Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-2230 — Booking Calendar <= 10.14.14 - Insecure Direct Object Reference to Authenticated (Subscri…

The Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 10.14.14 via the handle_ajax_save function due to missing validation …

booking_calendar | Remote | Authorization
Feb 18, 2026 Feb 18, 2026
Feb 18, 2026
Feb 18, 2026
9.8 CRITICAL
CVE-2025-70149 — CodeAstro Membership Management System SQL Injection Vulnerability

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.

membership_management_system | Remote | Injection
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
7.5 HIGH
CVE-2025-70147 — ProjectWorlds Online Time Table Generator Authentication Bypass

Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to obtain sensitive information (including plaintext passw…

online_time_table_generator | Remote | Authentication
Feb 18, 2026 Feb 20, 2026
Feb 18, 2026
Feb 20, 2026
9.1 CRITICAL
CVE-2025-70146 — ProjectWorlds Online Time Table Generator Authentication Bypass Vulnerability

Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized administrative operatio…

online_time_table_generator | Remote | Authentication
Feb 18, 2026 Feb 20, 2026
Feb 18, 2026
Feb 20, 2026
9.4 CRITICAL
CVE-2025-70141 — SourceCodester Customer Support System Unauthenticated Access Control Bypass

SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authentication or authorization before invoking adminis…

customer_support_system | Remote | Authorization
Feb 18, 2026 Feb 23, 2026
Feb 18, 2026
Feb 23, 2026
Showing 20 of 5705 Results