Latest CVE Feed
-
6.5
MEDIUMCVE-2026-2979
A flaw has been found in FastApiAdmin up to 2.2.0. This issue affects the function user_avatar_upload_controller of the file /backend/app/api/v1/module_system/user/controller.py of the component Scheduled Task API. Executing a manipulation can lead to unr... Read more
Affected Products :- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Misconfiguration
-
4.0
MEDIUMCVE-2026-26365
Akamai Ghost on Akamai CDN edge servers before 2026-02-06 mishandles processing of custom hop-by-hop HTTP headers, where an incoming request containing the header "Connection: Transfer-Encoding" could result in a forward request with invalid message frami... Read more
Affected Products :- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Injection
-
0.0
NACVE-2026-25747
Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes data read from the LevelDB aggregation repository using java.io.ObjectInputStream without applying any Object... Read more
Affected Products : camel- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Authentication
-
9.1
CRITICALCVE-2026-23552
Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component. The Camel-Keycloak KeycloakSecurityPolicy does not validate the iss (issuer) claim of JWT tokens against the configured realm. A token issued by one Keycloak ... Read more
Affected Products : camel- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2026-2978
A vulnerability was detected in FastApiAdmin up to 2.2.0. This vulnerability affects the function upload_file_controller of the file /backend/app/api/v1/module_system/params/controller.py of the component Scheduled Task API. Performing a manipulation resu... Read more
Affected Products :- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2026-2977
A security vulnerability has been detected in FastApiAdmin up to 2.2.0. This affects the function upload_controller of the file /backend/app/api/v1/module_common/file/controller.py of the component Scheduled Task API. Such manipulation leads to unrestrict... Read more
Affected Products :- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Misconfiguration
-
8.3
HIGHCVE-2026-1367
Zohocorp ManageEngine ADSelfService Plus versions 6522 and below are vulnerable to authenticated SQL Injection in the search report option.... Read more
Affected Products : manageengine_adselfservice_plus- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2026-2976
A weakness has been identified in FastApiAdmin up to 2.2.0. Affected by this issue is the function download_controller of the file /backend/app/api/v1/module_common/file/controller.py of the component Download Endpoint. This manipulation of the argument f... Read more
Affected Products :- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2026-2975
A security flaw has been discovered in FastApiAdmin up to 2.2.0. Affected by this vulnerability is the function reset_api_docs of the file /backend/app/plugin/init_app.py of the component Custom Documentation Endpoint. The manipulation results in informat... Read more
Affected Products :- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Information Disclosure
-
2.5
LOWCVE-2026-2974
A vulnerability was identified in AliasVault App up to 0.25.3 on Android/iOS. This vulnerability affects unknown code of the file shared_prefs/aliasvault.xml of the component Backup Handler. The manipulation of the argument accessToken/refreshToken/metada... Read more
Affected Products :- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Information Disclosure
-
4.8
MEDIUMCVE-2026-2972
A vulnerability was determined in a466350665 Smart-SSO up to 2.1.1. This affects the function Save of the file smart-sso-server/src/main/java/openjoe/smart/sso/server/controller/admin/UserController.java of the component Role Edit Page. Executing a manipu... Read more
Affected Products :- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2026-2971
A vulnerability was found in a466350665 Smart-SSO up to 2.1.1. Affected by this issue is some unknown functionality of the file smart-sso-server/src/main/resources/templates/login.html of the component Login. Performing a manipulation of the argument redi... Read more
Affected Products :- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Cross-Site Scripting
-
4.6
MEDIUMCVE-2026-2970
A vulnerability has been found in datapizza-labs datapizza-ai 0.0.2. Affected by this vulnerability is the function RedisCache of the file datapizza-ai-cache/redis/datapizza/cache/redis/cache.py. Such manipulation leads to deserialization. The attack requ... Read more
Affected Products :- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Information Disclosure
-
5.8
MEDIUMCVE-2026-2969
A flaw has been found in datapizza-labs datapizza-ai 0.0.2. Affected is the function ChatPromptTemplate of the file datapizza-ai-core/datapizza/modules/prompt/prompt.py of the component Jinja2 Template Handler. This manipulation of the argument Prompt cau... Read more
Affected Products :- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Injection
-
8.5
HIGHCVE-2026-2998
ERP developed by eAI Technologies has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a crafted DLL file in the same directory as the program, thereby executing arbitrary code.... Read more
Affected Products :- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Misconfiguration
-
6.3
MEDIUMCVE-2026-2968
A vulnerability was detected in Cesanta Mongoose up to 7.20. This impacts the function mg_chacha20_poly1305_decrypt of the file /src/tls_chacha20.c of the component Poly1305 Authentication Tag Handler. The manipulation results in improper verification of ... Read more
Affected Products : mongoose- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Cryptography
-
6.3
MEDIUMCVE-2026-2967
A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This affects the function getpeer of the file /src/net_builtin.c of the component TCP Sequence Number Handler. The manipulation leads to improper verification of source of a commun... Read more
Affected Products : mongoose- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2026-2997
Tronclass developed by WisdomGarden has a Insecure Direct Object Reference vulnerability. After obtaining a course ID, authenticated remote attackers to modify a specific parameter to obtain a course invitation code, thereby joining any course.... Read more
Affected Products : tronclass- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Authorization
-
6.3
MEDIUMCVE-2026-2966
A weakness has been identified in Cesanta Mongoose up to 7.20. The impacted element is the function mg_sendnsreq of the file /src/dns.c of the component DNS Transaction ID Handler. Executing a manipulation of the argument random can lead to insufficiently... Read more
Affected Products : mongoose- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Cryptography
-
4.8
MEDIUMCVE-2026-2965
A security flaw has been discovered in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.9. The affected element is an unknown function of the file /admin/SysModule/edit.html of the component System Extension Module. Performing a manipulation of the argument Tit... Read more
Affected Products : customer_relationship_management- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Cross-Site Scripting