Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-21863 — Malformed Valkey Cluster bus message can lead to Remote DoS

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus port can send an invalid packet that may cause an…

valkey | Remote | Denial of Service
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
8.0 HIGH
CVE-2025-70329 — TOTOLink X5000R OS Command Injection Vulnerability

TOTOLink X5000R v9.1.0cu_2415_B20250515 contains an OS command injection vulnerability in the setIptvCfg handler of the /usr/sbin/lighttpd executable. The vlanVidLan1 (and other vlanVidLanX) paramete…

x5000r_firmware x5000r | Injection
Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
8.5 HIGH
CVE-2025-67733 — Valkey Affected by RESP Protocol Injection via Lua error_reply

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary information into the response stream for…

valkey | Remote | Injection
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
7.4 HIGH
CVE-2025-63946 — Tencent PC Manager Privilege Escalation Vulnerability

A privilege escalation (PE) vulnerability in the Tencent PC Manager app thru 17.10.28554.205 on Windows devices enables a local user to execute programs with elevated privileges. However, execution r…

pcmanager | Authorization
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
7.4 HIGH
CVE-2025-63945 — Tencent iOA App Privilege Escalation Vulnerability

A privilege escalation (PE) vulnerability in the Tencent iOA app thru 210.9.28693.621001 on Windows devices enables a local user to execute programs with elevated privileges. However, execution requi…

ioa | Authorization
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
6.2 MEDIUM
CVE-2025-61147 — StrukturAG libde265 Segmentation Fault (Memory Corruption)

strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table().

| Memory Corruption
Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
4.0 MEDIUM
CVE-2025-61146 — Saitoha Libsixel Memory Leak Vulnerability

saitoha libsixel until v1.8.7 was discovered to contain a memory leak via the component malloc_stub.c.

libsixel | Memory Corruption
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
5.5 MEDIUM
CVE-2025-61145 — Libtiff Double Free Vulnerability

libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c.

libtiff | Memory Corruption
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
9.8 CRITICAL
CVE-2025-61144 — Libtiff Stack Overflow Vulnerability

libtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function.

libtiff | Remote | Memory Corruption
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
5.5 MEDIUM
CVE-2025-61143 — Libtiff NULL Pointer Dereference Vulnerability

libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c.

libtiff | Memory Corruption
Feb 23, 2026 Feb 25, 2026
Feb 23, 2026
Feb 25, 2026
6.1 MEDIUM
CVE-2026-26464 — Society Management System Portal Stored XSS Vulnerability

Stored Cross-Site Scripting (XSS) was found in the /admin/edit_user.php page of Society Management System Portal V1.0, which allows remote attackers to inject and store arbitrary JavaScript code that…

society_management_system_portal | Remote | Cross-Site Scripting
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
6.5 MEDIUM
CVE-2026-2698 — Improper Access Control

An improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope.

security_center | Remote | Authorization
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
7.1 HIGH
CVE-2026-27514 — Tenda F3 Plaintext Credential Exposure in Configuration Download

Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a sensitive information exposure vulnerability in the configuration download functionality. The configuration download response …

f3_firmware f3 | Remote | Information Disclosure
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
5.1 MEDIUM
CVE-2026-27513 — Tenda F3 CSRF in Web Management Interface

Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a cross-site request forgery (CSRF) vulnerability in the web-based administrative interface. The interface does not implement an…

f3_firmware f3 | Remote | Cross-Site Request Forgery
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
6.1 MEDIUM
CVE-2026-27512 — Tenda F3 Reflected Script Execution via Missing nosniff Header

Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a content-type confusion vulnerability in the administrative interface. Responses omit the X-Content-Type-Options: nosniff heade…

f3_firmware f3 | Remote | Cross-Site Scripting
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
5.1 MEDIUM
CVE-2026-27511 — Tenda F3 Clickjacking in Web Management Interface

Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a clickjacking vulnerability in the web-based administrative interface. The interface does not set the X-Frame-Options header, a…

f3_firmware f3 | Remote | Cross-Site Request Forgery
Feb 23, 2026 Feb 23, 2026
Feb 23, 2026
Feb 23, 2026
5.5 MEDIUM
CVE-2026-22568 — Unauthorized information retrieval in ZIA Admin UI

Improper neutralization of special elements in user-supplied input within the ZIA Admin UI could allow an authenticated administrator to access or retrieve unauthorized internal information in rare c…

zscaler_internet_access_admin_portal | Remote | Information Disclosure
Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
7.6 HIGH
CVE-2026-22567 — ZIA Admin UI Input Validation Bug

Improper validation of user-supplied input in the ZIA Admin UI could allow an authenticated administrator to initiate backend functions through specific input fields in limited scenarios.

Feb 23, 2026 Feb 26, 2026
Feb 23, 2026
Feb 26, 2026
9.0 HIGH
CVE-2026-3016 — UTT HiPER 810G formP2PLimitConfig strcpy buffer overflow

A vulnerability was identified in UTT HiPER 810G up to 1.7.7-171114. The affected element is the function strcpy of the file /goform/formP2PLimitConfig. The manipulation of the argument except leads …

810g_firmware 810g | Remote | Memory Corruption
Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
9.0 HIGH
CVE-2026-3015 — UTT HiPER 810G formPolicyRouteConf strcpy buffer overflow

A vulnerability was determined in UTT HiPER 810G up to 1.7.7-171114. Impacted is the function strcpy of the file /goform/formPolicyRouteConf. Executing a manipulation of the argument GroupName can le…

810g_firmware 810g | Remote | Memory Corruption
Feb 23, 2026 Feb 24, 2026
Feb 23, 2026
Feb 24, 2026
Showing 20 of 5410 Results