📅 Weekly CVE Roundup

February 2 - February 8, 2026

100 Total CVEs
15 Critical
49 High
36 Medium

🔴 Critical & High Severity Vulnerabilities

These are the most dangerous vulnerabilities disclosed this week. Prioritize patching these.

CVE-2026-25142 10.0

CVE-2026-25142 is a critical sandbox escape vulnerability in SandboxJS library versions before 0.8.27. Attackers can use the __lookupGetter__ method t...

Feb 2
CVE-2026-23515 9.9

Signal K Server versions before 1.5.0 contain a command injection vulnerability in the set-system-time plugin that allows authenticated users with wri...

Feb 2
CVE-2025-5329 9.8

This SQL injection vulnerability in Martcode Software's Delta Course Automation allows attackers to execute arbitrary SQL commands on the database. Al...

Feb 4
CVE-2026-25200 9.8

A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without proper authentication, leading to stored cross-site scriptin...

Feb 2
CVE-2026-25202 9.8

MagicINFO 9 Server versions below 21.1090.1 contain hardcoded database credentials, allowing attackers to authenticate and manipulate the database. Th...

Feb 2
CVE-2025-15030 9.8

The User Profile Builder WordPress plugin before version 3.15.2 has an improper password reset mechanism that allows unauthenticated attackers to rese...

Feb 2
CVE-2026-20418 9.8

CVE-2026-20418 is a critical out-of-bounds write vulnerability in Thread protocol implementations that allows remote attackers to execute arbitrary co...

Feb 2
CVE-2022-50981 9.8

CVE-2022-50981 allows unauthenticated remote attackers to gain full administrative access to affected devices because they ship without a default pass...

Feb 2
CVE-2026-22778 9.8

This vulnerability in vLLM allows attackers to leak heap memory addresses by sending invalid images to the multimodal endpoint, which reduces ASLR ent...

Feb 2
CVE-2026-24465 9.8

A stack-based buffer overflow vulnerability in ELECOM wireless LAN access point devices allows remote attackers to execute arbitrary code by sending s...

Feb 3
CVE-2024-2356 9.6

This CVE describes a Local File Inclusion vulnerability in the lollms-webui application that allows attackers to execute arbitrary Python code remotel...

Feb 2
CVE-2024-5386 9.6

In lunary-ai/lunary version 1.2.2, a privilege escalation vulnerability allows users with 'viewer' role to hijack other user accounts by obtaining pas...

Feb 2
CVE-2026-20407 9.3

This CVE describes a privilege escalation vulnerability in MediaTek wlan STA drivers where missing bounds checks allow local attackers to gain elevate...

Feb 2
CVE-2024-5986 9.1

This vulnerability in h2o-3 allows remote attackers to write arbitrary data to any file on the server, potentially leading to remote code execution an...

Feb 2
CVE-2026-25137 9.1

The NixOS Odoo package exposes the database manager without authentication, allowing unauthorized actors to delete or download the entire database and...

Feb 2
CVE-2026-20408 8.8

This CVE describes a heap buffer overflow vulnerability in wlan (wireless LAN) components that allows remote attackers to execute arbitrary code witho...

Feb 2
CVE-2025-15368 8.8

The SportsPress WordPress plugin has a Local File Inclusion vulnerability in all versions up to 2.7.26. Authenticated attackers with contributor-level...

Feb 4
CVE-2026-24788 8.8

CVE-2026-24788 is an OS command injection vulnerability in RaspAP raspap-webgui that allows authenticated users to execute arbitrary commands on the u...

Feb 2
CVE-2026-25201 8.8

An unauthenticated attacker can upload arbitrary files to MagicInfo9 Server, leading to remote code execution and privilege escalation. This affects M...

Feb 2
CVE-2026-24070 8.8

This vulnerability allows local privilege escalation on macOS systems running Native Access. A low-privileged user can exploit DYLIB injection in the ...

Feb 2
CVE-2022-50975 8.8

This vulnerability allows an unauthenticated remote attacker to hijack existing user sessions and gain full administrative access to affected devices....

Feb 2
CVE-2026-24763 8.8

OpenClaw (formerly Clawdbot) versions prior to 2026.1.29 contain a command injection vulnerability in the Docker sandbox execution mechanism. Authenti...

Feb 2
CVE-2026-25059 8.8

OpenList Frontend versions before 4.1.10 contain a path traversal vulnerability in file operation handlers that allows authenticated attackers to bypa...

Feb 2
CVE-2025-8587 8.6

This SQL injection vulnerability in AKCE Software's SKSPro allows attackers to execute arbitrary SQL commands on the database. All SKSPro installation...

Feb 2
CVE-2026-1761 8.6

A stack-based buffer overflow vulnerability in libsoup allows remote attackers to execute arbitrary code or crash applications by sending specially cr...

Feb 2
CVE-2026-1117 8.2

This vulnerability allows unauthenticated attackers to trigger resource-intensive text generation operations and manipulate server state in the lollms...

Feb 2
CVE-2026-1530 8.1

A vulnerability in fog-kubevirt allows remote attackers to perform Man-in-the-Middle attacks by intercepting communications between Satellite and Open...

Feb 2
CVE-2026-1531 8.1

This vulnerability in foreman_kubevirt disables SSL certificate verification by default when connecting to OpenShift without an explicitly set CA cert...

Feb 2
CVE-2026-24737 8.1

This vulnerability in jsPDF allows attackers to inject arbitrary PDF objects, including JavaScript actions, through user-controlled input to specific ...

Feb 2
CVE-2026-25060 8.1

OpenList Frontend versions before 4.1.10 have TLS certificate verification disabled by default for storage communications, allowing Man-in-the-Middle ...

Feb 2
CVE-2025-9974 8.0

CVE-2025-9974 is an OS command injection vulnerability in the unified WEBUI application of Nokia ONT/Beacon devices. Authenticated attackers with low ...

Feb 2
CVE-2026-23997 8.0

A stored XSS vulnerability in FacturaScripts allows attackers to inject malicious JavaScript into the Observations field, which executes when administ...

Feb 2
CVE-2026-20409 7.8

CVE-2026-20409 is an out-of-bounds write vulnerability in the imgsys component that allows local privilege escalation. Attackers with initial System p...

Feb 2
CVE-2026-20411 7.8

This CVE describes a use-after-free vulnerability in the cameraisp component that could allow local privilege escalation. Attackers with System privil...

Feb 2
CVE-2026-20412 7.8

CVE-2026-20412 is an out-of-bounds write vulnerability in the cameraisp component that allows local privilege escalation. Attackers with initial Syste...

Feb 2
CVE-2026-24071 7.8

This vulnerability allows attackers to bypass code signature verification in Native Access's XPC service on macOS through PID reuse attacks. An attack...

Feb 2
CVE-2026-24694 7.8

This vulnerability allows attackers to execute arbitrary code by exploiting insecure DLL loading in Roland Cloud Manager. Attackers can plant maliciou...

Feb 3
CVE-2022-50976 7.7

This vulnerability allows a local attacker with physical USB access to cause a full device reset by using an invalid reset file. It affects devices th...

Feb 2
CVE-2025-14914 7.6

This vulnerability allows a privileged user in IBM WebSphere Application Server Liberty to upload a zip archive containing path traversal sequences, w...

Feb 2
CVE-2025-8589 7.6

This CVE describes a reflected cross-site scripting (XSS) vulnerability in AKCE Software's SKSPro product. Attackers can inject malicious scripts into...

Feb 3
CVE-2026-20401 7.5

This vulnerability allows remote denial of service attacks against mobile devices with affected MediaTek modems. An attacker can crash the system by c...

Feb 2
CVE-2026-20402 7.5

This vulnerability in MediaTek modems allows remote denial of service through improper input validation. Attackers can crash affected devices by conne...

Feb 2
CVE-2026-20403 7.5

This vulnerability in MediaTek modems allows remote denial of service via system crash when a device connects to a malicious base station. Attackers c...

Feb 2
CVE-2026-20404 7.5

This vulnerability in MediaTek modems allows remote denial of service through improper input validation. An attacker can crash the system by connectin...

Feb 2
CVE-2026-20405 7.5

This vulnerability in MediaTek modems allows remote denial of service through system crashes when devices connect to rogue base stations. Attackers ca...

Feb 2
CVE-2026-20406 7.5

This vulnerability allows remote denial of service attacks against devices with affected MediaTek modems. An attacker can crash the system by connecti...

Feb 2
CVE-2026-20419 7.5

This vulnerability in MediaTek wlan AP/STA firmware allows remote attackers within wireless range to cause denial of service by making the system unre...

Feb 2
CVE-2026-20420 7.5

This vulnerability in MediaTek modems allows remote denial of service through system crashes when devices connect to rogue base stations. Attackers ca...

Feb 2
CVE-2026-20421 7.5

This vulnerability allows remote attackers to cause a system crash (denial of service) in affected modem devices by connecting to a rogue base station...

Feb 2
CVE-2026-20422 7.5

This vulnerability in MediaTek modems allows remote denial of service through improper input validation. An attacker can crash the system by connectin...

Feb 2
CVE-2024-54263 7.5

This CVE describes a PHP Local File Inclusion vulnerability in the Talemy Spirit Framework WordPress plugin. Attackers can exploit improper filename c...

Feb 2
CVE-2024-4147 7.5

This vulnerability allows authenticated users in lunary-ai/lunary to delete prompts belonging to other organizations through ID manipulation. The appl...

Feb 2
CVE-2026-0599 7.5

This vulnerability in huggingface/text-generation-inference allows unauthenticated attackers to trigger resource exhaustion by exploiting unbounded ex...

Feb 2
CVE-2022-50977 7.5

CVE-2022-50977 allows unauthenticated remote attackers to disrupt operations by switching between multiple configuration presets via HTTP requests. Th...

Feb 2
CVE-2022-50978 7.5

This vulnerability allows unauthenticated remote attackers to disrupt operations by switching between multiple configuration presets via Modbus TCP. I...

Feb 2
CVE-2026-1740 7.3

This vulnerability allows remote attackers to bypass authentication on EFM ipTIME A8004T routers via improper authentication in the Hidden Hiddenlogin...

Feb 2
CVE-2026-1777 7.2

The Amazon SageMaker Python SDK before v3.2.0 and v2.256.0 exposes the ModelBuilder HMAC signing key in cleartext via the DescribeTrainingJob API. Thi...

Feb 2
CVE-2026-0617 7.2

This stored XSS vulnerability in the LatePoint WordPress plugin allows unauthenticated attackers to inject malicious scripts into customer profile fie...

Feb 3
CVE-2026-1065 7.2

The Form Maker by 10Web WordPress plugin allows unauthenticated attackers to upload malicious SVG files containing JavaScript code due to weak file ex...

Feb 3
CVE-2026-22550 7.2

An OS command injection vulnerability in ELECOM WRC-X1500GS-B and WRC-X1500GSA-B wireless routers allows authenticated attackers to execute arbitrary ...

Feb 3
CVE-2025-15396 7.1

The Library Viewer WordPress plugin before version 3.2.0 contains a reflected cross-site scripting (XSS) vulnerability where unsanitized parameters ar...

Feb 2
CVE-2026-1058 7.1

The Form Maker WordPress plugin has a stored XSS vulnerability in versions up to 1.15.35. Unauthenticated attackers can inject malicious JavaScript in...

Feb 3
CVE-2025-10279 7.0

This CVE describes a local privilege escalation vulnerability in mlflow versions before 3.4.0 where temporary directories for Python virtual environme...

Feb 2
CVE-2026-24051 7.0

OpenTelemetry-Go SDK versions v1.20.0 through v1.39.0 on macOS/Darwin systems are vulnerable to path hijacking attacks. An attacker with local access ...

Feb 2

🏢 Most Affected Vendors

Mediatek 12 CVEs
Google 9 CVEs
Openwrt 2 CVEs
Gitlab 1 CVEs

🐛 Common Vulnerability Types

CWE-79 36 occurrences
CWE-787 10 occurrences
CWE-295 7 occurrences
CWE-352 6 occurrences
CWE-78 6 occurrences

📋 All CVEs This Week

CVE-2026-25142 10.0

CVE-2026-25142 is a critical sandbox escape vulnerability in SandboxJS library versions before 0.8.27. Attackers can use...

CVE-2026-23515 9.9

Signal K Server versions before 1.5.0 contain a command injection vulnerability in the set-system-time plugin that allow...

CVE-2025-5329 9.8

This SQL injection vulnerability in Martcode Software's Delta Course Automation allows attackers to execute arbitrary SQ...

CVE-2026-25200 9.8

A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without proper authentication, leading...

CVE-2026-25202 9.8

MagicINFO 9 Server versions below 21.1090.1 contain hardcoded database credentials, allowing attackers to authenticate a...

CVE-2025-15030 9.8

The User Profile Builder WordPress plugin before version 3.15.2 has an improper password reset mechanism that allows una...

CVE-2026-20418 9.8

CVE-2026-20418 is a critical out-of-bounds write vulnerability in Thread protocol implementations that allows remote att...

CVE-2022-50981 9.8

CVE-2022-50981 allows unauthenticated remote attackers to gain full administrative access to affected devices because th...

CVE-2026-22778 9.8

This vulnerability in vLLM allows attackers to leak heap memory addresses by sending invalid images to the multimodal en...

CVE-2026-24465 9.8

A stack-based buffer overflow vulnerability in ELECOM wireless LAN access point devices allows remote attackers to execu...

CVE-2024-2356 9.6

This CVE describes a Local File Inclusion vulnerability in the lollms-webui application that allows attackers to execute...

CVE-2024-5386 9.6

In lunary-ai/lunary version 1.2.2, a privilege escalation vulnerability allows users with 'viewer' role to hijack other ...

CVE-2026-20407 9.3

This CVE describes a privilege escalation vulnerability in MediaTek wlan STA drivers where missing bounds checks allow l...

CVE-2024-5986 9.1

This vulnerability in h2o-3 allows remote attackers to write arbitrary data to any file on the server, potentially leadi...

CVE-2026-25137 9.1

The NixOS Odoo package exposes the database manager without authentication, allowing unauthorized actors to delete or do...

CVE-2026-20408 8.8

This CVE describes a heap buffer overflow vulnerability in wlan (wireless LAN) components that allows remote attackers t...

CVE-2025-15368 8.8

The SportsPress WordPress plugin has a Local File Inclusion vulnerability in all versions up to 2.7.26. Authenticated at...

CVE-2026-24788 8.8

CVE-2026-24788 is an OS command injection vulnerability in RaspAP raspap-webgui that allows authenticated users to execu...

CVE-2026-25201 8.8

An unauthenticated attacker can upload arbitrary files to MagicInfo9 Server, leading to remote code execution and privil...

CVE-2026-24070 8.8

This vulnerability allows local privilege escalation on macOS systems running Native Access. A low-privileged user can e...

CVE-2022-50975 8.8

This vulnerability allows an unauthenticated remote attacker to hijack existing user sessions and gain full administrati...

CVE-2026-24763 8.8

OpenClaw (formerly Clawdbot) versions prior to 2026.1.29 contain a command injection vulnerability in the Docker sandbox...

CVE-2026-25059 8.8

OpenList Frontend versions before 4.1.10 contain a path traversal vulnerability in file operation handlers that allows a...

CVE-2025-8587 8.6

This SQL injection vulnerability in AKCE Software's SKSPro allows attackers to execute arbitrary SQL commands on the dat...

CVE-2026-1761 8.6

A stack-based buffer overflow vulnerability in libsoup allows remote attackers to execute arbitrary code or crash applic...

CVE-2026-1117 8.2

This vulnerability allows unauthenticated attackers to trigger resource-intensive text generation operations and manipul...

CVE-2026-1530 8.1

A vulnerability in fog-kubevirt allows remote attackers to perform Man-in-the-Middle attacks by intercepting communicati...

CVE-2026-1531 8.1

This vulnerability in foreman_kubevirt disables SSL certificate verification by default when connecting to OpenShift wit...

CVE-2026-24737 8.1

This vulnerability in jsPDF allows attackers to inject arbitrary PDF objects, including JavaScript actions, through user...

CVE-2026-25060 8.1

OpenList Frontend versions before 4.1.10 have TLS certificate verification disabled by default for storage communication...

CVE-2025-9974 8.0

CVE-2025-9974 is an OS command injection vulnerability in the unified WEBUI application of Nokia ONT/Beacon devices. Aut...

CVE-2026-23997 8.0

A stored XSS vulnerability in FacturaScripts allows attackers to inject malicious JavaScript into the Observations field...

CVE-2026-20409 7.8

CVE-2026-20409 is an out-of-bounds write vulnerability in the imgsys component that allows local privilege escalation. A...

CVE-2026-20411 7.8

This CVE describes a use-after-free vulnerability in the cameraisp component that could allow local privilege escalation...

CVE-2026-20412 7.8

CVE-2026-20412 is an out-of-bounds write vulnerability in the cameraisp component that allows local privilege escalation...

CVE-2026-24071 7.8

This vulnerability allows attackers to bypass code signature verification in Native Access's XPC service on macOS throug...

CVE-2026-24694 7.8

This vulnerability allows attackers to execute arbitrary code by exploiting insecure DLL loading in Roland Cloud Manager...

CVE-2022-50976 7.7

This vulnerability allows a local attacker with physical USB access to cause a full device reset by using an invalid res...

CVE-2025-14914 7.6

This vulnerability allows a privileged user in IBM WebSphere Application Server Liberty to upload a zip archive containi...

CVE-2025-8589 7.6

This CVE describes a reflected cross-site scripting (XSS) vulnerability in AKCE Software's SKSPro product. Attackers can...

CVE-2026-20401 7.5

This vulnerability allows remote denial of service attacks against mobile devices with affected MediaTek modems. An atta...

CVE-2026-20402 7.5

This vulnerability in MediaTek modems allows remote denial of service through improper input validation. Attackers can c...

CVE-2026-20403 7.5

This vulnerability in MediaTek modems allows remote denial of service via system crash when a device connects to a malic...

CVE-2026-20404 7.5

This vulnerability in MediaTek modems allows remote denial of service through improper input validation. An attacker can...

CVE-2026-20405 7.5

This vulnerability in MediaTek modems allows remote denial of service through system crashes when devices connect to rog...

CVE-2026-20406 7.5

This vulnerability allows remote denial of service attacks against devices with affected MediaTek modems. An attacker ca...

CVE-2026-20419 7.5

This vulnerability in MediaTek wlan AP/STA firmware allows remote attackers within wireless range to cause denial of ser...

CVE-2026-20420 7.5

This vulnerability in MediaTek modems allows remote denial of service through system crashes when devices connect to rog...

CVE-2026-20421 7.5

This vulnerability allows remote attackers to cause a system crash (denial of service) in affected modem devices by conn...

CVE-2026-20422 7.5

This vulnerability in MediaTek modems allows remote denial of service through improper input validation. An attacker can...

CVE-2024-54263 7.5

This CVE describes a PHP Local File Inclusion vulnerability in the Talemy Spirit Framework WordPress plugin. Attackers c...

CVE-2024-4147 7.5

This vulnerability allows authenticated users in lunary-ai/lunary to delete prompts belonging to other organizations thr...

CVE-2026-0599 7.5

This vulnerability in huggingface/text-generation-inference allows unauthenticated attackers to trigger resource exhaust...

CVE-2022-50977 7.5

CVE-2022-50977 allows unauthenticated remote attackers to disrupt operations by switching between multiple configuration...

CVE-2022-50978 7.5

This vulnerability allows unauthenticated remote attackers to disrupt operations by switching between multiple configura...

CVE-2026-1740 7.3

This vulnerability allows remote attackers to bypass authentication on EFM ipTIME A8004T routers via improper authentica...

CVE-2026-1777 7.2

The Amazon SageMaker Python SDK before v3.2.0 and v2.256.0 exposes the ModelBuilder HMAC signing key in cleartext via th...

CVE-2026-0617 7.2

This stored XSS vulnerability in the LatePoint WordPress plugin allows unauthenticated attackers to inject malicious scr...

CVE-2026-1065 7.2

The Form Maker by 10Web WordPress plugin allows unauthenticated attackers to upload malicious SVG files containing JavaS...

CVE-2026-22550 7.2

An OS command injection vulnerability in ELECOM WRC-X1500GS-B and WRC-X1500GSA-B wireless routers allows authenticated a...

CVE-2025-15396 7.1

The Library Viewer WordPress plugin before version 3.2.0 contains a reflected cross-site scripting (XSS) vulnerability w...

CVE-2026-1058 7.1

The Form Maker WordPress plugin has a stored XSS vulnerability in versions up to 1.15.35. Unauthenticated attackers can ...

CVE-2025-10279 7.0

This CVE describes a local privilege escalation vulnerability in mlflow versions before 3.4.0 where temporary directorie...

CVE-2026-24051 7.0

OpenTelemetry-Go SDK versions v1.20.0 through v1.39.0 on macOS/Darwin systems are vulnerable to path hijacking attacks. ...

CVE-2026-20410 6.7

This CVE describes an out-of-bounds write vulnerability in imgsys (likely MediaTek image processing subsystem) that allo...

CVE-2025-14740 6.7

Docker Desktop for Windows installer has permission assignment vulnerabilities allowing low-privileged attackers to gain...

CVE-2026-20413 6.7

This CVE describes an out-of-bounds write vulnerability in the imgsys component due to missing bounds checks. It allows ...

CVE-2026-20414 6.7

This CVE describes a use-after-free vulnerability in the imgsys component that allows local privilege escalation. An att...

CVE-2026-1741 6.6

This CVE describes a backdoor vulnerability in the EFM ipTIME A8004T router's debug interface. Attackers can remotely ma...

CVE-2026-20711 6.5

A cross-site scripting vulnerability in the email function of Cybozu Garoon allows attackers to inject malicious scripts...

CVE-2022-50979 6.5

This vulnerability allows an unauthenticated attacker on the same network segment to disrupt operations by switching bet...

CVE-2022-50980 6.5

An unauthenticated attacker on the same Controller Area Network (CAN) bus can disrupt operations by rapidly switching be...

CVE-2026-1210 6.4

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to inject malicious scri...

CVE-2026-1746 6.3

This SQL injection vulnerability in JeecgBoot 3.9.0 allows remote attackers to execute arbitrary SQL commands through th...

CVE-2026-1757 6.2

A memory leak vulnerability in xmllint's interactive shell allows local denial-of-service attacks. When users input only...

CVE-2025-70958 6.1

Multiple reflected cross-site scripting (XSS) vulnerabilities in Subrion CMS v4.2.1 installation module allow attackers ...

CVE-2026-1778 5.9

This vulnerability in Amazon SageMaker Python SDK disables TLS certificate verification when importing Triton Python mod...

CVE-2026-22881 5.7

A cross-site scripting vulnerability in the Message function of Cybozu Garoon allows attackers to inject malicious scrip...

CVE-2025-7105 5.7

This vulnerability in LibreChat allows attackers to exploit an unrestricted fork function to create numerous content for...

CVE-2026-20415 5.5

This vulnerability in the imgsys component allows memory corruption due to improper locking. It enables local denial of ...

CVE-2025-70959 5.4

A stored cross-site scripting vulnerability in Tendenci CMS allows attackers to inject malicious scripts into the Jobs m...

CVE-2025-70960 5.4

A stored cross-site scripting (XSS) vulnerability in Tendenci CMS v15.3.7 allows attackers to inject malicious scripts i...

CVE-2026-23476 5.4

This reflected XSS vulnerability in FacturaScripts allows attackers to inject malicious scripts into error messages that...

CVE-2025-14274 5.4

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to inject malicious scri...

CVE-2026-1447 5.4

The Mail Mint WordPress plugin is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to 1.19.2, allowing...

CVE-2026-1734 5.3

This vulnerability allows unauthorized remote access to the crontab endpoint in Zhong Bang CRMEB versions up to 5.6.3. A...

CVE-2026-1736 5.3

A reachable assertion vulnerability in Open5GS SGWC component allows remote attackers to cause denial of service by send...

CVE-2026-1737 5.3

This vulnerability in Open5GS allows remote attackers to trigger a reachable assertion in the CreateBearerRequest handle...

CVE-2026-1738 5.3

CVE-2026-1738 is a reachable assertion vulnerability in Open5GS SGWC component that allows remote attackers to cause den...

CVE-2026-1739 5.3

A null pointer dereference vulnerability in Free5GC's Policy Control Function (PCF) allows remote attackers to cause den...

CVE-2026-20417 5.3

This CVE describes an out-of-bounds write vulnerability in PCIe drivers that could allow local privilege escalation. Att...

CVE-2025-6208 5.3

The SimpleDirectoryReader component in llama_index.core versions before 0.12.41 has a memory management flaw where it lo...

CVE-2026-1760 5.3

This HTTP request smuggling vulnerability in SoupServer allows remote attackers to send specially crafted requests that ...

CVE-2026-25144 5.3

A stored cross-site scripting (XSS) vulnerability exists in Talishar's in-game chat system where the playerID parameter ...

CVE-2026-0909 5.3

The WP ULike WordPress plugin has an Insecure Direct Object Reference vulnerability that allows authenticated attackers ...

CVE-2026-0950 5.3

The Spectra Gutenberg Blocks plugin for WordPress has an information disclosure vulnerability that allows unauthenticate...

CVE-2026-25228 5.0

Signal K Server versions prior to 2.20.3 on Windows systems contain a path traversal vulnerability in the applicationDat...

CVE-2026-22888 4.9

An improper input verification vulnerability in Cybozu Garoon allows attackers to modify portal settings without proper ...

CVE-2026-1742 4.7

This vulnerability allows remote attackers to upload arbitrary files to the EFM ipTIME A8004T router via the VPN service...

CVE-2025-6594 4.7

This XSS vulnerability in MediaWiki's ApiSandbox.js allows attackers to inject malicious scripts into web pages viewed b...

📚 Past Roundups