Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.3 CRITICAL
CVE-2026-26219 — newbee-mall Unsalted MD5 Password Hashing Enables Offline Credential Cracking

newbee-mall stores and verifies user passwords using an unsalted MD5 hashing algorithm. The implementation does not incorporate per-user salts or computational cost controls, enabling attackers who o…

newbee-mall | Remote | Cryptography
Feb 12, 2026 Feb 25, 2026
Feb 12, 2026
Feb 25, 2026
9.8 CRITICAL
CVE-2026-26218 — newbee-mall Default Seeded Administrator Credentials Allow Account Takeover

newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisioned with a predictable default password. Deployments that initialize or reset …

newbee-mall | Remote | Authentication
Feb 12, 2026 Feb 25, 2026
Feb 12, 2026
Feb 25, 2026
6.5 MEDIUM
CVE-2026-22821 — mreporting affected by a SQLI on date change

mreporting is the more reporting GLPI plugin. Prior to 1.9.4, there is a possible SQL injection on date change. This vulnerability is fixed in 1.9.4.

more_reporting | Remote | Injection
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
5.3 MEDIUM
CVE-2026-21438 — webtransport-go affected by a Memory Exhaustion Attack due to Missing Cleanup of Streams …

webtransport-go is an implementation of the WebTransport protocol. Prior to 0.10.0, an attacker can cause unbounded memory consumption repeatedly creating and closing many WebTransport streams. Close…

webtransport-go | Remote | Denial of Service
Feb 12, 2026 Feb 19, 2026
Feb 12, 2026
Feb 19, 2026
7.5 HIGH
CVE-2026-21435 — webtransport-go CloseWithError can block indefinitely

webtransport-go is an implementation of the WebTransport protocol. Prior to v0.10.0, an attacker can cause a denial of service in webtransport-go by preventing or indefinitely delaying WebTransport s…

webtransport-go | Remote | Denial of Service
Feb 12, 2026 Feb 19, 2026
Feb 12, 2026
Feb 19, 2026
7.5 HIGH
CVE-2026-21434 — webtransport-go affected by Memory Exhaustion Attack due to Missing Length Check in WT_CL…

webtransport-go is an implementation of the WebTransport protocol. From 0.3.0 to 0.9.0, an attacker can cause excessive memory consumption in webtransport-go's session implementation by sending a WT_…

webtransport-go | Remote | Memory Corruption
Feb 12, 2026 Feb 19, 2026
Feb 12, 2026
Feb 19, 2026
9.8 CRITICAL
CVE-2025-70981 — CordysCRM SQL Injection Vulnerability

CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds parameter.

cordys_crm | Remote | Injection
Feb 12, 2026 Feb 18, 2026
Feb 12, 2026
Feb 18, 2026
7.5 HIGH
CVE-2025-69807 — Bareiron Buffer Overflow Denial of Service

p2r3 Bareiron commit: 8e4d4020d is vulnerable to Buffer Overflow, which allows unauthenticated remote attackers to cause a denial of service via a packet sent to the server.

bareiron | Remote | Memory Corruption
Feb 12, 2026 Feb 23, 2026
Feb 12, 2026
Feb 23, 2026
7.5 HIGH
CVE-2025-69806 — Bareiron Out-of-bounds Read

p2r3 bareiron commit: 8e4d4020d contains an Out-of-bounds Read, which allows unauthenticated remote attackers to get relative information leakage via a packet sent to the server

bareiron | Remote | Information Disclosure
Feb 12, 2026 Feb 23, 2026
Feb 12, 2026
Feb 23, 2026
7.8 HIGH
CVE-2025-63421 — Filosoft Comerc.32 Local Code Execution

An issue in filosoft Comerc.32 Commercial Invoicing v.16.0.0.3 allows a local attacker to execute arbitrary code via the comeinst.exe file

Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
7.3 HIGH
CVE-2025-54519 — Doc Nav DLL Hijacking Privilege Escalation Vulnerability

A DLL hijacking vulnerability in Doc Nav could allow a local attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

| Misconfiguration
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
8.7 HIGH
CVE-2025-52533 — Xilinx Spartan Debug Interface Privilege Escalation

Improper Access Control in an on-chip debug interface could allow a privileged attacker to enable a debug interface and potentially compromise data confidentiality or integrity.

Remote | Authorization
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
6.3 MEDIUM
CVE-2024-36319 — AMD VCN Firmware Register Write Vulnerability

Debug code left active in AMD's Video Decoder Engine Firmware (VCN FW) could allow a attacker to submit a maliciously crafted command causing the VCN FW to perform read/writes HW registers, potential…

| Misconfiguration
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
8.4 HIGH
CVE-2023-31323 — AMD Secure Processor ASP Type Confusion Vulnerability

Type confusion in the AMD Secure Processor (ASP) could allow an attacker to pass a malformed argument to the External Global Memory Interconnect Trusted Agent (XGMI TA) leading to a memory safety vio…

| Memory Corruption
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
4.6 MEDIUM
CVE-2023-20601 — Cisco RAS TA Driver Buffer Overflow

Improper input validation within RAS TA Driver can allow a local attacker to access out-of-bounds memory, potentially resulting in a denial-of-service condition.

| Memory Corruption
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
8.8 HIGH
CVE-2025-61880 — Infoblox NIOS Deserialization Remote Code Execution

In Infoblox NIOS through 9.0.7, insecure deserialization can result in remote code execution.

nios | Remote | Information Disclosure
Feb 12, 2026 Feb 19, 2026
Feb 12, 2026
Feb 19, 2026
7.7 HIGH
CVE-2025-61879 — Infoblox NIOS Privilege Escalation File Write Vulnerability

In Infoblox NIOS through 9.0.7, a High-Privileged User Can Trigger an Arbitrary File Write via the Account Creation Mechanism.

nios | Remote | Authorization
Feb 12, 2026 Feb 19, 2026
Feb 12, 2026
Feb 19, 2026
7.5 HIGH
CVE-2025-55210 — FreePBX API has a Privilege Escalation Error in GraphQL Allowing Authenticated Users to A…

FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to 17.0.5 and 16.0.17, FreePBX module api (PBX API) is vulnerable to privilege escalation by authentica…

freepbx | Remote | Authentication
Feb 12, 2026 Feb 27, 2026
Feb 12, 2026
Feb 27, 2026
8.6 HIGH
CVE-2025-54756 — BrightSign Players Use of Default Credentials

BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 use a default password that is guessable with knowledge of the device information. The latest rele…

| Authentication
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
9.2 CRITICAL
CVE-2026-26217 — Crawl4AI < 0.8.0 Docker API Local File Inclusion via file URL Handling

Crawl4AI versions prior to 0.8.0 contain a local file inclusion vulnerability in the Docker API deployment. The /execute_js, /screenshot, /pdf, and /html endpoints accept file:// URLs, allowing unaut…

crawl4ai | Remote | Path Traversal
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
Showing 20 of 5042 Results