9.3

CVSS4.0

CVE-2026-2096 - Flowring|Agentflow - Missing Authenticaton

Agentflow developed by Flowring has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify, and delete database contents by using a specific functionality.

📅 Published: Feb. 10, 2026, 6:59 a.m. 🔄 Last Modified: Feb. 10, 2026, 7:34 p.m.

9.3

CVSS4.0

CVE-2026-2095 - Flowring|Agentflow - Authentication Bypass

Agentflow developed by Flowring has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to exploit a specific functionality to obtain arbitrary user authentication token and log into the system as any user.

📅 Published: Feb. 10, 2026, 6:53 a.m. 🔄 Last Modified: Feb. 10, 2026, 7:34 p.m.

8.7

CVSS4.0

CVE-2026-2094 - Flowring|Docpedia - SQL Injection

Docpedia developed by Flowring has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

📅 Published: Feb. 10, 2026, 6:47 a.m. 🔄 Last Modified: Feb. 10, 2026, 7:33 p.m.

8.7

CVSS4.0

CVE-2026-2093 - Flowring|Docpedia - SQL Injection

Docpedia developed by Flowring has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

📅 Published: Feb. 10, 2026, 6:45 a.m. 🔄 Last Modified: Feb. 10, 2026, 8:15 p.m.

5.7

CVSS3.1

CVE-2025-12063 -

An insecure direct object reference allowed a non-admin user to modify or remove certain data objects without having the appropriate permissions.

📅 Published: Feb. 10, 2026, 5:52 a.m. 🔄 Last Modified: Feb. 10, 2026, 8:16 p.m.

4.6

CVSS3.1

CVE-2025-12757 -

An AXIS Camera Station Pro feature can be exploited in a way that allows a non-admin user to view information they are not permitted to.

📅 Published: Feb. 10, 2026, 5:47 a.m. 🔄 Last Modified: Feb. 10, 2026, 8:16 p.m.

4.5

CVSS3.1

CVE-2025-13064 -

A server-side injection was possible for a malicious admin to manipulate the application to include a malicious script which is executed by the server. This attack is only possible if the admin uses a client that have been tampered with.

📅 Published: Feb. 10, 2026, 5:40 a.m. 🔄 Last Modified: Feb. 10, 2026, 8:16 p.m.

7.8

CVSS3.1

CVE-2025-11547 -

AXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin user.

📅 Published: Feb. 10, 2026, 5:35 a.m. 🔄 Last Modified: Feb. 11, 2026, 4:56 a.m.

7.1

CVSS3.1

CVE-2025-11142 -

The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with an operator- or administrator- privileged service account.

📅 Published: Feb. 10, 2026, 5:32 a.m. 🔄 Last Modified: Feb. 11, 2026, 4:56 a.m.

6.4

CVSS3.1

CVE-2026-0996 - Fluent Forms <= 6.1.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting via AI Form Builde…

The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the AI Form Builder module in all versions up to, and including, 6.1.14 due to a combination of missing authorization checks, a leaked nonce, and insufficient input sanitization. The vulnerability allows Subscrib…

📅 Published: Feb. 10, 2026, 5:29 a.m. 🔄 Last Modified: Feb. 10, 2026, 3:40 p.m.
Total resulsts: 332124
Page 30 of 33,213
« previous page » next page
Filters