Latest CVE Feed
-
6.5
MEDIUMCVE-2026-2122
A security flaw has been discovered in Xiaopi Panel up to 20260126. This impacts an unknown function of the file /demo.php of the component WAF Firewall. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. Th... Read more
Affected Products :- Published: Feb. 08, 2026
- Modified: Feb. 08, 2026
- Vuln Type: Injection
-
8.3
HIGHCVE-2026-2120
A vulnerability was identified in D-Link DIR-823X 250416. This affects an unknown function of the file /goform/set_server_settings of the component Configuration Parameter Handler. The manipulation of the argument terminal_addr/server_ip/server_port leads... Read more
Affected Products :- Published: Feb. 08, 2026
- Modified: Feb. 08, 2026
- Vuln Type: Injection
-
8.3
HIGHCVE-2026-2118
A vulnerability was determined in UTT HiPER 810 1.7.4-141218. The impacted element is the function sub_4407D4 of the file /goform/formReleaseConnect of the component rehttpd. Executing a manipulation of the argument Isp_Name can lead to command injection.... Read more
Affected Products :- Published: Feb. 08, 2026
- Modified: Feb. 08, 2026
- Vuln Type: Injection
-
7.5
HIGHCVE-2026-2117
A vulnerability was found in itsourcecode Society Management System 1.0. The affected element is an unknown function of the file /admin/edit_activity.php. Performing a manipulation of the argument activity_id results in sql injection. The attack can be in... Read more
Affected Products :- Published: Feb. 08, 2026
- Modified: Feb. 08, 2026
- Vuln Type: Injection
-
7.5
HIGHCVE-2026-2116
A vulnerability has been found in itsourcecode Society Management System 1.0. Impacted is an unknown function of the file /admin/edit_expenses.php. Such manipulation of the argument expenses_id leads to sql injection. It is possible to launch the attack r... Read more
Affected Products :- Published: Feb. 08, 2026
- Modified: Feb. 08, 2026
- Vuln Type: Injection
-
7.5
HIGHCVE-2026-2115
A flaw has been found in itsourcecode Society Management System 1.0. This issue affects some unknown processing of the file /admin/delete_expenses.php. This manipulation of the argument expenses_id causes sql injection. It is possible to initiate the atta... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Injection
-
7.5
HIGHCVE-2026-2114
A vulnerability was detected in itsourcecode Society Management System 1.0. This vulnerability affects unknown code of the file /admin/edit_admin.php. The manipulation of the argument admin_id results in sql injection. The attack may be performed from rem... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Injection
-
7.1
HIGHCVE-2026-25859
Wekan versions prior to 8.20 allow non-administrative users to access migration functionality due to insufficient permission checks, potentially resulting in unauthorized migration operations.... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Authorization
-
9.3
CRITICALCVE-2026-25858
macrozheng mall version 1.0.3 and prior contains an authentication vulnerability in the mall-portal password reset workflow that allows an unauthenticated attacker to reset arbitrary user account passwords using only a victim’s telephone number. The passw... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Authentication
-
8.6
HIGHCVE-2026-25857
Tenda G300-F router firmware versio 16.01.14.2 and prior contain an OS command injection vulnerability in the WAN diagnostic functionality (formSetWanDiag). The implementation constructs a shell command that invokes curl and incorporates attacker-controll... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Injection
-
7.1
HIGHCVE-2026-25568
WeKan versions prior to 8.19 contain an authorization logic vulnerability where the instance configuration setting allowPrivateOnly is not sufficiently enforced at board creation time. When allowPrivateOnly is enabled, users can still create public boards... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2026-25567
WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in the card comment creation API. The endpoint accepts an authorId from the request body, allowing an authenticated user to spoof the recorded comment author by supplying anot... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Authentication
-
7.1
HIGHCVE-2026-25566
WeKan versions prior to 8.19 contain an authorization vulnerability in card move logic. A user can specify a destination board/list/swimlane without adequate authorization checks for the destination and without validating that destination objects belong t... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Authorization
-
7.1
HIGHCVE-2026-25565
WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only board read access rather than requiring write permission. This can allow users with read-only roles to perform card updates that should r... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Authorization
-
7.1
HIGHCVE-2026-25564
WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes. The implementation does not verify that the supplied cardId belongs to the supplied boardId, allowing cross-board ID tamper... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Authorization
-
7.1
HIGHCVE-2026-25563
WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes. The implementation does not verify that the supplied cardId belongs to the supplied boardId, allowing cross-board ID tamper... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2026-25562
WeKan versions prior to 8.19 contain an information disclosure vulnerability in the attachments publication. Attachment metadata can be returned without properly scoping results to boards and cards accessible to the requesting user, potentially exposing a... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Information Disclosure
-
7.1
HIGHCVE-2026-25561
WeKan versions prior to 8.19 contain an authorization weakness in the attachment upload API. The API does not fully validate that provided identifiers (such as boardId, cardId, swimlaneId, and listId) are consistent and refer to a coherent card/board rela... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Authorization
-
8.7
HIGHCVE-2026-25560
WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP authentication. User-supplied username input is incorporated into LDAP search filters and DN-related values without adequate escaping, allowing an attacker to manipulate L... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Injection
-
4.8
MEDIUMCVE-2025-15564
A vulnerability has been found in Mapnik up to 4.2.0. This vulnerability affects the function mapnik::detail::mod<...>::operator of the file src/value.cpp. The manipulation leads to divide by zero. The attack needs to be performed locally. The exploit has... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Denial of Service