Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-2608 — Gutenberg Blocks by Kadence Blocks <= 3.5.32 - Missing Authorization

The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and inc…

Remote | Authorization
Feb 17, 2026 Feb 18, 2026
Feb 17, 2026
Feb 18, 2026
8.3 HIGH
CVE-2026-2247 — SQL Injection in Clickedu's SaaS platform

SQL injection vulnerability (SQLi) in Clicldeu SaaS, specifically in the generation of reports, which occurs when a previously authenticated remote attacker executes a malicious payload in the URL ge…

Remote | Injection
Feb 17, 2026 Feb 18, 2026
Feb 17, 2026
Feb 18, 2026
6.5 MEDIUM
CVE-2025-8303 — XSS in EKA Software's Real Estate Script V5 (With Doping Module – Store Module – New Lang…

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EKA Software Computer Information Advertising Services Ltd. Real Estate Script V5 (With Do…

Remote | Cross-Site Scripting
Feb 17, 2026 Feb 18, 2026
Feb 17, 2026
Feb 18, 2026
8.6 HIGH
CVE-2025-7631 — Time-Based Blind SQLi in Tumeva Internet Technologies' Tumeva Prime News Software

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tumeva Internet Technologies Software Information Advertising and Consulting Services Trade Ltd. …

Remote | Injection
Feb 17, 2026 Mar 09, 2026
Feb 17, 2026
Mar 09, 2026
Showing 20 of 5544 Results