Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.2 MEDIUM
CVE-2019-25326 — ipPulse 1.92 - 'Enter Key' Denial of Service

ipPulse 1.92 contains a denial of service vulnerability that allows local attackers to crash the application by providing an oversized input in the Enter Key field. Attackers can generate a 256-byte …

ippulse | Denial of Service
Feb 18, 2026 Feb 24, 2026
Feb 18, 2026
Feb 24, 2026
7.5 HIGH
CVE-2026-2668 — Rongzhitong Visual Integrated Command and Dispatch Platform User add access control

A vulnerability was found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. This affects an unknown function of the file /dm/dispatch/user/add of the component User Handl…

Feb 18, 2026 Feb 26, 2026
Feb 18, 2026
Feb 26, 2026
5.5 MEDIUM
CVE-2026-2667 — Rongzhitong Visual Integrated Command and Dispatch Platform api access control

A vulnerability has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. The impacted element is an unknown function of the file /dispatch/api?cmd=userinfo. The m…

Feb 18, 2026 Feb 26, 2026
Feb 18, 2026
Feb 26, 2026
7.5 HIGH
CVE-2026-24746 — InvoicePlane has a Stored Cross-Site Scripting (XSS) issue

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability occurs in the Edit Quotes functions of InvoicePla…

invoiceplane | Remote | Cross-Site Scripting
Feb 18, 2026 Feb 20, 2026
Feb 18, 2026
Feb 20, 2026
7.2 HIGH
CVE-2026-1999 — Server-Side Request Forgery in GitHub Enterprise Server Webhook Delivery Allows Access to…

A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to access internal services bound to loopback or unspecified addresses…

enterprise_server | Remote | Authorization
Feb 18, 2026 Mar 03, 2026
Feb 18, 2026
Mar 03, 2026
6.5 MEDIUM
CVE-2026-1355 — Missing Authorization Check in GitHub Enterprise Server Allows Unauthorized Uploads to Re…

A Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to upload unauthorized content to another user’s repository migration export due to a missing…

enterprise_server | Remote | Authorization
Feb 18, 2026 Feb 19, 2026
Feb 18, 2026
Feb 19, 2026
6.3 MEDIUM
CVE-2026-1200 — Remote code execution via segmentation fault in increasebufferto function

A flaw was found in the rgaufman/live555 fork of live555. A remote attacker could exploit a segmentation fault, in the `increaseBufferTo` function. This vulnerability can lead to memory corruption pr…

Remote | Memory Corruption
Feb 18, 2026 Feb 19, 2026
Feb 18, 2026
Feb 19, 2026
6.5 MEDIUM
CVE-2026-0665 — Qemu-kvm: heap off-by-one in kvm xen physdevop_map_pirq

An off-by-one error was found in QEMU's KVM Xen guest support. A malicious guest could use this flaw to trigger out-of-bounds heap accesses in the QEMU process via the emulated Xen physdev hypercall …

qemu | Memory Corruption
Feb 18, 2026 Feb 19, 2026
Feb 18, 2026
Feb 19, 2026
9.0 CRITICAL
CVE-2026-0573 — Improper Handling of HTTP Redirects vulnerability was identified in GitHub Enterprise Ser…

An URL redirection vulnerability was identified in GitHub Enterprise Server that allowed attacker-controlled redirects to leak sensitive authorization tokens. The repository_pages API insecurely foll…

enterprise_server | Remote | Server-Side Request Forgery
Feb 18, 2026 Feb 19, 2026
Feb 18, 2026
Feb 19, 2026
3.3 LOW
CVE-2025-8860 — Qemu-kvm: uefi-vars: information disclosure vulnerability in uefi_vars_write callback

A flaw was found in QEMU in the uefi-vars virtual device. When the guest writes to register UEFI_VARS_REG_BUFFER_SIZE, the .write callback `uefi_vars_write` is invoked. The function allocates a heap …

qemu | Information Disclosure
Feb 18, 2026 Feb 19, 2026
Feb 18, 2026
Feb 19, 2026
7.7 HIGH
CVE-2025-1272 — Kernel: secure boot does not automatically enable kernel lockdown

The Linux Kernel lockdown mode for kernel versions starting on 6.12 and above for Fedora Linux has the lockdown mode disabled without any warning. This may allow an attacker to gain access to sensiti…

enterprise_linux gix-date | Misconfiguration
Feb 18, 2026 Feb 26, 2026
Feb 18, 2026
Feb 26, 2026
5.5 MEDIUM
CVE-2025-14876 — Qemu-kvm: unbounded allocation in virtio-crypto

A flaw was found in the virtio-crypto device of QEMU. A malicious guest operating system can exploit a missing length limit in the AKCIPHER path, leading to uncontrolled memory allocation. This can r…

qemu | Denial of Service
Feb 18, 2026 Feb 19, 2026
Feb 18, 2026
Feb 19, 2026
5.5 MEDIUM
CVE-2025-12343 — Ffmpeg: double-free vulnerability in ffmpeg tensorflow dnn backend

A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple tim…

ffmpeg | Memory Corruption
Feb 18, 2026 Feb 26, 2026
Feb 18, 2026
Feb 26, 2026
5.5 MEDIUM
CVE-2025-10256 — Ffmpeg: null pointer dereference in firequalizer filter (libavfilter/af_firequalizer.c)

A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() f…

ffmpeg | Memory Corruption
Feb 18, 2026 Feb 26, 2026
Feb 18, 2026
Feb 26, 2026
4.8 MEDIUM
CVE-2025-0577 — Glibc: vdso getrandom acceleration may return predictable randomness

An insufficient entropy vulnerability was found in glibc. The getrandom and arc4random family of functions may return predictable randomness if these functions are called again after the fork, which …

Remote | Cryptography
Feb 18, 2026 Feb 19, 2026
Feb 18, 2026
Feb 19, 2026
7.2 HIGH
CVE-2026-2666 — mingSoft MCMS Template Archive uploadTemplate.do unrestricted upload

A flaw has been found in mingSoft MCMS 6.1.1. The affected element is an unknown function of the file /ms/file/uploadTemplate.do of the component Template Archive Handler. Executing a manipulation of…

mcms | Remote | Misconfiguration
Feb 18, 2026 Feb 19, 2026
Feb 18, 2026
Feb 19, 2026
6.5 MEDIUM
CVE-2026-2665 — huanzi-qch base-admin JSP Parser SysFileController.java upload unrestricted upload

A vulnerability was detected in huanzi-qch base-admin up to 57a8126bb3353a004f3c7722089e3b926ea83596. Impacted is the function Upload of the file SysFileController.java of the component JSP Parser. P…

Remote | Misconfiguration
Feb 18, 2026 Feb 19, 2026
Feb 18, 2026
Feb 19, 2026
6.5 MEDIUM
CVE-2026-2663 — Alixhan xh-admin-backend Database Query query sql injection

A security vulnerability has been detected in Alixhan xh-admin-backend up to 1.7.0. This issue affects some unknown processing of the file /frontend-api/system-service/api/system/role/query of the co…

Remote | Injection
Feb 18, 2026 Feb 19, 2026
Feb 18, 2026
Feb 19, 2026
7.8 HIGH
CVE-2026-2662 — FascinatedBox lily lily_emitter.c count_transforms out-of-bounds

A weakness has been identified in FascinatedBox lily up to 2.3. This vulnerability affects the function count_transforms of the file src/lily_emitter.c. This manipulation causes out-of-bounds read. T…

lily | Memory Corruption
Feb 18, 2026 Feb 20, 2026
Feb 18, 2026
Feb 20, 2026
7.8 HIGH
CVE-2026-2661 — Squirrel sqobject.h operator heap-based overflow

A security flaw has been discovered in Squirrel up to 3.2. This affects the function SQObjectPtr::operator in the library squirrel/sqobject.h. The manipulation results in heap-based buffer overflow. …

squirrel | Memory Corruption
Feb 18, 2026 Feb 20, 2026
Feb 18, 2026
Feb 20, 2026
Showing 20 of 5050 Results