CVE Security Advisories

Stay informed about the latest critical and high-severity vulnerabilities. Updated daily.

14
Total CVEs
13
Critical
1
High

Critical Vulnerabilities

CVE-2026-1306

Feb 14, 2026

Critical (9.8)

The midi-Synth plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type and file extension validation in the 'export' AJAX action in all versions up to, and including, 1.1...

Read Advisory

CVE-2025-69770

Feb 13, 2026

Critical (10.0)

A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execute arbitrary commands via uploading a crafted zip file....

Read Advisory

CVE-2026-26216

Feb 12, 2026

Critical (10.0)

Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks parameter containing Python code that is executed using...

Read Advisory

CVE-2025-64075

Feb 11, 2026

Critical (10.0)

A path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to bypass authentication and perform administrative actions by ...

Read Advisory

CVE-2026-0488

Feb 10, 2026

Critical (9.9)

An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the abi...

Read Advisory

CVE-2026-26009

Feb 10, 2026

Critical (9.9)

Catalyst is a platform built for enterprise game server hosts, game communities, and billing panel integrations. Install scripts defined in server templates execute directly on the host operating syst...

Read Advisory

CVE-2026-22903

Feb 9, 2026

Critical (9.8)

An unauthenticated remote attacker can send a crafted HTTP request containing an overly long SESSIONID cookie. This can trigger a stack buffer overflow in the modified lighttpd server, causing it to c...

Read Advisory

CVE-2026-1868

Feb 9, 2026

Critical (9.9)

GitLab has remediated a vulnerability in the Duo Workflow Service component of GitLab AI Gateway affecting all versions of the AI Gateway from 18.1.6, 18.2.6, 18.3.1 to 18.6.1, 18.7.0, and 18.8.0 in w...

Read Advisory

CVE-2026-1615

Feb 9, 2026

Critical (9.8)

All versions of the package jsonpath are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. The library relies on the static-eval module to process JS...

Read Advisory

CVE-2026-22904

Feb 9, 2026

Critical (9.8)

Improper length handling when parsing multiple cookie fields (including TRACKID) allows an unauthenticated remote attacker to send oversized cookie values and trigger a stack buffer overflow, resultin...

Read Advisory

CVE-2026-22906

Feb 9, 2026

Critical (9.8)

User credentials are stored using AES‑ECB encryption with a hardcoded key. An unauthenticated remote attacker obtaining the configuration file can decrypt and recover plaintext usernames and passwords...

Read Advisory

CVE-2025-15027

Feb 8, 2026

Critical (9.8)

The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.6.03. This is due to the plugin allowing a user to update arbitrary user met...

Read Advisory

CVE-2024-0001

Jan 15, 2024

Critical (9.8)

A critical remote code execution vulnerability in Example Software allows attackers to execute arbitrary code...

Read Advisory

High Severity Vulnerabilities

CVE-2024-0002

Jan 14, 2024

High (8.1)

An authentication bypass vulnerability in Network Service allows unauthorized access to protected resources...

Read Advisory