Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.4 MEDIUM
CVE-2026-1401 — Tune Library <= 1.6.3 - Missing Authorization to Authenticated (Subscriber+) Stored Cross…

The Tune Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via CSV import in all versions up to, and including, 1.6.3. This is due to insufficient input sanitization and outpu…

tune_library | Remote | Cross-Site Scripting
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
6.1 MEDIUM
CVE-2026-0521 — Reflected Cross-Site Scripting in PDF Export Error Message

A reflected cross-site scripting (XSS) vulnerability in the PDF export functionality of the TYDAC AG MAP+ solution allows unauthenticated attackers to craft a malicious URL, that if visited by a vict…

map\+ | Remote | Cross-Site Scripting
Feb 06, 2026 Feb 18, 2026
Feb 06, 2026
Feb 18, 2026
5.3 MEDIUM
CVE-2025-10753 — OAuth Single Sign On – SSO (OAuth Client) <= 6.26.14 - Missing Authorization

The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 6.26.14. This is due to missing capability checks and aut…

oauth_single_sign_on | Remote | Authentication
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
5.5 MEDIUM
CVE-2026-1991 — libuvc UVC Descriptor device.c uvc_scan_streaming null pointer dereference

A vulnerability was detected in libuvc up to 0.0.7. Affected is the function uvc_scan_streaming of the file src/device.c of the component UVC Descriptor Handler. The manipulation results in null poin…

libuvc | Memory Corruption
Feb 06, 2026 Mar 05, 2026
Feb 06, 2026
Mar 05, 2026
4.2 MEDIUM
CVE-2026-0598 — Ansible-lightspeed: broken object level authorization leading to cross-user ai conversati…

A security flaw was identified in the Ansible Lightspeed API conversation endpoints that handle AI chat interactions. The APIs do not properly verify whether a conversation identifier belongs to the …

Remote | Authorization
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
4.8 MEDIUM
CVE-2026-1990 — oatpp Type.hpp ObjectWrapper null pointer dereference

A security vulnerability has been detected in oatpp up to 1.3.1. This impacts the function oatpp::data::type::ObjectWrapper::ObjectWrapper of the file src/oatpp/data/type/Type.hpp. The manipulation l…

| Memory Corruption
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
5.5 MEDIUM
CVE-2026-1979 — mruby JMPNOT-to-JMPIF Optimization vm.c mrb_vm_exec use after free

A flaw has been found in mruby up to 3.4.0. This affects the function mrb_vm_exec of the file src/vm.c of the component JMPNOT-to-JMPIF Optimization. Executing a manipulation can lead to use after fr…

mruby | Memory Corruption
Feb 06, 2026 Feb 28, 2026
Feb 06, 2026
Feb 28, 2026
7.5 HIGH
CVE-2026-1978 — kalyan02 NanoCMS User Information pagesdata.txt direct request

A vulnerability was detected in kalyan02 NanoCMS up to 0.4. Affected by this issue is some unknown functionality of the file /data/pagesdata.txt of the component User Information Handler. Performing …

nanocms | Remote | Misconfiguration
Feb 06, 2026 Feb 27, 2026
Feb 06, 2026
Feb 27, 2026
6.5 MEDIUM
CVE-2026-1977 — isaacwasserman mcp-vegalite-server visualize_data eval code injection

A security vulnerability has been detected in isaacwasserman mcp-vegalite-server up to 16aefed598b8cd897b78e99b907f6e2984572c61. Affected by this vulnerability is the function eval of the component v…

Remote | Injection
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
8.8 HIGH
CVE-2025-15566 — ingress-nginx auth-proxy-set-headers nginx configuration injection

A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-proxy-set-headers` Ingress annotation can be used to inject configuration into nginx. This can lead to arb…

ingress-nginx | Remote | Injection
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
Showing 20 of 5090 Results