This page offers a live ATOM feed of the latest CVEs and Vulnerabilities from cvefeed.io. HIGH or CRITICAL
- CVE-2026-78037 - Xiiaozet LK100W OS Command Injection
- CVE-2026-76943 - Xiiaozet LK100W Authentication Bypass Using an Alternate Path or Channel
- CVE-2026-75814 - Ebyte NE2-D11 Cross-Site Request Forgery
- CVE-2026-75419 - GoWind CMS Missing Authorization Vulnerability
- CVE-2026-73125 - Ebyte NE2-D11 Missing Authentication for Critical Function
- CVE-2026-71187 - Ebyte NE2-D11 Use of Client-Side Authentication
- CVE-2026-68929 - FastGPT: Unauthenticated WeChat channel hijack and denial of service via shareId-only authorization
- CVE-2026-50152 - Ceph Monitor subscription handler improperly authorizes config-key store reads, exposing cluster secrets to read-only users
- CVE-2026-39944 - Ceph: CephX AES Authentication error
- CVE-2026-18965 - Missing Authorization in PayRange API
- CVE-2025-30156 - Ceph: AES-CBC misuse in CephX and RADOSGW enables authentication bypass and credential forgery
- CVE-2026-81934 - Redis TLS pending-data list use-after-free
- CVE-2026-81728 - Dolibarr before 24.0.0 SQL Injection via the CSV and XLSX Import Update Keys
- CVE-2026-81522 - Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C++ Driver