Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-2094 — Flowring|Docpedia - SQL Injection

Docpedia developed by Flowring has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

Remote | Injection
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
8.7 HIGH
CVE-2026-2093 — Flowring|Docpedia - SQL Injection

Docpedia developed by Flowring has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

Remote | Injection
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
5.7 MEDIUM
CVE-2025-12063 — Apache Data Object Reference Bypass

An insecure direct object reference allowed a non-admin user to modify or remove certain data objects without having the appropriate permissions.

Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
6.4 MEDIUM
CVE-2026-0996 — Fluent Forms <= 6.1.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting via AI F…

The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the AI Form Builder module in all versions up to, and including, 6.1.14 due to a combination of missing authoriz…

contact_form | Remote | Cross-Site Scripting
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
4.5 MEDIUM
CVE-2025-13064 — Apache HTTP Server Cross-Site Scripting (XSS)

A server-side injection was possible for a malicious admin to manipulate the application to include a malicious script which is executed by the server. This attack is only possible if the admin uses …

Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
4.6 MEDIUM
CVE-2025-12757 — AXIS Camera Station Pro Information Disclosure

An AXIS Camera Station Pro feature can be exploited in a way that allows a non-admin user to view information they are not permitted to.

Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
7.8 HIGH
CVE-2025-11547 — AXIS Camera Station Pro Privilege Escalation Vulnerability

AXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin user.

Feb 10, 2026 Feb 17, 2026
Feb 10, 2026
Feb 17, 2026
8.8 HIGH
CVE-2025-11142 — VAPIX API Mediaclip.cgi Remote Code Execution Vulnerability

The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with an operator- or ad…

axis_os axis_os | Remote | Injection
Feb 10, 2026 Feb 28, 2026
Feb 10, 2026
Feb 28, 2026
Showing 20 of 5508 Results