Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.8 HIGH
CVE-2026-23740 — Asterisk vulnerable to potential privilege escalation

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, when ast_coredumper writes its gdb init and output files …

asterisk asterisk certified_asterisk | Misconfiguration
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
6.5 MEDIUM
CVE-2026-23739 — Asterisk xml.c uses unsafe XML_PARSE_NOENT leading to potential XXE Injection

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the ast_xml_open() function in xml.c parses XML documents…

asterisk asterisk certified_asterisk | Remote | XML External Entity
Feb 06, 2026 Feb 18, 2026
Feb 06, 2026
Feb 18, 2026
6.1 MEDIUM
CVE-2026-23738 — The Asterisk embedded web server 's /httpstatus page echos user supplied values(cookie an…

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, user supplied/control values for Cookies and any GET vari…

asterisk asterisk certified_asterisk | Remote | Cross-Site Scripting
Feb 06, 2026 Feb 18, 2026
Feb 06, 2026
Feb 18, 2026
9.8 CRITICAL
CVE-2025-64111 — Gogs's update .git/config file allows remote command execution

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, due to the insufficient patch for CVE-2024-56731, it's still possible to update files in the .git directory and achieve re…

gogs | Remote | Injection
Feb 06, 2026 Feb 18, 2026
Feb 06, 2026
Feb 18, 2026
8.5 HIGH
CVE-2019-25305 — JumpStart 0.6.0.0 - 'jswpbapi' Unquoted Service Path

JumpStart 0.6.0.0 contains an unquoted service path vulnerability in the jswpbapi service running with LocalSystem privileges. Attackers can exploit the unquoted path containing spaces to inject and …

jumpstart | Misconfiguration
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
8.5 HIGH
CVE-2019-25304 — Intelligent Security System SecurOS Enterprise 10.2 - 'SecurosCtrlService' Unquoted Servi…

SecurOS Enterprise 10.2 contains an unquoted service path vulnerability in the SecurosCtrlService that allows local users to potentially execute code with elevated privileges. Attackers can exploit t…

| Misconfiguration
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
7.1 HIGH
CVE-2019-25303 — TheJshen contentManagementSystem 1.04 - 'id' SQL Injection

TheJshen ContentManagementSystem 1.04 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'id' GET parameter. Attackers can exploit boolean-based, …

Remote | Injection
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
8.5 HIGH
CVE-2019-25302 — Acer Launch Manager 6.1.7600.16385 - 'DsiWMIService' Unquoted Service Path

Acer Launch Manager 6.1.7600.16385 contains an unquoted service path vulnerability in the DsiWMIService that allows local users to potentially execute code with elevated privileges. Attackers can exp…

| Misconfiguration
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
6.4 MEDIUM
CVE-2019-25301 — thrsrossi Millhouse-Project 1.414 - 'content' Persistent Cross-Site Scripting

Millhouse-Project 1.414 contains a persistent cross-site scripting vulnerability in the comment submission functionality that allows attackers to inject malicious scripts. Attackers can post comments…

Remote | Cross-Site Scripting
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
7.1 HIGH
CVE-2019-25300 — thejshen Globitek CMS 1.4 - 'id' SQL Injection

thejshen Globitek CMS 1.4 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'id' GET parameter. Attackers can exploit boolean-based, time-based, …

Remote | Injection
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
7.1 HIGH
CVE-2019-25299 — rimbalinux AhadPOS 1.11 - 'alamatCustomer' SQL Injection

RimbaLinux AhadPOS 1.11 contains a SQL injection vulnerability in the 'alamatCustomer' parameter that allows attackers to manipulate database queries through crafted POST requests. Attackers can expl…

Remote | Injection
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
9.1 CRITICAL
CVE-2019-25298 — html5_snmp 1.11 - 'Router_ID' SQL Injection

html5_snmp 1.11 contains multiple SQL injection vulnerabilities that allow attackers to manipulate database queries through Router_ID and Router_IP parameters. Attackers can exploit error-based, time…

html5_snmp | Remote | Injection
Feb 06, 2026 Mar 02, 2026
Feb 06, 2026
Mar 02, 2026
6.4 MEDIUM
CVE-2019-25294 — html5_snmp 1.11 - 'Remark' Persistent Cross-Site Scripting

html5_snmp 1.11 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through the 'Remark' parameter in add_router_operation.php. Attackers can cr…

html5_snmp | Remote | Cross-Site Scripting
Feb 06, 2026 Mar 02, 2026
Feb 06, 2026
Mar 02, 2026
8.5 HIGH
CVE-2019-25293 — Blue Stacks App Player 2.4.44.62.57 - "BstHdLogRotatorSvc" Unquote Service Path

BlueStacks App Player 2.4.44.62.57 contains an unquoted service path vulnerability in the BstHdLogRotatorSvc service that allows local attackers to potentially execute arbitrary code. Attackers can e…

bluestacks | Misconfiguration
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
8.5 HIGH
CVE-2019-25292 — Alps HID Monitor Service 8.1.0.10 - 'ApHidMonitorService' Unquote Service Path

Alps HID Monitor Service 8.1.0.10 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the…

| Misconfiguration
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
8.5 HIGH
CVE-2019-25266 — Wondershare Application Framework Service 2.4.3.231 - 'WsAppService' Unquote Service Path

Wondershare Application Framework Service 2.4.3.231 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attacke…

| Misconfiguration
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
9.8 CRITICAL
CVE-2026-2057 — SourceCodester Medical Center Portal Management System login.php sql injection

A vulnerability was detected in SourceCodester Medical Center Portal Management System 1.0. This affects an unknown function of the file /login.php. The manipulation of the argument User results in s…

Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
7.7 HIGH
CVE-2025-13523 — Cross-Site Scripting (XSS) via Unescaped Display Names in Mattermost Confluence Plugin OA…

Mattermost Confluence plugin version <1.7.0 fails to properly escape user-controlled display names in HTML template rendering which allows authenticated Confluence users with malicious display names …

confluence | Remote | Cross-Site Scripting
Feb 06, 2026 Feb 24, 2026
Feb 06, 2026
Feb 24, 2026
7.5 HIGH
CVE-2026-2056 — D-Link DIR-605L/DIR-619L DHCP Connection Status wan_connection_status.asp information dis…

A security vulnerability has been detected in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. The impacted element is an unknown function of the file /wan_connection_status.asp of the component DHCP Co…

dir-605l_firmware dir-619l_firmware dir-605l dir-619l | Remote | Information Disclosure
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
5.4 MEDIUM
CVE-2026-1337 — Insufficient escaping of unicode characters in query log

Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that treats them as HTML. The…

neo4j | Remote | Cross-Site Scripting
Feb 06, 2026 Feb 24, 2026
Feb 06, 2026
Feb 24, 2026
Showing 20 of 5092 Results