Common Vulnerabilities and Exposures (CVE)

CVE-2026-25938

Feb 9, 2026 22:18:15 UTC

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to execute arbitrary code on the server when the ...

CVE-2026-25934

Feb 9, 2026 22:13:41 UTC

go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not properly verified. This resulted in go-gi...

CVE-2026-25931

Feb 9, 2026 22:10:37 UTC

vscode-spell-checker is a basic spell checker that works well with code and documents. Prior to v4.5.4, DocumentSettings._determineIsTrusted treats the configuration value cSpell.trustedWorkspace as the authoritative trust flag. The value d...

CVE-2026-25925

Feb 9, 2026 21:59:08 UTC

PowerDocu contains a Windows GUI executable to perform technical documentations. Prior to 2.4.0, PowerDocu contains a critical security vulnerability in how it parses JSON files within Flow or App packages. The application blindly trusts th...

CVE-2026-25923

Feb 9, 2026 21:56:02 UTC

my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to 20260208.1, the application fails to filter the phar:// protocol in URL validation, allowing attackers to upload a malic...

CVE-2026-25808

Feb 9, 2026 21:50:10 UTC

Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Prior to 0.6.20 and 0.7.2, there is a security vulnerability where DMs and followers-only posts were exposed through the ActivityPub outbo...

CVE-2025-15315

Feb 9, 2026 21:48:49 UTC

Tanium addressed a local privilege escalation vulnerability in Tanium Module Server.

CVE-2025-15316

Feb 9, 2026 21:48:49 UTC

Tanium addressed a local privilege escalation vulnerability in Tanium Server.

CVE-2025-67189

Feb 9, 2026 21:47:58 UTC

A buffer overflow vulnerability exists in the setParentalRules interface of TOTOLINK A950RG V4.1.2cu.5204_B20210112. The urlKeyword parameter is not properly validated, and the function concatenates multiple user-controlled fields into a fi...

CVE-2025-69848

Feb 9, 2026 21:46:39 UTC

NetBox is an open-source infrastructure resource modeling and IP address management platform. A reflected cross-site scripting (XSS) vulnerability exists in versions 2.11.0 through 3.7.x in the ProtectedError handling logic, where object na...

CVE-2026-25807

Feb 9, 2026 21:46:20 UTC

ZAI Shell is an autonomous SysOps agent designed to navigate, repair, and secure complex environments. Prior to 9.0.3, the P2P terminal sharing feature (share start) opens a TCP socket on port 5757 without any authentication mechanism. Any ...

CVE-2025-69970

Feb 9, 2026 21:45:58 UTC

FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' flag is commented out by default, causing the application to initialize with authentication disabled. This allows unauth...

CVE-2025-71031

Feb 9, 2026 21:44:44 UTC

Water-Melon Melon commit 9df9292 and below is vulnerable to Denial of Service. The HTTP component doesn't have any maximum length. As a result, an excessive request header could cause a denial of service by consuming RAM memory.

CVE-2025-15317

Feb 9, 2026 21:43:41 UTC

Tanium addressed an uncontrolled resource consumption vulnerability in Tanium Server.

CVE-2025-68721

Feb 9, 2026 21:40:21 UTC

Axigen Mail Server before 10.5.57 contains an improper access control vulnerability in the WebAdmin interface. A delegated admin account with zero permissions can bypass access control checks and gain unauthorized access to the SSL Certific...