Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.7 MEDIUM
CVE-2026-27653 — Soliton Systems K.K. Installer Default Permission Vulnerability (Elevation of Privilege)

The installers for multiple products provided by Soliton Systems K.K. contain an issue with incorrect default permissions, which may allow arbitrary code to be executed with SYSTEM privileges.

Feb 27, 2026 Mar 17, 2026
Feb 27, 2026
Mar 17, 2026
8.8 HIGH
CVE-2026-3292 — jizhiCMS Batch Model.php findAll sql injection

A security vulnerability has been detected in jizhiCMS up to 2.5.6. Affected is the function findAll in the library frphp/lib/Model.php of the component Batch Interface. The manipulation of the argum…

jizhicms | Remote | Injection
Feb 27, 2026 Feb 27, 2026
Feb 27, 2026
Feb 27, 2026
9.8 CRITICAL
CVE-2026-3289 — Sanluan PublicCMS Template Cache Generation TemplateCacheComponent.java saveMetadata path…

A weakness has been identified in Sanluan PublicCMS 6.202506.d. This impacts the function saveMetadata of the file TemplateCacheComponent.java of the component Template Cache Generation. Executing a …

publiccms | Remote | Path Traversal
Feb 27, 2026 Mar 02, 2026
Feb 27, 2026
Mar 02, 2026
9.8 CRITICAL
CVE-2026-3287 — youlaitech youlai-mall App-side Product Pagination Endpoint SpuController.java listPagedS…

A security flaw has been discovered in youlaitech youlai-mall 2.0.0. This affects the function listPagedSpuForApp of the file mall-pms/pms-boot/src/main/java/com/youlai/mall/pms/controller/app/SpuCon…

youlai-mall | Remote | Injection
Feb 27, 2026 Mar 02, 2026
Feb 27, 2026
Mar 02, 2026
9.1 CRITICAL
CVE-2026-28370 — OpenStack Vitrage Code Execution Vulnerability

In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger code execution on the Vitrage service host as the user the Vit…

vitrage | Remote | Injection
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
5.3 MEDIUM
CVE-2026-1558 — WP Recipe Maker <= 10.3.2 - Insecure Direct Object Reference to Unauthenticated Arbitrary…

The WP Recipe Maker plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) in versions up to, and including, 10.3.2. This is due to the /wp-json/wp-recipe-maker/v1/integrati…

wp_recipe_maker | Remote | Authorization
Feb 27, 2026 Feb 27, 2026
Feb 27, 2026
Feb 27, 2026
7.8 HIGH
CVE-2026-1442 — Unitree UPK files Hard-Coded Key

Since the encryption algorithm used to protect firmware updates is itself encrypted using key material available to an attacker (or anyone paying attention), the firmware updates may be altered by an…

Feb 27, 2026 Mar 11, 2026
Feb 27, 2026
Mar 11, 2026
Showing 20 of 5947 Results