This page offers a live ATOM feed of the latest CVEs and Vulnerabilities from cvefeed.io. HIGH or CRITICAL
- CVE-2021-48008 - Chanjet CRM SQL Injection via get_usedspace.php
- CVE-2019-25776 - Weaver E-cology SQL Injection via SyncUserInfo.jsp
- CVE-2023-54399 - Hongjing e-HR < 8.2 SQL Injection via /servlet/codesettree
- CVE-2026-93762 - Data deletion and attribute disclosure via field-name method injection in in-memory queries
- CVE-2026-93752 - CSSOM through 0.5.0 Denial of Service via length Property
- CVE-2026-93748 - http-cache-semantics through 4.2.0 Cross-User Cache Disclosure via max-stale
- CVE-2026-92701 - Cocos AI: Intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path
- CVE-2026-91127 - File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer
- CVE-2026-81179 - SysReptor: Host header injection might allow account takeover
- CVE-2026-62278 - LubeLogger: Path Traversal in HandleTranslationFileUpload Allows Authenticated Users to Write Files Outside Data Directory
- CVE-2026-61550 - Icinga 2: Improper access control for JSON-RPC update certificate messages
- CVE-2026-59163 - Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass
- CVE-2026-33625 - LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading
- CVE-2025-66455 - LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py
- CVE-2026-93765 - Document deletion and process crash via unvalidated method-name dispatch in atomic pop operation