Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.1 MEDIUM
CVE-2025-15562 — Reflected Cross-Site Scripting in NesterSoft WorkTime

The server API endpoint /report/internet/urls reflects received data into the HTML response without applying proper encoding or filtering. This allows an attacker to execute arbitrary JavaScript in t…

worktime | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 26, 2026
Feb 19, 2026
Feb 26, 2026
7.8 HIGH
CVE-2025-15561 — Local Privilege Escalation in NesterSoft WorkTime

An attacker can exploit the update behavior of the WorkTime monitoring daemon to elevate privileges on the local system to NT Authority\SYSTEM. A malicious executable must be named  WTWatch.exe and d…

worktime | Authentication
Feb 19, 2026 Feb 26, 2026
Feb 19, 2026
Feb 26, 2026
8.8 HIGH
CVE-2025-15560 — SQL Injection in NesterSoft WorkTime

An authenticated attacker with minimal permissions can exploit a SQL injection in the WorkTime server "widget" API endpoint to inject SQL queries. If the Firebird backend is used, attackers are able …

worktime | Remote | Injection
Feb 19, 2026 Feb 26, 2026
Feb 19, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2025-15559 — Unauthenticated OS Command Injection in NesterSoft WorkTime

An unauthenticated attacker can inject OS commands when calling a server API endpoint in NesterSoft WorkTime. The server API call to generate and download the WorkTime client from the WorkTime server…

worktime | Remote | Injection
Feb 19, 2026 Mar 03, 2026
Feb 19, 2026
Mar 03, 2026
6.4 MEDIUM
CVE-2026-2718 — Dealia <= 1.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gutenberg …

The Dealia – Request a Quote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Gutenberg block attributes in all versions up to, and including, 1.0.6. This is due to the use of `w…

Remote | Cross-Site Scripting
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
4.4 MEDIUM
CVE-2026-2716 — Client Testimonial Slider <= 2.0 - Authenticated (Administrator+) Stored Cross-Site Scrip…

The Client Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Testimonial Heading' setting in all versions up to, and including, 2.0. This is due to insuffi…

Remote | Cross-Site Scripting
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
6.5 MEDIUM
CVE-2026-22268 — Dell PowerProtect Data Manager Privilege Escalation Denial of Service

Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with remote access could potentially exploit this vuln…

powerprotect_data_manager | Remote | Authorization
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
8.8 HIGH
CVE-2026-22267 — Dell PowerProtect Data Manager Privilege Escalation Vulnerability

Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with remote access could potentially exploit this vuln…

powerprotect_data_manager | Remote | Authorization
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
8.8 HIGH
CVE-2026-22266 — Dell PowerProtect Data Manager REST API Improper Verification of Source of a Communicatio…

Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Improper Verification of Source of a Communication Channel vulnerability in the REST API. A high privileged attacker with remo…

powerprotect_data_manager | Remote | Authentication
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
6.5 MEDIUM
CVE-2026-1461 — Simple Membership <= 4.7.0 - Unauthenticated Improper Handling of Missing Values

The Simple Membership plugin for WordPress is vulnerable to Improper Handling of Missing Values in all versions up to, and including, 4.7.0 via the Stripe webhook handler. This is due to the plugin o…

simple_membership | Remote | Authentication
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
5.3 MEDIUM
CVE-2026-1219 — MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar 4.0 - 5.10 - Unauthenti…

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 4.0 to 5.10 via the 'load_track_note_ajax' due…

mp3_audio_player_for_music\,_radio_\&_podcast | Remote | Information Disclosure
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
9.1 CRITICAL
CVE-2025-13590 — Authenticated arbitrary file upload via a System REST API requiring administrator permiss…

A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST API. Successful uploads may lead to remote code exe…

Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
10.0 CRITICAL
CVE-2025-12107 — Potential authenticated Server-Side Template Injection (SSTI) vulnerability.

Due to the use of a vulnerable third-party Velocity template engine, a malicious actor with admin privilege may inject and execute arbitrary template syntax within server-side templates. Successfu…

identity_server wso2_identity_server | Remote | Injection
Feb 19, 2026 Mar 06, 2026
Feb 19, 2026
Mar 06, 2026
6.1 MEDIUM
CVE-2026-2736 — Reflected Cross-Site Scripting (XSS) vulnerability in Alkacon's OpenCms

Reflected Cross-site Scripting (XSS) in Alkacon's OpenCms v18.0, which allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL containing the ‘q’ p…

opencms | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 23, 2026
Feb 19, 2026
Feb 23, 2026
5.4 MEDIUM
CVE-2026-2735 — Stored Cross-Site Scripting (XSS) vulnerability in Alkacon's OpenCms

Stored Cross-Site Scripting (XSS) in Alkacon's OpenCms v18.0, which occurs when user input is not properly validated when sending a POST request to ‘/blog/new-article/org.opencms.ugc.CmsUgcEditServic…

opencms | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 23, 2026
Feb 19, 2026
Feb 23, 2026
6.5 MEDIUM
CVE-2026-27094 — WordPress CoBlocks plugin <= 3.1.16 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GoDaddy CoBlocks coblocks allows Stored XSS.This issue affects CoBlocks: from n/a through <= 3.1.…

coblocks | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
6.5 MEDIUM
CVE-2026-27092 — WordPress WPAdverts plugin <= 2.2.11 - Broken Access Control vulnerability

Missing Authorization vulnerability in Greg Winiarski WPAdverts wpadverts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPAdverts: from n/a through <= 2.2…

Remote | Authorization
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
4.3 MEDIUM
CVE-2026-27090 — WordPress Kenta Companion plugin <= 1.3.3 - Cross Site Request Forgery (CSRF) vulnerabili…

Cross-Site Request Forgery (CSRF) vulnerability in WP Moose Kenta Companion kenta-companion allows Cross Site Request Forgery.This issue affects Kenta Companion: from n/a through <= 1.3.3.

Remote | Cross-Site Request Forgery
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
6.5 MEDIUM
CVE-2026-27074 — WordPress Shortcoder plugin <= 6.5.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vaakash Shortcoder shortcoder allows Stored XSS.This issue affects Shortcoder: from n/a through <…

Remote | Cross-Site Scripting
Feb 19, 2026 Feb 27, 2026
Feb 19, 2026
Feb 27, 2026
6.5 MEDIUM
CVE-2026-27069 — WordPress Soledad theme <= 8.7.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Soledad soledad allows DOM-Based XSS.This issue affects Soledad: from n/a through <= …

soledad | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
Showing 20 of 5329 Results