Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2025-70397 — Jizhicms SQL Injection Vulnerability

jizhicms 2.5.6 is vulnerable to SQL Injection in Article/deleteAll and Extmolds/deleteAll via the data parameter.

jizhicms | Remote | Injection
Feb 17, 2026 Feb 19, 2026
Feb 17, 2026
Feb 19, 2026
9.0 CRITICAL
CVE-2025-65753 — Guardian Gryphon TLS Certification Command Execution

An issue in the TLS certification mechanism of Guardian Gryphon v01.06.0006.22 allows attackers to execute commands as root.

Remote | Authentication
Feb 17, 2026 Feb 19, 2026
Feb 17, 2026
Feb 19, 2026
9.8 CRITICAL
CVE-2026-2616 — Beetel 777VR1 Web Management hard-coded credentials

A vulnerability has been found in Beetel 777VR1 up to 01.00.09. The impacted element is an unknown function of the component Web Management Interface. The manipulation leads to hard-coded credentials…

777vr1_firmware 777vr1 | Remote | Authentication
Feb 17, 2026 Feb 19, 2026
Feb 17, 2026
Feb 19, 2026
9.6 CRITICAL
CVE-2026-22208 — OpenS100 Portrayal Engine Unrestricted Lua Standard Library Access

OpenS100 (the reference implementation S-100 viewer) prior to commit 753cf29 contain a remote code execution vulnerability via an unrestricted Lua interpreter. The Portrayal Engine initializes Lua us…

Remote | Injection
Feb 17, 2026 Feb 18, 2026
Feb 17, 2026
Feb 18, 2026
5.7 MEDIUM
CVE-2025-70829 — Datart H2 JDBC Connection String Information Exposure

An information exposure vulnerability in Datart v1.0.0-rc.3 allows authenticated attackers to access sensitive data via a custom H2 JDBC connection string.

datart | Information Disclosure
Feb 17, 2026 Feb 23, 2026
Feb 17, 2026
Feb 23, 2026
6.5 MEDIUM
CVE-2024-31118 — WordPress SP Project & Document Manager plugin <= 4.70 - Broken Access Control to XSS vul…

Missing Authorization vulnerability in Smartypants SP Project & Document Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SP Project & Document Manag…

sp_project_\&_document_manager | Remote | Authorization
Feb 17, 2026 Feb 18, 2026
Feb 17, 2026
Feb 18, 2026
6.5 MEDIUM
CVE-2022-41650 — WordPress Custom Content by Country plugin <= 3.1.2 - Broken Access Control vulnerability

Missing Authorization vulnerability in Paul Custom Content by Country (by Shield Security) custom-content-by-country.This issue affects Custom Content by Country (by Shield Security): from n/a throug…

Remote | Authorization
Feb 17, 2026 Feb 18, 2026
Feb 17, 2026
Feb 18, 2026
Showing 20 of 5547 Results