Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.1 MEDIUM
CVE-2025-46320 — FileMaker WebDirect Cross-Site Scripting (XSS)

A cross-site scripting (XSS) vulnerability in a FileMaker WebDirect custom homepage could lead to unauthorized access and remote code execution. This vulnerability has been fully addressed in FileMak…

filemaker_server | Remote | Cross-Site Scripting
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
6.5 MEDIUM
CVE-2026-3131 — Devolutions Server Unauthenticated Access Control Bypass

Improper access control in multiple DVLS REST API endpoints in Devolutions Server 2025.3.14.0 and earlier allows an authenticated user with view-only permission to access sensitive connection data.

devolutions_server | Remote | Authorization
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
8.8 HIGH
CVE-2026-3105 — SQL Injection in Contact Activity API Sorting

SummaryThis advisory addresses a SQL injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity time…

mautic | Remote | Injection
Feb 24, 2026 Feb 27, 2026
Feb 24, 2026
Feb 27, 2026
5.9 MEDIUM
CVE-2026-27477 — Mastodon has SSRF via unvalidated FASP Provider base_url

Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versions 4.4.0 through 4.4.13 and 4.5.0 through 4.5.6, a…

mastodon | Remote | Server-Side Request Forgery
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-26342 — Tattile Smart+ / Vega / Basic <= 1.181.5 Insufficient Session Token Expiration

Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior implement an authentication token (X-User-Token) with insufficient expiration. An attacker who obtains a valid toke…

Feb 24, 2026 Feb 27, 2026
Feb 24, 2026
Feb 27, 2026
9.8 CRITICAL
CVE-2026-26341 — Tattile Smart+ / Vega / Basic <= 1.181.5 Default Credentials

Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that are not forced to be changed during installation or commissioning. An attacker w…

Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
8.7 HIGH
CVE-2026-26340 — Tattile Smart+ / Vega / Basic <= 1.181.5 Unauthenticated RTSP Stream Disclosure

Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior expose RTSP streams without requiring authentication. A remote attacker can connect to the RTSP service and access …

Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
7.5 HIGH
CVE-2026-24241 — NVIDIA Delegated Licensing Service Authentication Bypass

NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an attacker could exploit an improper authentication issue. A successful exploit of this vulnerability mi…

delegated_license_service | Remote | Authentication
Feb 24, 2026 Feb 27, 2026
Feb 24, 2026
Feb 27, 2026
2.7 LOW
CVE-2026-23859 — Dell Wyse Management Suite Client-Side Enforcement Bypass Vulnerability

Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Client-Side Enforcement of Server-Side Security vulnerability. A high privileged attacker with remote access could potentially exploit…

wyse_management_suite | Remote | Misconfiguration
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
5.4 MEDIUM
CVE-2026-23858 — Dell Wyse Management Suite Cross-site Scripting Vulnerability

Dell Wyse Management Suite, versions prior to WMS 5.5, contain an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with re…

wyse_management_suite | Remote | Cross-Site Scripting
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
7.2 HIGH
CVE-2026-22766 — Dell Wyse Management Suite Unrestricted File Upload Vulnerability

Dell Wyse Management Suite, versions prior to WMS 5.5, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploi…

wyse_management_suite | Remote | Misconfiguration
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
8.8 HIGH
CVE-2026-22765 — Dell Wyse Management Suite Elevation of Privileges Missing Authorization Vulnerability

Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Missing Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leadin…

wyse_management_suite | Remote | Authorization
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
4.3 MEDIUM
CVE-2026-1768 — Devolutions Server Permission Cache Poisoning Vulnerability

A permission cache poisoning vulnerability in Devolutions Server allows authenticated users to bypass permissions to access entries.This issue affects Devolutions Server: before 2025.3.15.

devolutions_server | Remote | Authorization
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
8.8 HIGH
CVE-2025-33181 — NVIDIA Cumulus Linux and NVOS Command Injection Vulnerability

NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could inject a command. A successful exploit of this vulnerability might lead to esca…

Feb 24, 2026 Feb 27, 2026
Feb 24, 2026
Feb 27, 2026
8.8 HIGH
CVE-2025-33180 — NVIDIA Cumulus Linux and NVOS Command Injection Vulnerability

NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could inject a command. A successful exploit of this vulnerability might lead to esca…

Feb 24, 2026 Feb 27, 2026
Feb 24, 2026
Feb 27, 2026
8.8 HIGH
CVE-2025-33179 — NVIDIA Cumulus Linux and NVOS Privilege Escalation Vulnerability

NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could run an unauthorized command. A successful exploit of this vulnerability might l…

Feb 24, 2026 Feb 27, 2026
Feb 24, 2026
Feb 27, 2026
7.8 HIGH
CVE-2025-1789 — Genetec Update Service Privilege Escalation

Local privilege escalation in Genetec Update Service. An authenticated, low-privileged, Windows user could exploit this vulnerability to gain elevated privileges on the affected system.

genetec_update_service | Authentication
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
5.8 MEDIUM
CVE-2025-1787 — Genetec Update Service Privilege Escalation

Local admin could to leak information from the Genetec Update Service configuration web page. An authenticated, admin privileged, Windows user could exploit this vulnerability to gain elevated privil…

genetec_update_service | Information Disclosure
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
8.2 HIGH
CVE-2026-27468 — Mastodon may allow unconfirmed FASP to make subscriptions

Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versions 4.4.0 through 4.4.13 and 4.5.0 through 4.5.6, a…

mastodon | Remote | Denial of Service
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
6.1 MEDIUM
CVE-2026-27156 — NiceGUI has XSS via Code Injection

NiceGUI is a Python-based UI framework. Prior to version 3.8.0, several NiceGUI APIs that execute methods on client-side elements (`Element.run_method()`, `AgGrid.run_grid_method()`, `EChart.run_char…

nicegui | Remote | Cross-Site Scripting
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
Showing 20 of 5392 Results