Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2025-15147 — WCFM Membership – WooCommerce Memberships for Multivendor Marketplace <= 2.11.8 - Insecur…

The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.11.8 via the '…

wcfm_membership | Remote | Authorization
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
7.7 HIGH
CVE-2026-25958 — Cube privilege escalation via a specially crafted request

Cube is a semantic layer for building data applications. From 0.27.19 to before 1.5.13, 1.4.2, and 1.0.14, it is possible to make a specially crafted request with a valid API token that leads to priv…

cube.js | Remote | Authorization
Feb 09, 2026 Feb 19, 2026
Feb 09, 2026
Feb 19, 2026
6.5 MEDIUM
CVE-2026-25957 — Cube Denial of Service (DoS) - An authenticated attacker can crash the server by sending …

Cube is a semantic layer for building data applications. From 1.1.17 to before 1.5.13 and 1.4.2, it is possible to make the entire Cube API unavailable by submitting a specially crafted request to a …

cube.js | Remote | Denial of Service
Feb 09, 2026 Feb 24, 2026
Feb 09, 2026
Feb 24, 2026
8.6 HIGH
CVE-2026-25951 — FUXA has a Path Traversal Sanitization Bypass

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.11, there is a flaw in the path sanitization logic allows an authenticated attacker with administrative privileg…

fuxa | Remote | Path Traversal
Feb 09, 2026 Feb 13, 2026
Feb 09, 2026
Feb 13, 2026
9.3 CRITICAL
CVE-2026-25939 — FUXA Unauthenticated Remote Arbitrary Scheduler Write

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10, an authorization bypass vulnerability in the FUXA allows an unauthenticated, remote attac…

fuxa | Remote | Authorization
Feb 09, 2026 Feb 13, 2026
Feb 09, 2026
Feb 13, 2026
9.8 CRITICAL
CVE-2026-25938 — FUXA Unauthenticated Remote Code Execution in Node-RED Integration

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to execu…

fuxa | Remote | Authentication
Feb 09, 2026 Feb 13, 2026
Feb 09, 2026
Feb 13, 2026
4.3 MEDIUM
CVE-2026-25934 — go-git improperly verifies data integrity values for .idx and .pack files

go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not …

go-git | Remote | Misconfiguration
Feb 09, 2026 Feb 20, 2026
Feb 09, 2026
Feb 20, 2026
7.8 HIGH
CVE-2026-25931 — vscode-spell-checker has a workspace-trust bypass Code Execution

vscode-spell-checker is a basic spell checker that works well with code and documents. Prior to v4.5.4, DocumentSettings._determineIsTrusted treats the configuration value cSpell.trustedWorkspace as …

| Misconfiguration
Feb 09, 2026 Feb 10, 2026
Feb 09, 2026
Feb 10, 2026
9.8 CRITICAL
CVE-2026-25895 — FUXA Unauthenticated Remote Code Execution via Arbitrary File Write in Upload API

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary files to arbitrary locat…

fuxa | Remote | Path Traversal
Feb 09, 2026 Feb 13, 2026
Feb 09, 2026
Feb 13, 2026
9.8 CRITICAL
CVE-2026-25894 — FUXA Unauthenticated Remote Code Execution via Hardcoded JWT Secret in Default Configurat…

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An insecure default configuration in FUXA allows an unauthenticated, remote attacker to gain administrative access and execut…

fuxa | Remote | Authentication
Feb 09, 2026 Feb 13, 2026
Feb 09, 2026
Feb 13, 2026
10.0 CRITICAL
CVE-2026-25893 — FUXA Unauthenticated Remote Code Execution via Admin JWT Minting

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to gain administra…

fuxa | Remote | Authentication
Feb 09, 2026 Feb 13, 2026
Feb 09, 2026
Feb 13, 2026
7.8 HIGH
CVE-2025-15319 — Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.

Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.

endpoint_patch | Authorization
Feb 09, 2026 Feb 10, 2026
Feb 09, 2026
Feb 10, 2026
5.5 MEDIUM
CVE-2025-15318 — Tanium addressed an arbitrary file deletion vulnerability in End-User Notifications Endpo…

Tanium addressed an arbitrary file deletion vulnerability in End-User Notifications Endpoint Tools.

endpoint_end-user-notifications | Misconfiguration
Feb 09, 2026 Feb 10, 2026
Feb 09, 2026
Feb 10, 2026
7.5 HIGH
CVE-2026-25961 — SumatraPDF Update MITM -> Arbitrary Code Execution

SumatraPDF is a multi-format reader for Windows. In 3.5.0 through 3.5.2, SumatraPDF's update mechanism disables TLS hostname verification (INTERNET_FLAG_IGNORE_CERT_CN_INVALID) and executes installer…

sumatrapdf | Remote | Misconfiguration
Feb 09, 2026 Feb 20, 2026
Feb 09, 2026
Feb 20, 2026
7.8 HIGH
CVE-2026-25925 — PowerDocu Affected by Remote Code Execution via Insecure Deserialization

PowerDocu contains a Windows GUI executable to perform technical documentations. Prior to 2.4.0, PowerDocu contains a critical security vulnerability in how it parses JSON files within Flow or App pa…

powerdocu | Injection
Feb 09, 2026 Feb 28, 2026
Feb 09, 2026
Feb 28, 2026
8.7 HIGH
CVE-2026-25923 — Phar Deserialization leading to Arbitrary File Deletion in my little forum

my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to 20260208.1, the application fails to filter the phar:// protocol in URL validat…

Remote | Injection
Feb 09, 2026 Feb 10, 2026
Feb 09, 2026
Feb 10, 2026
5.5 MEDIUM
CVE-2026-25920 — SumatraPDF has a heap out-of-bounds read in MOBI HuffDic decompressor

SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, a heap out-of-bounds read vulnerability exists in SumatraPDF's MOBI HuffDic decompressor. The bounds check in AddCdicData() only…

sumatrapdf | Memory Corruption
Feb 09, 2026 Feb 20, 2026
Feb 09, 2026
Feb 20, 2026
5.9 MEDIUM
CVE-2026-25918 — unity-cli Exposes Plaintext Credentials in Debug Logs (sign-package command)

unity-cli is a command line utility for the Unity Game Engine. Prior to 1.8.2 , the sign-package command in @rage-against-the-pixel/unity-cli logs sensitive credentials in plaintext when the --verbos…

unity-cli | Information Disclosure
Feb 09, 2026 Feb 28, 2026
Feb 09, 2026
Feb 28, 2026
7.5 HIGH
CVE-2026-25892 — Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endp…

Adminer is open-source database management software. Adminer v5.4.1 and earlier has a version check mechanism where adminer.org sends signed version info via JavaScript postMessage, which the browser…

adminer | Remote | Denial of Service
Feb 09, 2026 Feb 20, 2026
Feb 09, 2026
Feb 20, 2026
8.1 HIGH
CVE-2026-25890 — File Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URL

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to 2.57.1, an authenticated user can bypass th…

filebrowser | Remote | Authorization
Feb 09, 2026 Feb 20, 2026
Feb 09, 2026
Feb 20, 2026
Showing 20 of 5090 Results