Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-2978 — FastApiAdmin Scheduled Task API controller.py upload_file_controller unrestricted upload

A vulnerability was detected in FastApiAdmin up to 2.2.0. This vulnerability affects the function upload_file_controller of the file /backend/app/api/v1/module_system/params/controller.py of the comp…

fastapi-admin fastapiadmin | Remote | Misconfiguration
Feb 23, 2026 Mar 05, 2026
Feb 23, 2026
Mar 05, 2026
8.8 HIGH
CVE-2026-2977 — FastApiAdmin Scheduled Task API controller.py upload_controller unrestricted upload

A security vulnerability has been detected in FastApiAdmin up to 2.2.0. This affects the function upload_controller of the file /backend/app/api/v1/module_common/file/controller.py of the component S…

fastapi-admin fastapiadmin | Remote | Misconfiguration
Feb 23, 2026 Mar 05, 2026
Feb 23, 2026
Mar 05, 2026
8.3 HIGH
CVE-2026-1367 — SQL Injection

Zohocorp ManageEngine ADSelfService Plus versions 6522 and below are vulnerable to authenticated SQL Injection in the search report option.

manageengine_adselfservice_plus | Remote | Injection
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
6.5 MEDIUM
CVE-2026-2976 — FastApiAdmin Download Endpoint controller.py download_controller information disclosure

A weakness has been identified in FastApiAdmin up to 2.2.0. Affected by this issue is the function download_controller of the file /backend/app/api/v1/module_common/file/controller.py of the componen…

fastapi-admin fastapiadmin | Remote | Information Disclosure
Feb 23, 2026 Mar 05, 2026
Feb 23, 2026
Mar 05, 2026
5.5 MEDIUM
CVE-2026-2975 — FastApiAdmin Custom Documentation Endpoint init_app.py reset_api_docs information disclos…

A security flaw has been discovered in FastApiAdmin up to 2.2.0. Affected by this vulnerability is the function reset_api_docs of the file /backend/app/plugin/init_app.py of the component Custom Docu…

fastapi-admin fastapiadmin | Remote | Information Disclosure
Feb 23, 2026 Mar 05, 2026
Feb 23, 2026
Mar 05, 2026
2.5 LOW
CVE-2026-2974 — AliasVault App Backup aliasvault.xml backup

A vulnerability was identified in AliasVault App up to 0.25.3 on Android/iOS. This vulnerability affects unknown code of the file shared_prefs/aliasvault.xml of the component Backup Handler. The mani…

| Information Disclosure
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
5.4 MEDIUM
CVE-2026-2972 — a466350665 Smart-SSO Role Edit UserController.java save cross site scripting

A vulnerability was determined in a466350665 Smart-SSO up to 2.1.1. This affects the function Save of the file smart-sso-server/src/main/java/openjoe/smart/sso/server/controller/admin/UserController.…

smart-sso | Remote | Cross-Site Scripting
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
6.1 MEDIUM
CVE-2026-2971 — a466350665 Smart-SSO Login login.html cross site scripting

A vulnerability was found in a466350665 Smart-SSO up to 2.1.1. Affected by this issue is some unknown functionality of the file smart-sso-server/src/main/resources/templates/login.html of the compone…

smart-sso | Remote | Cross-Site Scripting
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
7.5 HIGH
CVE-2026-2970 — datapizza-labs datapizza-ai cache.py RedisCache deserialization

A vulnerability has been found in datapizza-labs datapizza-ai 0.0.2. Affected by this vulnerability is the function RedisCache of the file datapizza-ai-cache/redis/datapizza/cache/redis/cache.py. Suc…

datapizza_ai datapizza-ai | Information Disclosure
Feb 23, 2026 Mar 03, 2026
Feb 23, 2026
Mar 03, 2026
7.2 HIGH
CVE-2026-2969 — datapizza-labs datapizza-ai Jinja2 Template prompt.py ChatPromptTemplate special elements…

A flaw has been found in datapizza-labs datapizza-ai 0.0.2. Affected is the function ChatPromptTemplate of the file datapizza-ai-core/datapizza/modules/prompt/prompt.py of the component Jinja2 Templa…

datapizza_ai datapizza-ai | Remote | Injection
Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
8.5 HIGH
CVE-2026-2998 — eAI Technologies|ERP - DLL Hijacking

ERP developed by eAI Technologies has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a crafted DLL file in the same directory as the program, thereby executing arbitra…

| Misconfiguration
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
6.3 MEDIUM
CVE-2026-2968 — Cesanta Mongoose Poly1305 Authentication Tag tls_chacha20.c mg_chacha20_poly1305_decrypt …

A vulnerability was detected in Cesanta Mongoose up to 7.20. This impacts the function mg_chacha20_poly1305_decrypt of the file /src/tls_chacha20.c of the component Poly1305 Authentication Tag Handle…

mongoose | Remote | Cryptography
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
6.3 MEDIUM
CVE-2026-2967 — Cesanta Mongoose TCP Sequence Number net_builtin.c getpeer verification of source

A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This affects the function getpeer of the file /src/net_builtin.c of the component TCP Sequence Number Handler. The manipulat…

mongoose | Remote | Authentication
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
6.5 MEDIUM
CVE-2026-2997 — WisdomGarden|Tronclass - Insecure Direct Object Reference

Tronclass developed by WisdomGarden has a Insecure Direct Object Reference vulnerability. After obtaining a course ID, authenticated remote attackers to modify a specific parameter to obtain a course…

tronclass | Remote | Authorization
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
6.3 MEDIUM
CVE-2026-2966 — Cesanta Mongoose DNS Transaction ID dns.c mg_sendnsreq random values

A weakness has been identified in Cesanta Mongoose up to 7.20. The impacted element is the function mg_sendnsreq of the file /src/dns.c of the component DNS Transaction ID Handler. Executing a manipu…

mongoose | Remote | Cryptography
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
4.8 MEDIUM
CVE-2026-2965 — 07FLYCMS/07FLY-CMS/07FlyCRM System Extension edit.html cross site scripting

A security flaw has been discovered in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.9. The affected element is an unknown function of the file /admin/SysModule/edit.html of the component System Extensi…

customer_relationship_management | Remote | Cross-Site Scripting
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
9.8 CRITICAL
CVE-2026-2964 — higuma web-audio-recorder-js Dynamic Config Handling WebAudioRecorder.js extend prototype…

A vulnerability was identified in higuma web-audio-recorder-js 0.1/0.1.1. Impacted is the function extend in the library lib/WebAudioRecorder.js of the component Dynamic Config Handling. Such manipul…

webaudiorecorder.js | Remote | Misconfiguration
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-24494 — SQL injection vulnerability in Order Up Online Ordering System

SQL Injection vulnerability in the /api/integrations/getintegrations endpoint of Order Up Online Ordering System 1.0 allows an unauthenticated attacker to access sensitive backend database data via a…

Remote | Injection
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
6.5 MEDIUM
CVE-2026-2963 — Jinher OA C6 OfficeSupplyTypeRight.aspx sql injection

A vulnerability was determined in Jinher OA C6 up to 20260210. This issue affects some unknown processing of the file /C6/Jhsoft.Web.officesupply/OfficeSupplyTypeRight.aspx. This manipulation of the …

jinher_oa_c6 | Remote | Injection
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
9.0 HIGH
CVE-2026-2962 — D-Link DWR-M960 Scheduled Reboot Configuration Endpoint formDateReboot sub_460F30 stack-b…

A vulnerability was found in D-Link DWR-M960 1.01.07. This vulnerability affects the function sub_460F30 of the file /boafrm/formDateReboot of the component Scheduled Reboot Configuration Endpoint. T…

dwr-m960_firmware dwr-m960 | Remote | Memory Corruption
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
Showing 20 of 5378 Results