Posts

Showing posts from February, 2026

CVE-2026-28554 - wpForo Forum 2.4.14 Missing Authorization via Post Approval AJAX Handler

CVE ID : CVE-2026-28554 Published : Feb. 28, 2026, 10:16 p.m. | 1 hour, 25 minutes ago Description : wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to approve or unapprove any forum post via the wpforo_approve_ajax AJAX handler. Attackers exploit the nonce-only check by submitting a valid nonce with an arbitrary post ID to bypass moderation controls entirely. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/alqOXJh via IFTTT

CVE-2025-69437 - PublicCMS Stored XSS in PDF Upload

CVE ID : CVE-2025-69437 Published : Feb. 27, 2026, 5:16 p.m. | 1 hour, 5 minutes ago Description : PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass PDF security checks in the backend CmsFileUtils.java. If a user uploads a PDF file containing a malicious payload to the system and views it, the embedded JavaScript payload can be triggered, resulting in issues such as credential theft, arbitrary API execution, and other security concerns. This vulnerability affects all file upload endpoint, including /cmsTemplate/save, /file/doUpload, /cmsTemplate/doUpload, /file/doBatchUpload, /cmsWebFile/doUpload, etc. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/kXfdJLK via IFTTT

CVE-2025-56605 - PuneethReddyHC Event Management System Reflected Cross-Site Scripting

CVE ID : CVE-2025-56605 Published : Feb. 26, 2026, 4:23 p.m. | 1 hour, 56 minutes ago Description : A reflected Cross-Site Scripting (XSS) vulnerability exists in the register.php backend script of PuneethReddyHC Event Management System 1.0. The mobile POST parameter is improperly validated and echoed back in the HTTP response without sanitization, allowing an attacker to inject and execute arbitrary JavaScript code in the victim's browser. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/4nPmdCX via IFTTT

CVE-2026-26228 - VLC for Android < 3.7.0 Remote Access Path Traversal

CVE ID : CVE-2026-26228 Published : Feb. 26, 2026, 3:21 p.m. | 58 minutes ago Description : VideoLAN VLC for Android prior to version 3.7.0 contains a path traversal vulnerability in the Remote Access Server routing for the authenticated endpoint GET /download. The file query parameter is concatenated into a filesystem path under the configured download directory without canonicalization or directory containment checks, allowing an authenticated attacker with network reachability to the Remote Access Server to request files outside the intended directory. The impact is bounded by the Android application sandbox and storage restrictions, typically limiting exposure to app-internal and app-specific external storage. Severity: 2.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/fLMkVQs via IFTTT

CVE-2026-20033 - Cisco NX-OS Software Denial of Service Vulnerability

CVE ID : CVE-2026-20033 Published : Feb. 25, 2026, 5:25 p.m. | 7 minutes ago Description : A vulnerability in Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation when processing specific Ethernet frames. An attacker could exploit this vulnerability by sending a crafted Ethernet frame to the management interface of an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition. Note: Only the out-of-band (OOB) management interface is affected. Severity: 7.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/iRZSAMP via IFTTT

CVE-2026-23678 - Binardat 10G08-0800GSM Network Switch Traceroute CLI Command Injection

CVE ID : CVE-2026-23678 Published : Feb. 24, 2026, 3:03 p.m. | 1 hour, 4 minutes ago Description : Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain a command injection vulnerability in the traceroute diagnostic function of the affected device web management interface. By injecting the %1a character into the hostname parameter, an authenticated attacker with access to the web interface can execute arbitrary CLI commands on the device. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/t1veog2 via IFTTT

CVE-2025-14905 - 389-ds-base: 389-ds-base: remote code execution and denial of service via heap buffer overflow

CVE ID : CVE-2025-14905 Published : Feb. 23, 2026, 4:29 p.m. | 1 hour, 31 minutes ago Description : A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callback` function within the `schema.c` file. This occurs because the code incorrectly calculates the buffer size by summing alias string lengths without accounting for additional formatting characters. When a large number of aliases are processed, this oversight can lead to a heap overflow, potentially allowing a remote attacker to cause a Denial of Service (DoS) or achieve Remote Code Execution (RCE). Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/fQcysbq via IFTTT

CVE-2026-2956 - qinming99 dst-admin restore revertBackup command injection

CVE ID : CVE-2026-2956 Published : Feb. 22, 2026, 10:15 p.m. | 1 hour, 44 minutes ago Description : A security flaw has been discovered in qinming99 dst-admin up to 1.5.0. This affects the function revertBackup of the file /home/restore. The manipulation of the argument Name results in command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/sugSWCO via IFTTT

CVE-2026-2872 - Tenda A21 MAC Filtering Configuration Endpoint setBlackRule set_device_name stack-based overflow

CVE ID : CVE-2026-2872 Published : Feb. 21, 2026, 4:16 p.m. | 1 hour, 40 minutes ago Description : A security vulnerability has been detected in Tenda A21 1.0.0.0. This vulnerability affects the function set_device_name of the file /goform/setBlackRule of the component MAC Filtering Configuration Endpoint. Such manipulation of the argument devName/mac leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/q0KpwE3 via IFTTT

CVE-2026-26095 - Incorrect Permission Assignment for Critical Resource in Owl opds

CVE ID : CVE-2026-26095 Published : Feb. 20, 2026, 5:25 p.m. | 27 minutes ago Description : Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File Manipulation via a crafted network request. Severity: 8.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/gTbf7WY via IFTTT

CVE-2026-23604 - GFI MailEssentials AI < 22.4 Keyword Filtering Rule Stored XSS

CVE ID : CVE-2026-23604 Published : Feb. 19, 2026, 6:24 p.m. | 14 minutes ago Description : GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Keyword Filtering rule creation workflow. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv1$TXB_RuleName parameter to /MailEssentials/pages/MailSecurity/contentchecking.aspx, which is stored and later rendered in the management interface, allowing script execution in the context of a logged-in user. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/yCUWspN via IFTTT

CVE-2025-13602 - Apache Remote Code Execution

CVE ID : CVE-2025-13602 Published : Feb. 18, 2026, 5:21 p.m. | 1 hour, 16 minutes ago Description : Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/U8kBns6 via IFTTT

CVE-2024-55271 - PhpGurukul Gym Management System CSRF Vulnerability

CVE ID : CVE-2024-55271 Published : Feb. 17, 2026, 5:21 p.m. | 1 hour, 14 minutes ago Description : A Cross-Site Request Forgery (CSRF) vulnerability has been identified in phpgurukul Gym Management System 1.0. This issue is present in the profile update functionality of the User Panel, specifically the /profile.php endpoint. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/RoJH5Kk via IFTTT

CVE-2026-26930 - SmarterTools SmarterMail MAPI Cross-Site Scripting Vulnerability

CVE ID : CVE-2026-26930 Published : Feb. 16, 2026, 5:18 p.m. | 1 hour, 14 minutes ago Description : SmarterTools SmarterMail before 9526 allows XSS via MAPI requests. Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/9dwojSK via IFTTT

CVE-2026-2523 - Open5GS SMF gn-handler.c smf_gn_handle_create_pdp_context_request assertion

CVE ID : CVE-2026-2523 Published : Feb. 16, 2026, 1:15 a.m. | 1 hour, 16 minutes ago Description : A vulnerability was detected in Open5GS up to 2.7.6. The affected element is the function smf_gn_handle_create_pdp_context_request of the file /src/smf/gn-handler.c of the component SMF. The manipulation results in reachable assertion. It is possible to launch the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/Fl0EA6i via IFTTT

CVE-2026-2521 - Open5GS SGW-C sgwc_s5c_handle_create_session_response memory corruption

CVE ID : CVE-2026-2521 Published : Feb. 15, 2026, 11:16 p.m. | 1 hour, 15 minutes ago Description : A weakness has been identified in Open5GS up to 2.7.6. This issue affects the function sgwc_s5c_handle_create_session_response of the component SGW-C. Executing a manipulation can lead to memory corruption. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/FgjvtoW via IFTTT

CVE-2026-23189 - ceph: fix NULL pointer dereference in ceph_mds_auth_match()

CVE ID : CVE-2026-23189 Published : Feb. 14, 2026, 5:15 p.m. | 1 hour, 14 minutes ago Description : In the Linux kernel, the following vulnerability has been resolved: ceph: fix NULL pointer dereference in ceph_mds_auth_match() The CephFS kernel client has regression starting from 6.18-rc1. We have issue in ceph_mds_auth_match() if fs_name == NULL: const char fs_name = mdsc->fsc->mount_options->mds_namespace; ... if (auth->match.fs_name && strcmp(auth->match.fs_name, fs_name)) { / fsname mismatch, try next one */ return 0; } Patrick Donnelly suggested that: In summary, we should definitely start decoding `fs_name` from the MDSMap and do strict authorizations checks against it. Note that the `-o mds_namespace=foo` should only be used for selecting the file system to mount and nothing else. It's possible no mds_namespace is specified but the kernel will mount the only file system that exists which may have name "foo". This patch reworks ceph_mdsm...

CVE-2026-23188 - net: usb: r8152: fix resume reset deadlock

CVE-2026-23187 - pmdomain: imx8m-blk-ctrl: fix out-of-range access of bc->domains

CVE ID : CVE-2026-23187 Published : Feb. 14, 2026, 5:15 p.m. | 1 hour, 14 minutes ago Description : In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx8m-blk-ctrl: fix out-of-range access of bc->domains Fix out-of-range access of bc->domains in imx8m_blk_ctrl_remove(). Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/nTDAM3z via IFTTT

CVE-2026-23186 - hwmon: (acpi_power_meter) Fix deadlocks related to acpi_power_meter_notify()

CVE ID : CVE-2026-23186 Published : Feb. 14, 2026, 5:15 p.m. | 1 hour, 14 minutes ago Description : In the Linux kernel, the following vulnerability has been resolved: hwmon: (acpi_power_meter) Fix deadlocks related to acpi_power_meter_notify() The acpi_power_meter driver's .notify() callback function, acpi_power_meter_notify(), calls hwmon_device_unregister() under a lock that is also acquired by callbacks in sysfs attributes of the device being unregistered which is prone to deadlocks between sysfs access and device removal. Address this by moving the hwmon device removal in acpi_power_meter_notify() outside the lock in question, but notice that doing it alone is not sufficient because two concurrent METER_NOTIFY_CONFIG notifications may be attempting to remove the same device at the same time. To prevent that from happening, add a new lock serializing the execution of the switch () statement in acpi_power_meter_notify(). For simplicity, it is a static mutex which shoul...

CVE-2026-2026 - Improper Access Control Allows Denial of Service

CVE ID : CVE-2026-2026 Published : Feb. 13, 2026, 4:14 p.m. | 1 hour, 14 minutes ago Description : A vulnerability has been identified where weak file permissions in the Nessus Agent directory on Windows hosts could allow unauthorized access, potentially permitting Denial of Service (DoS) attacks. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/SE6LP5e via IFTTT

CVE-2025-56647 - Farmfe Core Origin Validation Bypass (WebSocket)

CVE ID : CVE-2025-56647 Published : Feb. 12, 2026, 4:16 p.m. | 1 hour, 12 minutes ago Description : npm @farmfe/core before 1.7.6 is Missing Origin Validation in WebSocket. The development (hot module reloading) server does not validate origin when connecting to a WebSocket client. This allows attackers to surveil developers running Farm who visit their webpage and steal source code that is leaked by the WebSocket server. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/ODyG0WJ via IFTTT

CVE-2026-25084 - ZLAN Information Technology ZLAN5143D Missing Authentication for Critical Function

CVE ID : CVE-2026-25084 Published : Feb. 11, 2026, 4:11 p.m. | 1 hour, 16 minutes ago Description : Authentication for ZLAN5143D can be bypassed by directly accessing internal URLs. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/vF6La1g via IFTTT

CVE-2025-31655 - Intel Battery Life Diagnostic Tool Privilege Escalation Vulnerability

CVE ID : CVE-2025-31655 Published : Feb. 10, 2026, 5:16 p.m. | 58 minutes ago Description : Incorrect default permissions for some Intel(R) Battery Life Diagnostic Tool within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts. Severity: 6.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/mN3veg8 via IFTTT

CVE-2026-2241 - janet-lang janet os.c os_strftime out-of-bounds

CVE ID : CVE-2026-2241 Published : Feb. 9, 2026, 4:02 p.m. | 1 hour, 15 minutes ago Description : A vulnerability was found in janet-lang janet up to 1.40.1. This affects the function os_strftime of the file src/core/os.c. Performing a manipulation results in out-of-bounds read. The attack must be initiated from a local position. The exploit has been made public and could be used. The patch is named 0f285855f0e34f9183956be5f16e045f54626bff. To fix this issue, it is recommended to deploy a patch. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/GxIX7sS via IFTTT

CVE-2025-63354 - Hitron HI3120 Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-63354 Published : Feb. 9, 2026, 3:16 p.m. | 55 minutes ago Description : Hitron HI3120 v7.2.4.5.2b1 allows stored XSS via the Parental Control option when creating a new filter. The device fails to properly handle inputs, allowing an attacker to inject and execute JavaScript. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/81wfB2s via IFTTT

CVE-2026-2161 - itsourcecode Directory Management System forget-password.php sql injection

CVE ID : CVE-2026-2161 Published : Feb. 8, 2026, 4:15 p.m. | 1 hour, 48 minutes ago Description : A vulnerability was found in itsourcecode Directory Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/forget-password.php. The manipulation of the argument email results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/5TQHm7V via IFTTT

CVE-2026-2107 - yeqifu warehouse Log Info LoginfoController.java batchDeleteLoginfo improper authorization

CVE ID : CVE-2026-2107 Published : Feb. 7, 2026, 7:15 p.m. | 45 minutes ago Description : A vulnerability was found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function loadAllLoginfo/deleteLoginfo/batchDeleteLoginfo of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\LoginfoController.java of the component Log Info Handler. The manipulation results in improper authorization. The attack can be launched remotely. The exploit has been made public and could be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/ELepf4S via IFTTT

CVE-2026-2105 - yeqifu warehouse Department Management DeptController.java deleteDept improper authorization

CVE ID : CVE-2026-2105 Published : Feb. 7, 2026, 5:15 p.m. | 45 minutes ago Description : A flaw has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. The affected element is the function addDept/updateDept/deleteDept of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\DeptController.java of the component Department Management. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been published and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/Do7kVvR via IFTTT

CVE-2025-13523 - Cross-Site Scripting (XSS) via Unescaped Display Names in Mattermost Confluence Plugin OAuth2 Flow

CVE ID : CVE-2025-13523 Published : Feb. 6, 2026, 4:16 p.m. | 1 hour, 43 minutes ago Description : Mattermost Confluence plugin version <1.7.0 fails to properly escape user-controlled display names in HTML template rendering which allows authenticated Confluence users with malicious display names to execute arbitrary JavaScript in victim browsers via sending a specially crafted OAuth2 connection link that, when visited, renders the attacker's display name without proper sanitization. Mattermost Advisory ID: MMSA-2025-00557 Severity: 7.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/648KFmR via IFTTT

CVE-2020-37132 - UltraVNC Launcher 1.2.4.0 - 'Password' Denial of Service

CVE ID : CVE-2020-37132 Published : Feb. 5, 2026, 5:16 p.m. | 41 minutes ago Description : UltraVNC Launcher 1.2.4.0 contains a denial of service vulnerability in its password configuration properties that allows local attackers to crash the application. Attackers can paste an overly long 300-character string into the password field to trigger an application crash and prevent normal launcher functionality. Severity: 6.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/raKNtP1 via IFTTT

CVE-2026-23094 - uacce: fix isolate sysfs check condition

CVE ID : CVE-2026-23094 Published : Feb. 4, 2026, 5:16 p.m. | 39 minutes ago Description : In the Linux kernel, the following vulnerability has been resolved: uacce: fix isolate sysfs check condition uacce supports the device isolation feature. If the driver implements the isolate_err_threshold_read and isolate_err_threshold_write callback functions, uacce will create sysfs files now. Users can read and configure the isolation policy through sysfs. Currently, sysfs files are created as long as either isolate_err_threshold_read or isolate_err_threshold_write callback functions are present. However, accessing a non-existent callback function may cause the system to crash. Therefore, intercept the creation of sysfs if neither read nor write exists; create sysfs if either is supported, but intercept unsupported operations at the call site. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabili...

CVE-2020-37105 - PMB 5.6 - 'logid' SQL Injection

CVE ID : CVE-2020-37105 Published : Feb. 3, 2026, 4:52 p.m. | 59 minutes ago Description : PMB 5.6 contains a SQL injection vulnerability in the administration download script that allows authenticated attackers to execute arbitrary SQL commands through the 'logid' parameter. Attackers can leverage this vulnerability by sending crafted requests to the /admin/sauvegarde/download.php endpoint with manipulated logid values to interact with the database. Severity: 7.1 | HIGH

CVE-2026-0630 - Command Injection Vulnerability on TP-Link Archer BE230 v1.2

CVE ID : CVE-2026-0630 Published : Feb. 2, 2026, 6:16 p.m. | 1 hour, 34 minutes ago Description : An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) allows adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration integrity, network security, and service availability. This CVE covers one of multiple distinct OS command injection issues identified across separate code paths. Although similar in nature, each instance is tracked under a unique CVE ID.This issue affects Archer BE230 v1.2 < 1.2.4 Build 20251218 rel.70420. Severity: 8.5 | HIGH

CVE-2026-1770 - Improper Control of Dynamically-Managed Code Resources in Crafter Studio

CVE ID : CVE-2026-1770 Published : Feb. 2, 2026, 5:16 p.m. | 34 minutes ago Description : Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass. By inserting malicious Groovy elements, an attacker may bypass sandbox restrictions and obtain RCE (Remote Code Execution). Severity: 4.5 | MEDIUM

CVE-2026-0921 - Apache HTTP Server Remote Code Execution

CVE ID : CVE-2026-0921 Published : Feb. 2, 2026, 5:16 p.m. | 34 minutes ago Description : Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

CVE-2026-1737 - Open5GS CreateBearerRequest s5c-handler.c sgwc_s5c_handle_create_bearer_request assertion

CVE ID : CVE-2026-1737 Published : Feb. 2, 2026, 1:02 a.m. | 46 minutes ago Description : A vulnerability was detected in Open5GS up to 2.7.6. The affected element is the function sgwc_s5c_handle_create_bearer_request of the file /src/sgwc/s5c-handler.c of the component CreateBearerRequest Handler. Performing a manipulation results in reachable assertion. Remote exploitation of the attack is possible. The exploit is now public and may be used. To fix this issue, it is recommended to deploy a patch. The issue report is flagged as already-fixed.

CVE-2026-1733 - Zhong Bang CRMEB :uni tidyOrder improper authorization

CVE ID : CVE-2026-1733 Published : Feb. 1, 2026, 11:15 p.m. | 32 minutes ago Description : A vulnerability was identified in Zhong Bang CRMEB up to 5.6.3. This affects the function detail/tidyOrder of the file /api/store_integral/order/detail/:uni. The manipulation of the argument order_id leads to improper authorization. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.3 | MEDIUM

CVE-2021-47856 - Easy Cart Shopping Cart 2021 Cross-Site Scripting via Search Parameter

CVE ID : CVE-2021-47856 Published : Feb. 1, 2026, 1:15 p.m. | 30 minutes ago Description : Easy Cart Shopping Cart 2021 contains a non-persistent cross-site scripting vulnerability in the search module's keyword parameter. Remote attackers can inject malicious script code through the search input to compromise user sessions and manipulate application content. Severity: 6.4 | MEDIUM