Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.9 CRITICAL
CVE-2026-1868 — Improper Neutralization of Special Elements Used in a Template Engine in GitLab AI Gateway

GitLab has remediated a vulnerability in the Duo Workflow Service component of GitLab AI Gateway affecting all versions of the AI Gateway from 18.1.6, 18.2.6, 18.3.1 to 18.6.1, 18.7.0, and 18.8.0 in …

ai-gateway | Remote | Denial of Service
Feb 09, 2026 Feb 09, 2026
Feb 09, 2026
Feb 09, 2026
8.5 HIGH
CVE-2026-0870 — GIGABYTE|MacroHub - Local Privilege Escalation

MacroHub developed by GIGABYTE has a Local Privilege Escalation vulnerability. Due to the MacroHub application launching external applications with improper privileges, allowing authenticated local a…

| Authorization
Feb 09, 2026 Feb 09, 2026
Feb 09, 2026
Feb 09, 2026
8.8 HIGH
CVE-2026-2218 — D-Link DCS-933L alphapd setSystemAdmin command injection

A vulnerability was determined in D-Link DCS-933L up to 1.14.11. This affects an unknown function of the file /setSystemAdmin of the component alphapd. This manipulation of the argument AdminID cause…

dcs-933l_firmware dcs-933l | Remote | Injection
Feb 09, 2026 Feb 11, 2026
Feb 09, 2026
Feb 11, 2026
9.8 CRITICAL
CVE-2026-2217 — itsourcecode Event Management System manage_user.php sql injection

A vulnerability was found in itsourcecode Event Management System 1.0. The impacted element is an unknown function of the file /admin/manage_user.php. The manipulation of the argument ID results in s…

event_management_system | Remote | Injection
Feb 09, 2026 Feb 10, 2026
Feb 09, 2026
Feb 10, 2026
5.3 MEDIUM
CVE-2026-2216 — rachelos WeRSS we-mp-rss tools.py download_export_file path traversal

A flaw has been found in rachelos WeRSS we-mp-rss up to 1.4.8. Impacted is the function download_export_file of the file apis/tools.py. Executing a manipulation of the argument filename can lead to p…

Remote | Path Traversal
Feb 09, 2026 Feb 09, 2026
Feb 09, 2026
Feb 09, 2026
5.7 MEDIUM
CVE-2026-22613 — Eaton Network M3 Firmware Man-in-the-middle Attack

The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacker to perform a Man-in-the-middle attack. This security is…

Remote | Misconfiguration
Feb 09, 2026 Feb 09, 2026
Feb 09, 2026
Feb 09, 2026
Showing 20 of 5386 Results