Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.5

    MEDIUM
    CVE-2026-2979

    A flaw has been found in FastApiAdmin up to 2.2.0. This issue affects the function user_avatar_upload_controller of the file /backend/app/api/v1/module_system/user/controller.py of the component Scheduled Task API. Executing a manipulation can lead to unr... Read more

    Affected Products :
    • Published: Feb. 23, 2026
    • Modified: Feb. 23, 2026
    • Vuln Type: Misconfiguration
  • 4.0

    MEDIUM
    CVE-2026-26365

    Akamai Ghost on Akamai CDN edge servers before 2026-02-06 mishandles processing of custom hop-by-hop HTTP headers, where an incoming request containing the header "Connection: Transfer-Encoding" could result in a forward request with invalid message frami... Read more

    Affected Products :
    • Published: Feb. 23, 2026
    • Modified: Feb. 23, 2026
    • Vuln Type: Injection
  • 0.0

    NA
    CVE-2026-25747

    Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes data read from the LevelDB aggregation repository using java.io.ObjectInputStream without applying any Object... Read more

    Affected Products : camel
    • Published: Feb. 23, 2026
    • Modified: Feb. 23, 2026
    • Vuln Type: Authentication
  • 9.1

    CRITICAL
    CVE-2026-23552

    Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component.  The Camel-Keycloak KeycloakSecurityPolicy does not validate the iss (issuer) claim of JWT tokens against the configured realm. A token issued by one Keycloak ... Read more

    Affected Products : camel
    • Published: Feb. 23, 2026
    • Modified: Feb. 23, 2026
    • Vuln Type: Authentication
  • 6.5

    MEDIUM
    CVE-2026-2978

    A vulnerability was detected in FastApiAdmin up to 2.2.0. This vulnerability affects the function upload_file_controller of the file /backend/app/api/v1/module_system/params/controller.py of the component Scheduled Task API. Performing a manipulation resu... Read more

    Affected Products :
    • Published: Feb. 23, 2026
    • Modified: Feb. 23, 2026
    • Vuln Type: Misconfiguration
  • 6.5

    MEDIUM
    CVE-2026-2977

    A security vulnerability has been detected in FastApiAdmin up to 2.2.0. This affects the function upload_controller of the file /backend/app/api/v1/module_common/file/controller.py of the component Scheduled Task API. Such manipulation leads to unrestrict... Read more

    Affected Products :
    • Published: Feb. 23, 2026
    • Modified: Feb. 23, 2026
    • Vuln Type: Misconfiguration
  • 8.3

    HIGH
    CVE-2026-1367

    Zohocorp ManageEngine ADSelfService Plus versions 6522 and below are vulnerable to authenticated SQL Injection in the search report option.... Read more

    Affected Products : manageengine_adselfservice_plus
    • Published: Feb. 23, 2026
    • Modified: Feb. 23, 2026
    • Vuln Type: Injection
  • 5.3

    MEDIUM
    CVE-2026-2976

    A weakness has been identified in FastApiAdmin up to 2.2.0. Affected by this issue is the function download_controller of the file /backend/app/api/v1/module_common/file/controller.py of the component Download Endpoint. This manipulation of the argument f... Read more

    Affected Products :
    • Published: Feb. 23, 2026
    • Modified: Feb. 23, 2026
    • Vuln Type: Information Disclosure
  • 5.5

    MEDIUM
    CVE-2026-2975

    A security flaw has been discovered in FastApiAdmin up to 2.2.0. Affected by this vulnerability is the function reset_api_docs of the file /backend/app/plugin/init_app.py of the component Custom Documentation Endpoint. The manipulation results in informat... Read more

    Affected Products :
    • Published: Feb. 23, 2026
    • Modified: Feb. 23, 2026
    • Vuln Type: Information Disclosure
  • 2.5

    LOW
    CVE-2026-2974

    A vulnerability was identified in AliasVault App up to 0.25.3 on Android/iOS. This vulnerability affects unknown code of the file shared_prefs/aliasvault.xml of the component Backup Handler. The manipulation of the argument accessToken/refreshToken/metada... Read more

    Affected Products :
    • Published: Feb. 23, 2026
    • Modified: Feb. 23, 2026
    • Vuln Type: Information Disclosure
  • 4.8

    MEDIUM
    CVE-2026-2972

    A vulnerability was determined in a466350665 Smart-SSO up to 2.1.1. This affects the function Save of the file smart-sso-server/src/main/java/openjoe/smart/sso/server/controller/admin/UserController.java of the component Role Edit Page. Executing a manipu... Read more

    Affected Products :
    • Published: Feb. 23, 2026
    • Modified: Feb. 23, 2026
    • Vuln Type: Cross-Site Scripting
  • 5.3

    MEDIUM
    CVE-2026-2971

    A vulnerability was found in a466350665 Smart-SSO up to 2.1.1. Affected by this issue is some unknown functionality of the file smart-sso-server/src/main/resources/templates/login.html of the component Login. Performing a manipulation of the argument redi... Read more

    Affected Products :
    • Published: Feb. 23, 2026
    • Modified: Feb. 23, 2026
    • Vuln Type: Cross-Site Scripting
  • 4.6

    MEDIUM
    CVE-2026-2970

    A vulnerability has been found in datapizza-labs datapizza-ai 0.0.2. Affected by this vulnerability is the function RedisCache of the file datapizza-ai-cache/redis/datapizza/cache/redis/cache.py. Such manipulation leads to deserialization. The attack requ... Read more

    Affected Products :
    • Published: Feb. 23, 2026
    • Modified: Feb. 23, 2026
    • Vuln Type: Information Disclosure
  • 5.8

    MEDIUM
    CVE-2026-2969

    A flaw has been found in datapizza-labs datapizza-ai 0.0.2. Affected is the function ChatPromptTemplate of the file datapizza-ai-core/datapizza/modules/prompt/prompt.py of the component Jinja2 Template Handler. This manipulation of the argument Prompt cau... Read more

    Affected Products :
    • Published: Feb. 23, 2026
    • Modified: Feb. 23, 2026
    • Vuln Type: Injection
  • 8.5

    HIGH
    CVE-2026-2998

    ERP developed by eAI Technologies has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a crafted DLL file in the same directory as the program, thereby executing arbitrary code.... Read more

    Affected Products :
    • Published: Feb. 23, 2026
    • Modified: Feb. 23, 2026
    • Vuln Type: Misconfiguration
  • 6.3

    MEDIUM
    CVE-2026-2968

    A vulnerability was detected in Cesanta Mongoose up to 7.20. This impacts the function mg_chacha20_poly1305_decrypt of the file /src/tls_chacha20.c of the component Poly1305 Authentication Tag Handler. The manipulation results in improper verification of ... Read more

    Affected Products : mongoose
    • Published: Feb. 23, 2026
    • Modified: Feb. 23, 2026
    • Vuln Type: Cryptography
  • 6.3

    MEDIUM
    CVE-2026-2967

    A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This affects the function getpeer of the file /src/net_builtin.c of the component TCP Sequence Number Handler. The manipulation leads to improper verification of source of a commun... Read more

    Affected Products : mongoose
    • Published: Feb. 23, 2026
    • Modified: Feb. 23, 2026
    • Vuln Type: Authentication
  • 6.5

    MEDIUM
    CVE-2026-2997

    Tronclass developed by WisdomGarden has a Insecure Direct Object Reference vulnerability. After obtaining a course ID, authenticated remote attackers to modify a specific parameter to obtain a course invitation code, thereby joining any course.... Read more

    Affected Products : tronclass
    • Published: Feb. 23, 2026
    • Modified: Feb. 23, 2026
    • Vuln Type: Authorization
  • 6.3

    MEDIUM
    CVE-2026-2966

    A weakness has been identified in Cesanta Mongoose up to 7.20. The impacted element is the function mg_sendnsreq of the file /src/dns.c of the component DNS Transaction ID Handler. Executing a manipulation of the argument random can lead to insufficiently... Read more

    Affected Products : mongoose
    • Published: Feb. 23, 2026
    • Modified: Feb. 23, 2026
    • Vuln Type: Cryptography
  • 4.8

    MEDIUM
    CVE-2026-2965

    A security flaw has been discovered in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.9. The affected element is an unknown function of the file /admin/SysModule/edit.html of the component System Extension Module. Performing a manipulation of the argument Tit... Read more

    Affected Products : customer_relationship_management
    • Published: Feb. 23, 2026
    • Modified: Feb. 23, 2026
    • Vuln Type: Cross-Site Scripting
Showing 20 of 4697 Results