Latest CVE Feed
-
6.5
MEDIUMCVE-2026-2997
Tronclass developed by WisdomGarden has a Insecure Direct Object Reference vulnerability. After obtaining a course ID, authenticated remote attackers to modify a specific parameter to obtain a course invitation code, thereby joining any course.... Read more
Affected Products :- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Authorization
-
6.3
MEDIUMCVE-2026-2966
A weakness has been identified in Cesanta Mongoose up to 7.20. The impacted element is the function mg_sendnsreq of the file /src/dns.c of the component DNS Transaction ID Handler. Executing a manipulation of the argument random can lead to insufficiently... Read more
Affected Products :- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Cryptography
-
4.8
MEDIUMCVE-2026-2965
A security flaw has been discovered in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.9. The affected element is an unknown function of the file /admin/SysModule/edit.html of the component System Extension Module. Performing a manipulation of the argument Tit... Read more
Affected Products :- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Cross-Site Scripting
-
0.0
NACVE-2026-2968
A vulnerability was detected in Cesanta Mongoose up to 7.20. This impacts the function mg_chacha20_poly1305_decrypt of the file /src/tls_chacha20.c of the component Poly1305 Authentication Tag Handler. The manipulation results in improper verification of ... Read more
Affected Products :- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Cryptography
-
8.5
HIGHCVE-2026-2998
ERP developed by eAI Technologies has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a crafted DLL file in the same directory as the program, thereby executing arbitrary code.... Read more
Affected Products :- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Misconfiguration
-
0.0
NACVE-2026-2967
A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This affects the function getpeer of the file /src/net_builtin.c of the component TCP Sequence Number Handler. The manipulation leads to improper verification of source of a commun... Read more
Affected Products :- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Authentication
-
5.0
MEDIUMCVE-2026-2964
A vulnerability was identified in higuma web-audio-recorder-js 0.1/0.1.1. Impacted is the function extend in the library lib/WebAudioRecorder.js of the component Dynamic Config Handling. Such manipulation leads to improperly controlled modification of obj... Read more
Affected Products :- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2026-24494
SQL Injection vulnerability in the /api/integrations/getintegrations endpoint of Order Up Online Ordering System 1.0 allows an unauthenticated attacker to access sensitive backend database data via a crafted store_id parameter in a POST request.... Read more
Affected Products :- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2026-2963
A vulnerability was determined in Jinher OA C6 up to 20260210. This issue affects some unknown processing of the file /C6/Jhsoft.Web.officesupply/OfficeSupplyTypeRight.aspx. This manipulation of the argument id/offsnum causes sql injection. It is possible... Read more
Affected Products :- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Injection
-
9.0
HIGHCVE-2026-2962
A vulnerability was found in D-Link DWR-M960 1.01.07. This vulnerability affects the function sub_460F30 of the file /boafrm/formDateReboot of the component Scheduled Reboot Configuration Endpoint. The manipulation of the argument submit-url results in st... Read more
Affected Products :- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2026-2961
A vulnerability has been found in D-Link DWR-M960 1.01.07. This affects the function sub_4196C4 of the file /boafrm/formVpnConfigSetup of the component VPN Configuration Endpoint. The manipulation of the argument submit-url leads to stack-based buffer ove... Read more
Affected Products :- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2026-2960
A flaw has been found in D-Link DWR-M960 1.01.07. Affected by this issue is the function sub_468D64 of the file /boafrm/formDhcpv6s. Executing a manipulation of the argument submit-url can lead to stack-based buffer overflow. The attack can be executed re... Read more
Affected Products :- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2026-2959
A vulnerability was detected in D-Link DWR-M960 1.01.07. Affected by this vulnerability is the function sub_44E0F8 of the file /boafrm/formNewSchedule. Performing a manipulation of the argument url results in stack-based buffer overflow. Remote exploitati... Read more
Affected Products :- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2026-2958
A security vulnerability has been detected in D-Link DWR-M960 1.01.07. Affected is the function sub_457C5C of the file /boafrm/formWsc. Such manipulation of the argument save_apply leads to stack-based buffer overflow. The attack may be launched remotely.... Read more
Affected Products :- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Memory Corruption
-
0.0
NACVE-2026-2588
Crypt::NaCl::Sodium versions through 2.001 for Perl has an integer overflow flaw on 32-bit systems. Sodium.xs casts a STRLEN (size_t) to unsigned long long when passing a length pointer to libsodium functions. On 32-bit systems size_t is typically 32-bi... Read more
Affected Products :- Published: Feb. 23, 2026
- Modified: Feb. 23, 2026
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2026-2957
A weakness has been identified in qinming99 dst-admin up to 1.5.0. This impacts the function deleteBackup of the file src/main/java/com/tugos/dst/admin/controller/BackupController.java of the component File Handler. This manipulation causes denial of serv... Read more
Affected Products :- Published: Feb. 22, 2026
- Modified: Feb. 22, 2026
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2026-2956
A security flaw has been discovered in qinming99 dst-admin up to 1.5.0. This affects the function revertBackup of the file /home/restore. The manipulation of the argument Name results in command injection. The attack can be launched remotely. The exploit ... Read more
Affected Products :- Published: Feb. 22, 2026
- Modified: Feb. 22, 2026
- Vuln Type: Injection
-
8.8
HIGHCVE-2026-2447
Heap buffer overflow in libvpx. This vulnerability affects Firefox < 147.0.4, Firefox ESR < 140.7.1, Firefox ESR < 115.32.1, Thunderbird < 140.7.2, and Thunderbird < 147.0.2.... Read more
- Published: Feb. 16, 2026
- Modified: Feb. 22, 2026
- Vuln Type: Memory Corruption
-
7.2
HIGHCVE-2026-26930
SmarterTools SmarterMail before 9526 allows XSS via MAPI requests.... Read more
Affected Products : smartermail- Published: Feb. 16, 2026
- Modified: Feb. 22, 2026
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2026-2954
A vulnerability was found in Dromara UJCMS 10.0.2. Impacted is the function importChanel of the file /api/backend/ext/import-data/import-channel of the component ImportDataController. Performing a manipulation of the argument driverClassName/url results i... Read more
Affected Products : ujcms- Published: Feb. 22, 2026
- Modified: Feb. 22, 2026
- Vuln Type: Injection