Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2025-15100 — JAY Login & Register <= 2.6.03 - Authenticated (Subscriber+) Privilege Escalation via jay…

The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.6.03. This is due to the plugin allowing a user to update arbitrary user me…

Remote | Authorization
Feb 08, 2026 Feb 09, 2026
Feb 08, 2026
Feb 09, 2026
9.8 CRITICAL
CVE-2025-15027 — JAY Login & Register <= 2.6.03 - Unauthenticated Privilege Escalation via jay_login_regis…

The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.6.03. This is due to the plugin allowing a user to update arbitrary user me…

Remote | Authorization
Feb 08, 2026 Feb 09, 2026
Feb 08, 2026
Feb 09, 2026
9.8 CRITICAL
CVE-2026-2122 — Xiaopi Panel WAF Firewall demo.php sql injection

A security flaw has been discovered in Xiaopi Panel up to 20260126. This impacts an unknown function of the file /demo.php of the component WAF Firewall. The manipulation of the argument ID results i…

panel | Remote | Injection
Feb 08, 2026 Mar 05, 2026
Feb 08, 2026
Mar 05, 2026
8.3 HIGH
CVE-2026-2120 — D-Link DIR-823X Configuration Parameter set_server_settings os command injection

A vulnerability was identified in D-Link DIR-823X 250416. This affects an unknown function of the file /goform/set_server_settings of the component Configuration Parameter Handler. The manipulation o…

dir-823x_firmware dir-823x | Remote | Injection
Feb 08, 2026 Feb 11, 2026
Feb 08, 2026
Feb 11, 2026
8.3 HIGH
CVE-2026-2118 — UTT HiPER 810 rehttpd formReleaseConnect sub_4407D4 command injection

A vulnerability was determined in UTT HiPER 810 1.7.4-141218. The impacted element is the function sub_4407D4 of the file /goform/formReleaseConnect of the component rehttpd. Executing a manipulation…

810_firmware 810 | Remote | Injection
Feb 08, 2026 Feb 13, 2026
Feb 08, 2026
Feb 13, 2026
9.8 CRITICAL
CVE-2026-2117 — itsourcecode Society Management System edit_activity.php sql injection

A vulnerability was found in itsourcecode Society Management System 1.0. The affected element is an unknown function of the file /admin/edit_activity.php. Performing a manipulation of the argument ac…

society_management_system | Remote | Injection
Feb 08, 2026 Feb 10, 2026
Feb 08, 2026
Feb 10, 2026
9.8 CRITICAL
CVE-2026-2116 — itsourcecode Society Management System edit_expenses.php sql injection

A vulnerability has been found in itsourcecode Society Management System 1.0. Impacted is an unknown function of the file /admin/edit_expenses.php. Such manipulation of the argument expenses_id leads…

society_management_system | Remote | Injection
Feb 08, 2026 Feb 10, 2026
Feb 08, 2026
Feb 10, 2026
9.8 CRITICAL
CVE-2026-2115 — itsourcecode Society Management System delete_expenses.php sql injection

A flaw has been found in itsourcecode Society Management System 1.0. This issue affects some unknown processing of the file /admin/delete_expenses.php. This manipulation of the argument expenses_id c…

society_management_system | Remote | Injection
Feb 07, 2026 Feb 10, 2026
Feb 07, 2026
Feb 10, 2026
9.8 CRITICAL
CVE-2026-2114 — itsourcecode Society Management System edit_admin.php sql injection

A vulnerability was detected in itsourcecode Society Management System 1.0. This vulnerability affects unknown code of the file /admin/edit_admin.php. The manipulation of the argument admin_id result…

society_management_system | Remote | Injection
Feb 07, 2026 Feb 10, 2026
Feb 07, 2026
Feb 10, 2026
8.8 HIGH
CVE-2026-25859 — WeKan < 8.20 Migration Functionality Insufficient Permission Checks

Wekan versions prior to 8.20 allow non-administrative users to access migration functionality due to insufficient permission checks, potentially resulting in unauthorized migration operations.

wekan | Remote | Authorization
Feb 07, 2026 Feb 10, 2026
Feb 07, 2026
Feb 10, 2026
9.8 CRITICAL
CVE-2026-25858 — macrozheng mall <= 1.0.3 Unauthenticated Password Reset via OTP Disclosure

macrozheng mall version 1.0.3 and prior contains an authentication vulnerability in the mall-portal password reset workflow that allows an unauthenticated attacker to reset arbitrary user account pas…

newbee-mall mall | Remote | Authentication
Feb 07, 2026 Mar 05, 2026
Feb 07, 2026
Mar 05, 2026
8.8 HIGH
CVE-2026-25857 — Tenda G300-F Command Injection via formSetWanDiag

Tenda G300-F router firmware version 16.01.14.2 and prior contain an OS command injection vulnerability in the WAN diagnostic functionality (formSetWanDiag). The implementation constructs a shell com…

rx9_pro_firmware g300-f_firmware g300-f | Remote | Injection
Feb 07, 2026 Mar 05, 2026
Feb 07, 2026
Mar 05, 2026
7.1 HIGH
CVE-2026-25568 — WeKan < 8.19 allowPrivateOnly Setting Enforcement Bypass

WeKan versions prior to 8.19 contain an authorization logic vulnerability where the instance configuration setting allowPrivateOnly is not sufficiently enforced at board creation time. When allowPriv…

wekan | Remote | Authorization
Feb 07, 2026 Feb 10, 2026
Feb 07, 2026
Feb 10, 2026
5.3 MEDIUM
CVE-2026-25567 — WeKan < 8.19 Card Comment Author Spoofing via User-controlled authorId

WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in the card comment creation API. The endpoint accepts an authorId from the request body, allowing an authenticated use…

wekan | Remote | Authentication
Feb 07, 2026 Feb 10, 2026
Feb 07, 2026
Feb 10, 2026
7.1 HIGH
CVE-2026-25566 — WeKan < 8.19 Cross-board Card Move Without Destination Authorization

WeKan versions prior to 8.19 contain an authorization vulnerability in card move logic. A user can specify a destination board/list/swimlane without adequate authorization checks for the destination …

wekan | Remote | Authorization
Feb 07, 2026 Feb 18, 2026
Feb 07, 2026
Feb 18, 2026
7.1 HIGH
CVE-2026-25565 — WeKan < 8.19 Read-only Board Roles Can Update Cards

WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only board read access rather than requiring write permission. This can allow users wi…

wekan | Remote | Authorization
Feb 07, 2026 Feb 10, 2026
Feb 07, 2026
Feb 10, 2026
7.5 HIGH
CVE-2026-25564 — WeKan < 8.19 Checklist Deletion IDOR via Missing Relationship Validation

WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes. The implementation does not verify that the supplied cardId belongs…

wekan | Remote | Authorization
Feb 07, 2026 Feb 10, 2026
Feb 07, 2026
Feb 10, 2026
7.5 HIGH
CVE-2026-25563 — WeKan < 8.19 Checklist Creation Cross-Board IDOR

WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes. The implementation does not verify that the supplied cardId belongs…

wekan | Remote | Authorization
Feb 07, 2026 Feb 10, 2026
Feb 07, 2026
Feb 10, 2026
5.3 MEDIUM
CVE-2026-25562 — WeKan < 8.19 Attachments Publication Information Disclosure

WeKan versions prior to 8.19 contain an information disclosure vulnerability in the attachments publication. Attachment metadata can be returned without properly scoping results to boards and cards a…

wekan | Remote | Information Disclosure
Feb 07, 2026 Feb 10, 2026
Feb 07, 2026
Feb 10, 2026
7.5 HIGH
CVE-2026-25561 — WeKan < 8.19 Attachment Upload Object Relationship Validation Bypass

WeKan versions prior to 8.19 contain an authorization weakness in the attachment upload API. The API does not fully validate that provided identifiers (such as boardId, cardId, swimlaneId, and listId…

wekan | Remote | Authorization
Feb 07, 2026 Feb 10, 2026
Feb 07, 2026
Feb 10, 2026
Showing 20 of 5092 Results