Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.2 CRITICAL
CVE-2026-21626 — Extension - stackideas.com - Information disclosure in post custom fields in EasyDiscuss …

Access control settings for forum post custom fields are not applied to the JSON output type, leading to an ACL violation vector an information disclosure

easydiscuss | Remote | Information Disclosure
Feb 06, 2026 Feb 18, 2026
Feb 06, 2026
Feb 18, 2026
6.4 MEDIUM
CVE-2026-1279 — Employee Directory <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting vi…

The Employee Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_title' parameter in the `search_employee_directory` shortcode in all versions up to, and includi…

Remote | Cross-Site Scripting
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
8.8 HIGH
CVE-2026-2008 — abhiphile fermat-mcp eqn_chart.py eqn_chart code injection

A vulnerability was detected in abhiphile fermat-mcp up to 47f11def1cd37e45dd060f30cdce346cbdbd6f0a. This vulnerability affects the function eqn_chart of the file fmcp/mpl_mcp/core/eqn_chart.py. Perf…

fermat | Remote | Injection
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
7.2 HIGH
CVE-2026-2000 — DCN DCME-320 Web Management Backend bridge_cfg.php apply_config command injection

A vulnerability was found in DCN DCME-320 up to 20260121. Impacted is the function apply_config of the file /function/system/basic/bridge_cfg.php of the component Web Management Backend. Performing a…

dcme-320_firmware dcme-320 | Remote | Injection
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
5.5 MEDIUM
CVE-2026-1998 — micropython runtime.c mp_import_all memory corruption

A flaw has been found in micropython up to 1.27.0. This vulnerability affects the function mp_import_all of the file py/runtime.c. This manipulation causes memory corruption. The attack needs to be l…

micropython | Memory Corruption
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
6.4 MEDIUM
CVE-2026-1909 — WaveSurfer-WP <= 2.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sr…

The WaveSurfer-WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's audio shortcode in all versions up to, and including, 2.8.3 due to insufficient input sanitization…

Remote | Cross-Site Scripting
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
6.4 MEDIUM
CVE-2026-1888 — Docus <= 1.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode A…

The Docus – YouTube Video Playlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'docusplaylist' shortcode in all versions up to, and including, 1.0.6 due to insufficient …

Remote | Cross-Site Scripting
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
6.4 MEDIUM
CVE-2026-1808 — Orange Confort+ accessibility toolbar for WordPress <= 0.7 - Authenticated (Contributor+)…

The Orange Confort+ accessibility toolbar for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' parameter of the ocplus_button shortcode in all versions up t…

Remote | Cross-Site Scripting
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
6.4 MEDIUM
CVE-2026-1401 — Tune Library <= 1.6.3 - Missing Authorization to Authenticated (Subscriber+) Stored Cross…

The Tune Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via CSV import in all versions up to, and including, 1.6.3. This is due to insufficient input sanitization and outpu…

tune_library | Remote | Cross-Site Scripting
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
6.1 MEDIUM
CVE-2026-0521 — Reflected Cross-Site Scripting in PDF Export Error Message

A reflected cross-site scripting (XSS) vulnerability in the PDF export functionality of the TYDAC AG MAP+ solution allows unauthenticated attackers to craft a malicious URL, that if visited by a vict…

map\+ | Remote | Cross-Site Scripting
Feb 06, 2026 Feb 18, 2026
Feb 06, 2026
Feb 18, 2026
5.3 MEDIUM
CVE-2025-10753 — OAuth Single Sign On – SSO (OAuth Client) <= 6.26.14 - Missing Authorization

The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 6.26.14. This is due to missing capability checks and aut…

oauth_single_sign_on | Remote | Authentication
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
5.5 MEDIUM
CVE-2026-1991 — libuvc UVC Descriptor device.c uvc_scan_streaming null pointer dereference

A vulnerability was detected in libuvc up to 0.0.7. Affected is the function uvc_scan_streaming of the file src/device.c of the component UVC Descriptor Handler. The manipulation results in null poin…

libuvc | Memory Corruption
Feb 06, 2026 Mar 05, 2026
Feb 06, 2026
Mar 05, 2026
4.2 MEDIUM
CVE-2026-0598 — Ansible-lightspeed: broken object level authorization leading to cross-user ai conversati…

A security flaw was identified in the Ansible Lightspeed API conversation endpoints that handle AI chat interactions. The APIs do not properly verify whether a conversation identifier belongs to the …

Remote | Authorization
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
4.8 MEDIUM
CVE-2026-1990 — oatpp Type.hpp ObjectWrapper null pointer dereference

A security vulnerability has been detected in oatpp up to 1.3.1. This impacts the function oatpp::data::type::ObjectWrapper::ObjectWrapper of the file src/oatpp/data/type/Type.hpp. The manipulation l…

| Memory Corruption
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
5.5 MEDIUM
CVE-2026-1979 — mruby JMPNOT-to-JMPIF Optimization vm.c mrb_vm_exec use after free

A flaw has been found in mruby up to 3.4.0. This affects the function mrb_vm_exec of the file src/vm.c of the component JMPNOT-to-JMPIF Optimization. Executing a manipulation can lead to use after fr…

mruby | Memory Corruption
Feb 06, 2026 Feb 28, 2026
Feb 06, 2026
Feb 28, 2026
7.5 HIGH
CVE-2026-1978 — kalyan02 NanoCMS User Information pagesdata.txt direct request

A vulnerability was detected in kalyan02 NanoCMS up to 0.4. Affected by this issue is some unknown functionality of the file /data/pagesdata.txt of the component User Information Handler. Performing …

nanocms | Remote | Misconfiguration
Feb 06, 2026 Feb 27, 2026
Feb 06, 2026
Feb 27, 2026
6.5 MEDIUM
CVE-2026-1977 — isaacwasserman mcp-vegalite-server visualize_data eval code injection

A security vulnerability has been detected in isaacwasserman mcp-vegalite-server up to 16aefed598b8cd897b78e99b907f6e2984572c61. Affected by this vulnerability is the function eval of the component v…

Remote | Injection
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
8.8 HIGH
CVE-2025-15566 — ingress-nginx auth-proxy-set-headers nginx configuration injection

A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-proxy-set-headers` Ingress annotation can be used to inject configuration into nginx. This can lead to arb…

ingress-nginx | Remote | Injection
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
7.5 HIGH
CVE-2026-1976 — Free5GC SMF SessionDeletionResponse null pointer dereference

A weakness has been identified in Free5GC up to 4.1.0. Affected is the function SessionDeletionResponse of the component SMF. This manipulation causes null pointer dereference. The attack is possible…

free5gc | Remote | Memory Corruption
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
7.5 HIGH
CVE-2026-1975 — Free5GC pfcp_reports.go identityTriggerType null pointer dereference

A security flaw has been discovered in Free5GC up to 4.1.0. This impacts the function identityTriggerType of the file pfcp_reports.go. The manipulation results in null pointer dereference. The attack…

free5gc | Remote | Memory Corruption
Feb 06, 2026 Feb 09, 2026
Feb 06, 2026
Feb 09, 2026
Showing 20 of 5134 Results