Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-25922 — authentik has a Signature Verification Bypass via SAML Assertion Wrapping

authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Assertion Signature under Verification Certificate enab…

authentik | Remote | Authentication
Feb 12, 2026 Feb 18, 2026
Feb 12, 2026
Feb 18, 2026
7.1 HIGH
CVE-2026-25768 — LavinMQ is missing vhost access control

LavinMQ is a high-performance message queue & streaming server. Before 2.6.6, an authenticated user could access metadata in the broker they should not have access to. This vulnerability is fixed in …

lavinmq | Remote | Authorization
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
8.6 HIGH
CVE-2026-25767 — LavinMQ has incomplete shovel configuration validation

LavinMQ is a high-performance message queue & streaming server. Before 2.6.8, an authenticated user, with the “Policymaker” tag, could create shovels bypassing access controls. an authenticated user …

lavinmq | Remote | Authorization
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
8.6 HIGH
CVE-2026-25748 — authentik has a forward authentication bypass with broken cookie

authentik is an open-source identity provider. Prior to 2025.10.4 and 2025.12.4, with a malformed cookie it was possible to bypass authentication when using forward authentication in the authentik Pr…

authentik | Remote | Authentication
Feb 12, 2026 Feb 19, 2026
Feb 12, 2026
Feb 19, 2026
9.1 CRITICAL
CVE-2026-25227 — authentik affected by Remote Code Execution via Context Key Injection in PropertyMapping …

authentik is an open-source identity provider. From 2021.3.1 to before 2025.8.6, 2025.10.4, and 2025.12.4, when using delegated permissions, a User that has the permission Can view * Property Mapping…

authentik | Remote | Authorization
Feb 12, 2026 Feb 19, 2026
Feb 12, 2026
Feb 19, 2026
9.8 CRITICAL
CVE-2026-24895 — FrankenPHP affected by Path Confusion via Unicode casing in CGI path splitting allows exe…

FrankenPHP is a modern application server for PHP. Prior to 1.11.2, FrankenPHP’s CGI path splitting logic improperly handles Unicode characters during case conversion. The logic computes the split in…

frankenphp | Remote | Path Traversal
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
8.7 HIGH
CVE-2026-24894 — FrankenPHP leaks session data between requests in worker mode

FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSION superglobal is not correctly reset between requests. This allows a subsequent…

frankenphp | Remote | Information Disclosure
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
9.2 CRITICAL
CVE-2026-24044 — ESS Community Helm Chart has a weak server key generation method

Element Server Suite Community Edition (ESS Community) deploys a Matrix stack using the provided Helm charts and Kubernetes distribution. The ESS Community Helm Chart secrets initialization hook (usi…

Remote | Cryptography
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
9.8 CRITICAL
CVE-2025-70314 — Webfsd Buffer Overflow Vulnerability

webfsd 1.21 is vulnerable to a Buffer Overflow via a crafted request. This is due to the filename variable

webfsd | Remote | Memory Corruption
Feb 12, 2026 Feb 18, 2026
Feb 12, 2026
Feb 18, 2026
7.5 HIGH
CVE-2025-67433 — Open TFTP Server MultiThreaded Heap Buffer Overflow

A heap buffer overflow in the processRequest function of Open TFTP Server MultiThreaded v1.7 allows attackers to cause a Denial of Service (DoS) via a crafted DATA packet.

Remote | Memory Corruption
Feb 12, 2026 Feb 26, 2026
Feb 12, 2026
Feb 26, 2026
7.5 HIGH
CVE-2025-67432 — Monkeybread Software MBS DynaPDF Plugin Stack Overflow DoS

A stack overflow in the ZBarcode_Encode function of Monkeybread Software MBS DynaPDF Plugin v21.3.1.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

Remote | Memory Corruption
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
7.5 HIGH
CVE-2019-25347 — thesystem App 1.0 - 'username' SQL Injection

thesystem App 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating the username parameter. Attackers can inject malicious SQL code like ' or '1=1 …

password_management_application | Remote | Injection
Feb 12, 2026 Mar 02, 2026
Feb 12, 2026
Mar 02, 2026
7.5 HIGH
CVE-2019-25346 — thesystem 1.0 - 'server_name' SQL Injection

TheSystem 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating the 'server_name' parameter. Attackers can inject malicious SQL code like ' or '1=1…

password_management_application | Remote | Injection
Feb 12, 2026 Mar 02, 2026
Feb 12, 2026
Mar 02, 2026
8.5 HIGH
CVE-2019-25345 — RTK IIS Codec Service 6.4.10041.133 - 'RtkI2SCodec' Unquote Service Path

Realtek IIS Codec Service 6.4.10041.133 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in t…

| Misconfiguration
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
8.5 HIGH
CVE-2019-25344 — MobileGo 8.5.0 - Insecure File Permissions

Wondershare MobileGo 8.5.0 contains an insecure file permissions vulnerability that allows local users to modify executable files in the application directory. Attackers can replace the original Mobi…

mobiletrans mobilego | Misconfiguration
Feb 12, 2026 Feb 26, 2026
Feb 12, 2026
Feb 26, 2026
8.5 HIGH
CVE-2019-25343 — NextVPN 4.10 - Insecure File Permissions

NextVPN 4.10 contains an insecure file permissions vulnerability that allows local users to modify executable files with full access rights. Attackers can replace system executables with malicious fi…

| Misconfiguration
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
9.3 CRITICAL
CVE-2026-26219 — newbee-mall Unsalted MD5 Password Hashing Enables Offline Credential Cracking

newbee-mall stores and verifies user passwords using an unsalted MD5 hashing algorithm. The implementation does not incorporate per-user salts or computational cost controls, enabling attackers who o…

newbee-mall | Remote | Cryptography
Feb 12, 2026 Feb 25, 2026
Feb 12, 2026
Feb 25, 2026
9.8 CRITICAL
CVE-2026-26218 — newbee-mall Default Seeded Administrator Credentials Allow Account Takeover

newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisioned with a predictable default password. Deployments that initialize or reset …

newbee-mall | Remote | Authentication
Feb 12, 2026 Feb 25, 2026
Feb 12, 2026
Feb 25, 2026
6.5 MEDIUM
CVE-2026-22821 — mreporting affected by a SQLI on date change

mreporting is the more reporting GLPI plugin. Prior to 1.9.4, there is a possible SQL injection on date change. This vulnerability is fixed in 1.9.4.

more_reporting | Remote | Injection
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
5.3 MEDIUM
CVE-2026-21438 — webtransport-go affected by a Memory Exhaustion Attack due to Missing Cleanup of Streams …

webtransport-go is an implementation of the WebTransport protocol. Prior to 0.10.0, an attacker can cause unbounded memory consumption repeatedly creating and closing many WebTransport streams. Close…

webtransport-go | Remote | Denial of Service
Feb 12, 2026 Feb 19, 2026
Feb 12, 2026
Feb 19, 2026
Showing 20 of 5064 Results