Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-23604 — GFI MailEssentials AI < 22.4 Keyword Filtering Rule Stored XSS

GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Keyword Filtering rule creation workflow. An authenticated user can supply HTML/JavaScript in t…

mailessentials | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
7.5 HIGH
CVE-2026-2232 — Product Table and List Builder for WooCommerce Lite <= 4.6.2 - Unauthenticated Time-Based…

The Product Table and List Builder for WooCommerce Lite plugin for WordPress is vulnerable to time-based SQL Injection via the 'search' parameter in all versions up to, and including, 4.6.2 due to in…

Remote | Injection
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
8.7 HIGH
CVE-2026-26336 — Hyland Alfresco Improper Authorization Arbitrary File Read

Hyland Alfresco allows unauthenticated attackers to read arbitrary files from protected directories (like WEB-INF) via the "/share/page/resource/" endpoint, thus leading to the disclosure of sensitiv…

Feb 19, 2026 Mar 03, 2026
Feb 19, 2026
Mar 03, 2026
9.9 CRITICAL
CVE-2026-26030 — Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote c…

Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within the `InMemoryVectorStore` filter functionality. The…

semantic_kernel | Remote | Injection
Feb 19, 2026 Mar 03, 2026
Feb 19, 2026
Mar 03, 2026
9.2 CRITICAL
CVE-2026-26016 — Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missin…

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.1, a missing authorization check in multiple controllers allows any user wit…

panel wings | Remote | Authorization
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
8.7 HIGH
CVE-2026-25998 — strongMan vulnerable to private credential recovery due to key and counter reuse

strongMan is a management interface for strongSwan, an OpenSource IPsec-based VPN. When storing credentials in the database (private keys, EAP secrets), strongMan encrypts the corresponding database …

strongman | Remote | Cryptography
Feb 19, 2026 Feb 23, 2026
Feb 19, 2026
Feb 23, 2026
9.3 CRITICAL
CVE-2026-24834 — Kata Container to Guest micro VM privilege escalation

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 3.27.0, an issue in Kata with …

kata_containers | Authentication
Feb 19, 2026 Feb 23, 2026
Feb 19, 2026
Feb 23, 2026
7.5 HIGH
CVE-2026-1581 — wpForo Forum <= 2.4.14 - Unauthenticated Time-Based SQL Injection

The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all versions up to, and including, 2.4.14 due to insufficient escaping on the user supplie…

wpforo_forum | Remote | Injection
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
4.7 MEDIUM
CVE-2025-69725 — Chi Open Redirect Vulnerability

An Open Redirect vulnerability in the go-chi/chi >=5.2.2 RedirectSlashes function allows remote attackers to redirect victim users to malicious websites using the legitimate website domain.

Remote | Misconfiguration
Feb 19, 2026 Feb 23, 2026
Feb 19, 2026
Feb 23, 2026
9.8 CRITICAL
CVE-2025-69674 — CDATA FD614GS3-R850 Buffer Overflow Arbitrary Code Execution

Buffer Overflow vulnerability in CDATA FD614GS3-R850 V3.2.7_P161006 (Build.0333.250211) allows an attacker to execute arbitrary code via the node_mac, node_opt, opt_param, and domainblk parameters of…

Remote | Memory Corruption
Feb 19, 2026 Feb 25, 2026
Feb 19, 2026
Feb 25, 2026
8.5 HIGH
CVE-2026-2274 — Arbitrary File Read and SSRF in Google AppSheet

A SSRF and Arbitrary File Read vulnerability in AppSheet Core in Google AppSheet prior to 2025-11-23 allows an authenticated remote attacker to read sensitive local files and access internal network …

Remote | Server-Side Request Forgery
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
8.6 HIGH
CVE-2026-26345 — SPIP < 4.4.8 Cross-Site Scripting in Public Area

SPIP before 4.4.8 contains a stored cross-site scripting (XSS) vulnerability in the public area triggered in certain edge-case usage patterns. The echapper_html_suspect() function does not adequately…

spip | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 24, 2026
Feb 19, 2026
Feb 24, 2026
6.1 MEDIUM
CVE-2026-26223 — SPIP < 4.4.8 Cross-Site Scripting via Iframe Tags in Private Area

SPIP before 4.4.8 allows cross-site scripting (XSS) in the private area via malicious iframe tags. The application does not properly sandbox or escape iframe content in the back-office, allowing an a…

spip | Remote | Cross-Site Scripting
Feb 19, 2026 Mar 02, 2026
Feb 19, 2026
Mar 02, 2026
8.1 HIGH
CVE-2026-25940 — jsPDF's PDF Injection in AcroForm module allows Arbitrary JavaScript Execution (RadioButt…

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actio…

jspdf | Remote | Injection
Feb 19, 2026 Feb 23, 2026
Feb 19, 2026
Feb 23, 2026
5.3 MEDIUM
CVE-2026-25766 — Echo has a Windows path traversal via backslash in middleware.Static default filesystem

Echo is a Go web framework. In versions 5.0.0 through 5.0.2 on Windows, Echo’s `middleware.Static` using the default filesystem allows path traversal via backslashes, enabling unauthenticated remote …

windows echo | Remote | Path Traversal
Feb 19, 2026 Feb 23, 2026
Feb 19, 2026
Feb 23, 2026
5.4 MEDIUM
CVE-2026-25739 — Indico affected by Cross-Site-Scripting via material uploads

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Versions prior to 3.3.10 are vulnerable to cross-site scripting when uploading certain…

indico | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 26, 2026
Feb 19, 2026
Feb 26, 2026
6.9 MEDIUM
CVE-2026-25738 — Indico has Server-Side Request Forgery (SSRF) in multiple places

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Versions prior to 3.3.10 are vulnerable to server-side request forgery. Indico makes o…

indico | Remote | Server-Side Request Forgery
Feb 19, 2026 Feb 26, 2026
Feb 19, 2026
Feb 26, 2026
6.1 MEDIUM
CVE-2025-71244 — SPIP < 4.4.5 Open Redirect via Login Form

SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a malicious URL that, when visited by a victim, redirects them to an arbitrary ext…

spip | Remote | Misconfiguration
Feb 19, 2026 Feb 24, 2026
Feb 19, 2026
Feb 24, 2026
9.8 CRITICAL
CVE-2025-71243 — SPIP Saisies Plugin < 5.11.1 Remote Code Execution

The 'Saisies pour formulaire' (Saisies) plugin for SPIP versions 5.4.0 through 5.11.0 contains a critical Remote Code Execution (RCE) vulnerability. An attacker can exploit this vulnerability to exec…

saisies_pour_formulaire saisies | Remote | Injection
Feb 19, 2026 Feb 26, 2026
Feb 19, 2026
Feb 26, 2026
6.5 MEDIUM
CVE-2025-71242 — SPIP < 4.3.6 Authorization Bypass Leading to Content Disclosure

SPIP before 4.3.6, 4.2.17, and 4.1.20 allows unauthorized content disclosure in the private area. The application does not properly check authorization when displaying content of articles and section…

spip | Remote | Authorization
Feb 19, 2026 Mar 02, 2026
Feb 19, 2026
Mar 02, 2026
Showing 20 of 5272 Results