability

Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exploited in the wild from 2025-12-16 through 2026 (by default, the encryption key…

fortios | Cryptography
Feb 05, 2026 Feb 06, 2026
Feb 05, 2026
Feb 06, 2026
6.1 MEDIUM
CVE-2026-1970 — Edimax BR-6258n formStaDrvSetup redirect

A flaw has been found in Edimax BR-6258n up to 1.18. This issue affects the function formStaDrvSetup of the file /goform/formStaDrvSetup. This manipulation of the argument submit-url causes open redi…

br-6258n_firmware br-6258n | Remote | Information Disclosure
Feb 05, 2026 Feb 20, 2026
Feb 05, 2026
Feb 20, 2026
5.3 MEDIUM
CVE-2026-1964 — WeKan REST Endpoint boards.js BoardTitleRESTBleed access control

A vulnerability was determined in WeKan up to 8.20. This impacts an unknown function of the file models/boards.js of the component REST Endpoint. This manipulation causes improper access controls. Re…

wekan | Remote | Authorization
Feb 05, 2026 Feb 12, 2026
Feb 05, 2026
Feb 12, 2026
9.8 CRITICAL
CVE-2026-1963 — WeKan Attachment Storage attachments.js MoveStorageBleed access control

A vulnerability was found in WeKan up to 8.20. This affects an unknown function of the file models/attachments.js of the component Attachment Storage. The manipulation results in improper access cont…

wekan | Remote | Authorization
Feb 05, 2026 Mar 06, 2026
Feb 05, 2026
Mar 06, 2026
9.8 CRITICAL
CVE-2026-1962 — WeKan Attachment Migration attachmentMigration.js AttachmentMigrationBleed access control

A vulnerability has been found in WeKan up to 8.20. The impacted element is an unknown function of the file server/attachmentMigration.js of the component Attachment Migration. The manipulation leads…

wekan | Remote | Authorization
Feb 05, 2026 Feb 12, 2026
Feb 05, 2026
Feb 12, 2026
9.3 CRITICAL
CVE-2026-0106 — "VPU MMAP Privilege Escalation Vulnerability"

In vpu_mmap of vpu_ioctl, there is a possible arbitrary address mmap due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. Us…

android | Memory Corruption
Feb 05, 2026 Feb 19, 2026
Feb 05, 2026
Feb 19, 2026
6.5 MEDIUM
CVE-2025-12131 — Truncated 802.15.4 packet leads to denial of service

A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service.

Feb 05, 2026 Feb 12, 2026
Feb 05, 2026
Feb 12, 2026
Showing 20 of 5134 Results