CVE-2026-2235 - HGiga|C&Cm@il - SQL Injection
CVE ID : CVE-2026-2235
Published : Feb. 9, 2026, 8:16 a.m. | 49 minutes ago
Description : C&Cm@il developed by HGiga has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2026-2235
Published : Feb. 9, 2026, 8:16 a.m. | 49 minutes ago
Description : C&Cm@il developed by HGiga has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-2236 - HGiga|C&Cm@il - SQL Injection
CVE ID : CVE-2026-2236
Published : Feb. 9, 2026, 8:16 a.m. | 49 minutes ago
Description : C&Cm@il developed by HGiga has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2026-2236
Published : Feb. 9, 2026, 8:16 a.m. | 49 minutes ago
Description : C&Cm@il developed by HGiga has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-2224 - code-projects Online Reviewer System btn_functions.php cross site scripting
CVE ID : CVE-2026-2224
Published : Feb. 9, 2026, 8:32 a.m. | 34 minutes ago
Description : A vulnerability was detected in code-projects Online Reviewer System 1.0. This affects an unknown part of the file /system/system/admins/manage/users/btn_functions.php. The manipulation of the argument firstname results in cross site scripting. It is possible to launch the attack remotely. The exploit is now public and may be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2026-2224
Published : Feb. 9, 2026, 8:32 a.m. | 34 minutes ago
Description : A vulnerability was detected in code-projects Online Reviewer System 1.0. This affects an unknown part of the file /system/system/admins/manage/users/btn_functions.php. The manipulation of the argument firstname results in cross site scripting. It is possible to launch the attack remotely. The exploit is now public and may be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-25904 - Overly permissive Deno configuration in mcp-run-python leads to SSRF
CVE ID : CVE-2026-25904
Published : Feb. 9, 2026, 8:51 a.m. | 14 minutes ago
Description : The Pydantic-AI MCP Run Python tool configures the Deno sandbox with an overly permissive configuration that allows the underlying Python code to access the localhost interface of the host to perform SSRF attacks. Note - the "mcp-run-python" project is archived and unlikely to receive a fix.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2026-25904
Published : Feb. 9, 2026, 8:51 a.m. | 14 minutes ago
Description : The Pydantic-AI MCP Run Python tool configures the Deno sandbox with an overly permissive configuration that allows the underlying Python code to access the localhost interface of the host to perform SSRF attacks. Note - the "mcp-run-python" project is archived and unlikely to receive a fix.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-25905 - Lack of isolation in mcp-run-python leads to MCP server takeover
CVE ID : CVE-2026-25905
Published : Feb. 9, 2026, 9:16 a.m. | 3 hours, 49 minutes ago
Description : The Python code being run by 'runPython' or 'runPythonAsync' is not isolated from the rest of the JS code, allowing any Python code to use the Pyodide APIs to modify the JS environment. This may result in an attacker hijacking the MCP server - for malicious purposes including MCP tool shadowing. Note - the "mcp-run-python" project is archived and unlikely to receive a fix.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2026-25905
Published : Feb. 9, 2026, 9:16 a.m. | 3 hours, 49 minutes ago
Description : The Python code being run by 'runPython' or 'runPythonAsync' is not isolated from the rest of the JS code, allowing any Python code to use the Pyodide APIs to modify the JS environment. This may result in an attacker hijacking the MCP server - for malicious purposes including MCP tool shadowing. Note - the "mcp-run-python" project is archived and unlikely to receive a fix.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-2225 - itsourcecode News Portal Project Administrator Login index.php sql injection
CVE ID : CVE-2026-2225
Published : Feb. 9, 2026, 9:16 a.m. | 3 hours, 49 minutes ago
Description : A flaw has been found in itsourcecode News Portal Project 1.0. This vulnerability affects unknown code of the file /admin/index.php of the component Administrator Login. This manipulation of the argument email causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2026-2225
Published : Feb. 9, 2026, 9:16 a.m. | 3 hours, 49 minutes ago
Description : A flaw has been found in itsourcecode News Portal Project 1.0. This vulnerability affects unknown code of the file /admin/index.php of the component Administrator Login. This manipulation of the argument email causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-23903 - Apache Shiro: Auth bypass when accessing static files only on case-insensitive filesystems
CVE ID : CVE-2026-23903
Published : Feb. 9, 2026, 10:15 a.m. | 2 hours, 50 minutes ago
Description : Authentication Bypass by Alternate Name vulnerability in Apache Shiro. This issue affects Apache Shiro: before 2.0.7. Users are recommended to upgrade to version 2.0.7, which fixes the issue. The issue only effects static files. If static files are served from a case-insensitive filesystem, such as default macOS setup, static files may be accessed by varying the case of the filename in the request. If only lower-case (common default) filters are present in Shiro, they may be bypassed this way. Shiro 2.0.7 and later has a new parameters to remediate this issue shiro.ini: filterChainResolver.caseInsensitive = true application.propertie: shiro.caseInsensitive=true Shiro 3.0.0 and later (upcoming) makes this the default.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2026-23903
Published : Feb. 9, 2026, 10:15 a.m. | 2 hours, 50 minutes ago
Description : Authentication Bypass by Alternate Name vulnerability in Apache Shiro. This issue affects Apache Shiro: before 2.0.7. Users are recommended to upgrade to version 2.0.7, which fixes the issue. The issue only effects static files. If static files are served from a case-insensitive filesystem, such as default macOS setup, static files may be accessed by varying the case of the filename in the request. If only lower-case (common default) filters are present in Shiro, they may be bypassed this way. Shiro 2.0.7 and later has a new parameters to remediate this issue shiro.ini: filterChainResolver.caseInsensitive = true application.propertie: shiro.caseInsensitive=true Shiro 3.0.0 and later (upcoming) makes this the default.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-2226 - DouPHP ZIP File file.php unrestricted upload
CVE ID : CVE-2026-2226
Published : Feb. 9, 2026, 10:15 a.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been found in DouPHP up to 1.9. This issue affects some unknown processing of the file /admin/file.php of the component ZIP File Handler. Such manipulation of the argument sql_filename leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2026-2226
Published : Feb. 9, 2026, 10:15 a.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been found in DouPHP up to 1.9. This issue affects some unknown processing of the file /admin/file.php of the component ZIP File Handler. Such manipulation of the argument sql_filename leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-2227 - D-Link DCS-931L setSystemAdmin doSystem command injection
CVE ID : CVE-2026-2227
Published : Feb. 9, 2026, 10:15 a.m. | 2 hours, 50 minutes ago
Description : A vulnerability was found in D-Link DCS-931L up to 1.13.0. Impacted is the function doSystem of the file /setSystemAdmin. Performing a manipulation of the argument AdminID results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2026-2227
Published : Feb. 9, 2026, 10:15 a.m. | 2 hours, 50 minutes ago
Description : A vulnerability was found in D-Link DCS-931L up to 1.13.0. Impacted is the function doSystem of the file /setSystemAdmin. Performing a manipulation of the argument AdminID results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-22922 - Apache Airflow: Airflow externalLogUrl Permission Bypass
CVE ID : CVE-2026-22922
Published : Feb. 9, 2026, 11:16 a.m. | 1 hour, 50 minutes ago
Description : Apache Airflow versions 3.1.0 through 3.1.6 contain an authorization flaw that can allow an authenticated user with custom permissions limited to task access to view task logs without having task log access. Users are recommended to upgrade to Apache Airflow 3.1.7 or later, which resolves this issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2026-22922
Published : Feb. 9, 2026, 11:16 a.m. | 1 hour, 50 minutes ago
Description : Apache Airflow versions 3.1.0 through 3.1.6 contain an authorization flaw that can allow an authenticated user with custom permissions limited to task access to view task logs without having task log access. Users are recommended to upgrade to Apache Airflow 3.1.7 or later, which resolves this issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-24098 - Apache Airflow: Assigning single DAG permission leaked all DAGs Import Errors
CVE ID : CVE-2026-24098
Published : Feb. 9, 2026, 11:16 a.m. | 1 hour, 50 minutes ago
Description : Apache Airflow versions before 3.1.7, has vulnerability that allows authenticated UI users with permission to one or more specific Dags to view import errors generated by other Dags they did not have access to. Users are advised to upgrade to 3.1.7 or later, which resolves this issue
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2026-24098
Published : Feb. 9, 2026, 11:16 a.m. | 1 hour, 50 minutes ago
Description : Apache Airflow versions before 3.1.7, has vulnerability that allows authenticated UI users with permission to one or more specific Dags to view import errors generated by other Dags they did not have access to. Users are advised to upgrade to 3.1.7 or later, which resolves this issue
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-25846 - JetBrains YouTrack Mailbox Token Exposure Vulnerability
CVE ID : CVE-2026-25846
Published : Feb. 9, 2026, 11:16 a.m. | 1 hour, 50 minutes ago
Description : In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2026-25846
Published : Feb. 9, 2026, 11:16 a.m. | 1 hour, 50 minutes ago
Description : In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-25847 - JetBrains PyCharm DOM-based XSS Vulnerability
CVE ID : CVE-2026-25847
Published : Feb. 9, 2026, 11:16 a.m. | 1 hour, 50 minutes ago
Description : In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possible
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2026-25847
Published : Feb. 9, 2026, 11:16 a.m. | 1 hour, 50 minutes ago
Description : In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possible
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-25848 - JetBrains Hub Authentication Bypass Vulnerability
CVE ID : CVE-2026-25848
Published : Feb. 9, 2026, 11:16 a.m. | 1 hour, 50 minutes ago
Description : In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2026-25848
Published : Feb. 9, 2026, 11:16 a.m. | 1 hour, 50 minutes ago
Description : In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-10463 - Improper Authentication in Birtech Information Technologies' Sensaway
CVE ID : CVE-2025-10463
Published : Feb. 9, 2026, 12:15 p.m. | 50 minutes ago
Description : Improper Authentication vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Senseway allows Authentication Abuse.This issue affects Senseway: through 09022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-10463
Published : Feb. 9, 2026, 12:15 p.m. | 50 minutes ago
Description : Improper Authentication vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Senseway allows Authentication Abuse.This issue affects Senseway: through 09022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6830 - SQLi in Xpoda Türkiye Information Technology's Xpoda Studio
CVE ID : CVE-2025-6830
Published : Feb. 9, 2026, 12:15 p.m. | 50 minutes ago
Description : Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpoda Türkiye Information Technology Inc. Xpoda Studio allows SQL Injection.This issue affects Xpoda Studio: through 09022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-6830
Published : Feb. 9, 2026, 12:15 p.m. | 50 minutes ago
Description : Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpoda Türkiye Information Technology Inc. Xpoda Studio allows SQL Injection.This issue affects Xpoda Studio: through 09022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-7708 - Sensitive Data Exposure in Atlas Software's k12net
CVE ID : CVE-2025-7708
Published : Feb. 9, 2026, 12:15 p.m. | 50 minutes ago
Description : Insertion of Sensitive Information Into Sent Data vulnerability in Atlas Educational Software Industry Ltd. Co. K12net allows Communication Channel Manipulation.This issue affects k12net: through 09022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 6.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-7708
Published : Feb. 9, 2026, 12:15 p.m. | 50 minutes ago
Description : Insertion of Sensitive Information Into Sent Data vulnerability in Atlas Educational Software Industry Ltd. Co. K12net allows Communication Channel Manipulation.This issue affects k12net: through 09022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 6.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-0632 - Fluent Forms Pro Add On Pack <= 6.1.12 - Authenticated (Subscriber+) Server-Side Request Forgery via 'saveDataSource'
CVE ID : CVE-2026-0632
Published : Feb. 9, 2026, 12:15 p.m. | 50 minutes ago
Description : The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.12 via the 'saveDataSource' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2026-0632
Published : Feb. 9, 2026, 12:15 p.m. | 50 minutes ago
Description : The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.12 via the 'saveDataSource' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-1959 - Stored Cross-Site Scripting (XSS) vulnerability in Loggro Pymes
CVE ID : CVE-2026-1959
Published : Feb. 9, 2026, 12:15 p.m. | 50 minutes ago
Description : Stored Cross-Site Scripting (XSS) vulnerability in Loggro Pymes, via the 'descripción' parameter in the '/loggrodemo/jbrain/MaestraCuentasBancarias' endpoint.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2026-1959
Published : Feb. 9, 2026, 12:15 p.m. | 50 minutes ago
Description : Stored Cross-Site Scripting (XSS) vulnerability in Loggro Pymes, via the 'descripción' parameter in the '/loggrodemo/jbrain/MaestraCuentasBancarias' endpoint.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-1960 - Stored Cross-Site Scripting (XSS) vulnerability in Loggro Pymes
CVE ID : CVE-2026-1960
Published : Feb. 9, 2026, 12:15 p.m. | 50 minutes ago
Description : Stored Cross-Site Scripting (XSS) vulnerability in Loggro Pymes, via the 'Facebook' parameter in '/loggrodemo/jbrain/ConsultaTerceros' endpoint.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2026-1960
Published : Feb. 9, 2026, 12:15 p.m. | 50 minutes ago
Description : Stored Cross-Site Scripting (XSS) vulnerability in Loggro Pymes, via the 'Facebook' parameter in '/loggrodemo/jbrain/ConsultaTerceros' endpoint.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-10464 - Cleartext password storage in Birtech Information Technologies' Sensaway
CVE ID : CVE-2025-10464
Published : Feb. 9, 2026, 12:49 p.m. | 17 minutes ago
Description : Insecure Storage of Sensitive Information vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Senseway allows Retrieve Embedded Sensitive Data.This issue affects Senseway: through 09022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-10464
Published : Feb. 9, 2026, 12:49 p.m. | 17 minutes ago
Description : Insecure Storage of Sensitive Information vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Senseway allows Retrieve Embedded Sensitive Data.This issue affects Senseway: through 09022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...