6.9

CVSS4.0

CVE-2026-2113 - yuan1994 tpadmin WebUploader preview.php deserialization

A security vulnerability has been detected in yuan1994 tpadmin up to 1.3.12. This affects an unknown part in the library /public/static/admin/lib/webuploader/0.1.5/server/preview.php of the component WebUploader. The manipulation leads to deserialization. The attack is possible to be carried out re…

📅 Published: Feb. 7, 2026, 9:02 p.m. 🔄 Last Modified: Feb. 7, 2026, 9:02 p.m.

5.3

CVSS4.0

CVE-2026-2111 - JeecgBoot Retrieval-Augmented Generation edit path traversal

A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this issue is some unknown functionality of the file /airag/knowledge/doc/edit of the component Retrieval-Augmented Generation Module. Executing a manipulation of the argument filePath can lead to path traversal. The attack can be…

📅 Published: Feb. 7, 2026, 8:32 p.m. 🔄 Last Modified: Feb. 7, 2026, 8:32 p.m.

6.3

CVSS4.0

CVE-2026-2110 - Tasin1025 SwiftBuy login.php excessive authentication

A security flaw has been discovered in Tasin1025 SwiftBuy up to 0f5011372e8d1d7edfd642d57d721c9fadc54ec7. Affected by this vulnerability is an unknown functionality of the file /login.php. Performing a manipulation results in improper restriction of excessive authentication attempts. Remote exploit…

📅 Published: Feb. 7, 2026, 8:02 p.m. 🔄 Last Modified: Feb. 7, 2026, 8:02 p.m.

5.3

CVSS4.0

CVE-2026-2109 - jsbroks COCO Annotator Delete Category undo improper authorization

A vulnerability was identified in jsbroks COCO Annotator up to 0.11.1. Affected is an unknown function of the file /api/undo/ of the component Delete Category Handler. Such manipulation of the argument ID leads to improper authorization. The attack may be launched remotely. The exploit is publicly …

📅 Published: Feb. 7, 2026, 7:32 p.m. 🔄 Last Modified: Feb. 7, 2026, 7:32 p.m.

6.9

CVSS4.0

CVE-2026-2108 - jsbroks COCO Annotator Endpoint long_task denial of service

A vulnerability was determined in jsbroks COCO Annotator up to 0.11.1. This impacts an unknown function of the file /api/info/long_task of the component Endpoint. This manipulation causes denial of service. The attack may be initiated remotely. The exploit has been publicly disclosed and may be uti…

📅 Published: Feb. 7, 2026, 7:02 p.m. 🔄 Last Modified: Feb. 7, 2026, 7:02 p.m.
Load More Vulnerability
avatar

Mehmet Ince

@mdisec

CVE stats coming here

avatar

Nuri Çilengir

@ncilengir

CVE stats coming here

avatar

@aydinnyunus

CVE stats coming here

avatar

Onurcan Genç

@onurcangnc

CVE stats coming here

avatar

Seyit Sigirci

@h3xecute

CVE stats coming here

avatar

Ali İltizar

@iltosec

CVE stats coming here

avatar

@b3rsec

CVE stats coming here

avatar

@furkank

CVE stats coming here

avatar

kutaysec

@kutaysec

CVE stats coming here