Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-2320 — Google Chrome File Input UI Spoofing Vulnerability

Inappropriate implementation in File input in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafte…

linux_kernel chrome macos windows edge_chromium | Remote | Misconfiguration
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
7.5 HIGH
CVE-2026-2319 — Google Chrome DevTools Race Condition Object Corruption Vulnerability

Race in DevTools in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures and install a malicious extension to potentially exploit obje…

linux_kernel chrome macos windows edge_chromium | Remote | Race Condition
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
6.5 MEDIUM
CVE-2026-2318 — Google Chrome PictureInPicture UI Spoofing Vulnerability

Inappropriate implementation in PictureInPicture in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a …

linux_kernel chrome macos windows | Remote | Misconfiguration
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
6.5 MEDIUM
CVE-2026-2317 — Google Chrome Animation Cross-Origin Data Leak Vulnerability

Inappropriate implementation in Animation in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

linux_kernel chrome macos windows edge_chromium | Remote | Information Disclosure
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
6.5 MEDIUM
CVE-2026-2316 — Google Chrome UI Spoofing Vulnerability

Insufficient policy enforcement in Frames in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

linux_kernel chrome macos windows edge_chromium | Remote | Misconfiguration
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
8.8 HIGH
CVE-2026-2315 — Google Chrome WebGPU Out-of-Bounds Memory Access Vulnerability

Inappropriate implementation in WebGPU in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security…

linux_kernel chrome macos windows | Remote | Memory Corruption
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
8.8 HIGH
CVE-2026-2314 — Google Chrome Heap Buffer Overflow Vulnerability

Heap buffer overflow in Codecs in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

linux_kernel chrome macos windows edge_chromium | Remote | Memory Corruption
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
8.8 HIGH
CVE-2026-2313 — Google Chrome CSS Use-After-Free Heap Corruption Vulnerability

Use after free in CSS in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

linux_kernel chrome macos windows edge_chromium | Remote | Memory Corruption
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
6.1 MEDIUM
CVE-2025-70297 — Mealie XSS Stored Vulnerability

A stored cross-site scripting (XSS) vulnerability in the recipe asset upload and media serving component in Mealie 3.3.1 allows remote authenticated users to inject arbitrary web script or HTML via a…

mealie | Remote | Cross-Site Scripting
Feb 11, 2026 Feb 23, 2026
Feb 11, 2026
Feb 23, 2026
5.4 MEDIUM
CVE-2025-70296 — Mealie Stored HTML Injection Vulnerability

A stored HTML injection vulnerability in the Recipe Notes rendering component in Mealie 3.3.1 allows remote authenticated users to inject arbitrary HTML, resulting in user interface redressing within…

mealie | Remote | Cross-Site Scripting
Feb 11, 2026 Feb 23, 2026
Feb 11, 2026
Feb 23, 2026
7.5 HIGH
CVE-2025-69873 — Ajv Regular Expression Denial of Service (ReDoS)

ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Poi…

ajv ajv | Remote | Denial of Service
Feb 11, 2026 Mar 02, 2026
Feb 11, 2026
Mar 02, 2026
9.8 CRITICAL
CVE-2025-69872 — DiskCache Python Pickle Deserialization Code Execution Vulnerability

DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache directory can achieve arbitrary code execution when a victim app…

Remote | Misconfiguration
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
8.1 HIGH
CVE-2025-69871 — MedusaJS Promotion Module Unauthenticated Race Condition Vulnerability

A race condition vulnerability exists in MedusaJS Medusa v2.12.2 and earlier in the registerUsage() function of the promotion module. The function performs a non-atomic read-check-update operation wh…

Remote | Race Condition
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
8.0 HIGH
CVE-2026-2361 — Improper search_path protection in PostgreSQL Anonymizer 2.5 allows any user with create …

PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a temporary view based on a function containing malicious code. When the anon.get_tablesampl…

anonymizer | Authorization
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
8.0 HIGH
CVE-2026-2360 — Improper search_path protection in PostgreSQL Anonymizer 2.5 allows any user to gain supe…

PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a custom operator in the public schema and place malicious code in that operator. This opera…

anonymizer | Authentication
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
6.6 MEDIUM
CVE-2026-0229 — PAN-OS: Denial of Service in Advanced DNS Security Feature

A denial-of-service (DoS) vulnerability in the Advanced DNS Security (ADNS) feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a malic…

pan-os | Remote | Denial of Service
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
1.3 LOW
CVE-2026-0228 — PAN-OS: Improper Validation of Terminal Server Agent Certificate

An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server Agents on Windows to PAN-OS using expired certificates even if the PAN-OS configuration would not no…

pan-os prisma_access | Remote | Misconfiguration
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
9.8 CRITICAL
CVE-2025-70085 — OpenSatKit Stack Buffer Overflow

An issue was discovered in OpenSatKit 2.2.1. The EventErrStr buffer has a fixed size of 256 bytes. The code uses sprintf to format two filenames (Source1Filename and the string returned by FileUtil_F…

opensatkit | Remote | Memory Corruption
Feb 11, 2026 Feb 17, 2026
Feb 11, 2026
Feb 17, 2026
7.5 HIGH
CVE-2025-70084 — OpenSatKit Directory Traversal Vulnerability

Directory traversal vulnerability in OpenSatKit 2.2.1 allows attackers to gain access to sensitive information or delete arbitrary files via crafted value to the FileUtil_GetFileInfo function.

opensatkit | Remote | Path Traversal
Feb 11, 2026 Feb 17, 2026
Feb 11, 2026
Feb 17, 2026
7.8 HIGH
CVE-2025-70083 — OpenSatKit Stack Buffer Overflow Vulnerability

An issue was discovered in OpenSatKit 2.2.1. The DirName field in the telecommand is provided by the ground segment and must be treated as untrusted input. The program copies DirName into the local b…

opensatkit | Memory Corruption
Feb 11, 2026 Feb 17, 2026
Feb 11, 2026
Feb 17, 2026
Showing 20 of 5092 Results