Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.9 MEDIUM
CVE-2026-24916 — Microsoft Windows Identity Authentication Bypass

Identity authentication bypass vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

harmonyos | Authentication
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
7.1 HIGH
CVE-2026-24915 — Cisco Media Out-of-Bounds Read Vulnerability

Out-of-bounds read issue in the media subsystem. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

harmonyos | Memory Corruption
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
5.5 MEDIUM
CVE-2026-24914 — "Canon Camera Type Confusion Vulnerability"

Type confusion vulnerability in the camera module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Memory Corruption
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
9.8 CRITICAL
CVE-2026-21643 — Fortinet FortiClientEMS SQL Injection

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized co…

forticlientems | Remote | Injection
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
4.3 MEDIUM
CVE-2026-1785 — Code Snippets <= 3.9.4 - Cross-Site Request Forgery to Cloud Snippet Download/Update Acti…

The Code Snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.9.4. This is due to missing nonce validation on the cloud snippet download a…

Remote | Cross-Site Request Forgery
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
9.8 CRITICAL
CVE-2026-1499 — WP Duplicate <= 1.1.8 - Authenticated (Subscriber+) Arbitrary File Upload via 'process_ad…

The WP Duplicate plugin for WordPress is vulnerable to Missing Authorization leading to Arbitrary File Upload in all versions up to and including 1.1.8. This is due to a missing capability check on t…

Remote | Authorization
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
6.4 MEDIUM
CVE-2026-1252 — Events Listing Widget <= 1.3.4 - Authenticated (Author+) Stored Cross-Site Scripting via …

The Events Listing Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Event URL' parameter in all versions up to, and including, 1.3.4 due to insufficient input sanitiz…

Remote | Cross-Site Scripting
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
Showing 20 of 5087 Results