Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.7 MEDIUM
CVE-2026-20137 — Risky Commands Safeguards Bypass through preloaded Data Models due to Path Traversal vuln…

In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.5, 9.3.7, and 9.2.9, and Splunk Cloud Platform versions below 10.1.2507.0, 10.0.2503.9, 9.3.2411.112, and 9.3.2408.122, a low-privileged user w…

splunk splunk_cloud_platform | Remote | Injection
Feb 18, 2026 Feb 20, 2026
Feb 18, 2026
Feb 20, 2026
9.8 CRITICAL
CVE-2025-70152 — Code-Projects Community Project Scholars Tracking System SQL Injection Vulnerability

code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php. These endpoints lac…

scholars_tracking_system | Remote | Injection
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
8.8 HIGH
CVE-2025-70151 — Code-Projects Scholars Tracking System Remote Code Execution Vulnerability

code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload. The endpoints update_profile_picture.php and upload_picture.…

scholars_tracking_system | Remote | Authentication
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
9.8 CRITICAL
CVE-2025-70150 — CodeAstro Membership Management System Unauthenticated Delete Member Vulnerability

CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id pa…

membership_management_system | Remote | Authentication
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
7.5 HIGH
CVE-2025-70148 — CodeAstro Membership Management System IDOR

Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users …

membership_management_system | Remote | Authentication
Feb 18, 2026 Feb 20, 2026
Feb 18, 2026
Feb 20, 2026
10.0 CRITICAL
CVE-2025-14009 — Zip Slip Vulnerability in nltk/nltk Leading to Remote Code Execution

A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py uses zipfile.extractall() without performing path…

nltk | Remote | Path Traversal
Feb 18, 2026 Mar 06, 2026
Feb 18, 2026
Mar 06, 2026
5.5 MEDIUM
CVE-2026-2657 — wren-lang wren Error Message wren_compiler.c printError stack-based overflow

A vulnerability has been found in wren-lang wren up to 0.4.0. This impacts the function printError of the file src/vm/wren_compiler.c of the component Error Message Handler. Such manipulation leads t…

wren | Memory Corruption
Feb 18, 2026 Feb 20, 2026
Feb 18, 2026
Feb 20, 2026
8.7 HIGH
CVE-2026-2507 — BIG-IP TMM Vulnerability

When BIG-IP AFM or BIG-IP DDoS is provisioned, undisclosed traffic can cause TMM to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

big-ip_access_policy_manager | Remote | Denial of Service
Feb 18, 2026 Feb 18, 2026
Feb 18, 2026
Feb 18, 2026
4.3 MEDIUM
CVE-2026-2230 — Booking Calendar <= 10.14.14 - Insecure Direct Object Reference to Authenticated (Subscri…

The Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 10.14.14 via the handle_ajax_save function due to missing validation …

booking_calendar | Remote | Authorization
Feb 18, 2026 Feb 18, 2026
Feb 18, 2026
Feb 18, 2026
9.8 CRITICAL
CVE-2025-70149 — CodeAstro Membership Management System SQL Injection Vulnerability

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.

membership_management_system | Remote | Injection
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
7.5 HIGH
CVE-2025-70147 — ProjectWorlds Online Time Table Generator Authentication Bypass

Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to obtain sensitive information (including plaintext passw…

online_time_table_generator | Remote | Authentication
Feb 18, 2026 Feb 20, 2026
Feb 18, 2026
Feb 20, 2026
9.1 CRITICAL
CVE-2025-70146 — ProjectWorlds Online Time Table Generator Authentication Bypass Vulnerability

Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized administrative operatio…

online_time_table_generator | Remote | Authentication
Feb 18, 2026 Feb 20, 2026
Feb 18, 2026
Feb 20, 2026
9.4 CRITICAL
CVE-2025-70141 — SourceCodester Customer Support System Unauthenticated Access Control Bypass

SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authentication or authorization before invoking adminis…

customer_support_system | Remote | Authorization
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
0.0 NA
CVE-2026-23230 — smb: client: split cached_fid bitfields to avoid shared-byte RMW races

In the Linux kernel, the following vulnerability has been resolved: smb: client: split cached_fid bitfields to avoid shared-byte RMW races is_open, has_lease and on_list are stored in the same bitf…

linux_kernel | Race Condition
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
0.0 NA
CVE-2026-23229 — crypto: virtio - Add spinlock protection with virtqueue notification

In the Linux kernel, the following vulnerability has been resolved: crypto: virtio - Add spinlock protection with virtqueue notification When VM boots with one virtio-crypto PCI device and builtin …

linux_kernel | Race Condition
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
0.0 NA
CVE-2026-23228 — smb: server: fix leak of active_num_conn in ksmbd_tcp_new_connection()

In the Linux kernel, the following vulnerability has been resolved: smb: server: fix leak of active_num_conn in ksmbd_tcp_new_connection() On kthread_run() failure in ksmbd_tcp_new_connection(), th…

linux_kernel | Memory Corruption
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
0.0 NA
CVE-2026-23227 — drm/exynos: vidi: use ctx->lock to protect struct vidi_context member variables related t…

In the Linux kernel, the following vulnerability has been resolved: drm/exynos: vidi: use ctx->lock to protect struct vidi_context member variables related to memory alloc/free Exynos Virtual Displ…

linux_kernel | Memory Corruption
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
7.8 HIGH
CVE-2026-23226 — ksmbd: add chann_lock to protect ksmbd_chann_list xarray

In the Linux kernel, the following vulnerability has been resolved: ksmbd: add chann_lock to protect ksmbd_chann_list xarray ksmbd_chann_list xarray lacks synchronization, allowing use-after-free i…

linux_kernel | Race Condition
Feb 18, 2026 Mar 02, 2026
Feb 18, 2026
Mar 02, 2026
0.0 NA
CVE-2026-23225 — sched/mmcid: Don't assume CID is CPU owned on mode switch

In the Linux kernel, the following vulnerability has been resolved: sched/mmcid: Don't assume CID is CPU owned on mode switch Shinichiro reported a KASAN UAF, which is actually an out of bounds acc…

linux_kernel | Memory Corruption
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
0.0 NA
CVE-2026-23224 — erofs: fix UAF issue for file-backed mounts w/ directio option

In the Linux kernel, the following vulnerability has been resolved: erofs: fix UAF issue for file-backed mounts w/ directio option [ 9.269940][ T3222] Call trace: [ 9.269948][ T3222] ext4_fi…

linux_kernel | Race Condition
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
Showing 20 of 5217 Results