Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-21435 — webtransport-go CloseWithError can block indefinitely

webtransport-go is an implementation of the WebTransport protocol. Prior to v0.10.0, an attacker can cause a denial of service in webtransport-go by preventing or indefinitely delaying WebTransport s…

webtransport-go | Remote | Denial of Service
Feb 12, 2026 Feb 19, 2026
Feb 12, 2026
Feb 19, 2026
7.5 HIGH
CVE-2026-21434 — webtransport-go affected by Memory Exhaustion Attack due to Missing Length Check in WT_CL…

webtransport-go is an implementation of the WebTransport protocol. From 0.3.0 to 0.9.0, an attacker can cause excessive memory consumption in webtransport-go's session implementation by sending a WT_…

webtransport-go | Remote | Memory Corruption
Feb 12, 2026 Feb 19, 2026
Feb 12, 2026
Feb 19, 2026
9.8 CRITICAL
CVE-2025-70981 — CordysCRM SQL Injection Vulnerability

CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds parameter.

cordys_crm | Remote | Injection
Feb 12, 2026 Feb 18, 2026
Feb 12, 2026
Feb 18, 2026
7.5 HIGH
CVE-2025-69807 — Bareiron Buffer Overflow Denial of Service

p2r3 Bareiron commit: 8e4d4020d is vulnerable to Buffer Overflow, which allows unauthenticated remote attackers to cause a denial of service via a packet sent to the server.

bareiron | Remote | Memory Corruption
Feb 12, 2026 Feb 23, 2026
Feb 12, 2026
Feb 23, 2026
7.5 HIGH
CVE-2025-69806 — Bareiron Out-of-bounds Read

p2r3 bareiron commit: 8e4d4020d contains an Out-of-bounds Read, which allows unauthenticated remote attackers to get relative information leakage via a packet sent to the server

bareiron | Remote | Information Disclosure
Feb 12, 2026 Feb 23, 2026
Feb 12, 2026
Feb 23, 2026
7.8 HIGH
CVE-2025-63421 — Filosoft Comerc.32 Local Code Execution

An issue in filosoft Comerc.32 Commercial Invoicing v.16.0.0.3 allows a local attacker to execute arbitrary code via the comeinst.exe file

Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
7.3 HIGH
CVE-2025-54519 — Doc Nav DLL Hijacking Privilege Escalation Vulnerability

A DLL hijacking vulnerability in Doc Nav could allow a local attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

| Misconfiguration
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
8.7 HIGH
CVE-2025-52533 — Xilinx Spartan Debug Interface Privilege Escalation

Improper Access Control in an on-chip debug interface could allow a privileged attacker to enable a debug interface and potentially compromise data confidentiality or integrity.

Remote | Authorization
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
6.3 MEDIUM
CVE-2024-36319 — AMD VCN Firmware Register Write Vulnerability

Debug code left active in AMD's Video Decoder Engine Firmware (VCN FW) could allow a attacker to submit a maliciously crafted command causing the VCN FW to perform read/writes HW registers, potential…

| Misconfiguration
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
8.4 HIGH
CVE-2023-31323 — AMD Secure Processor ASP Type Confusion Vulnerability

Type confusion in the AMD Secure Processor (ASP) could allow an attacker to pass a malformed argument to the External Global Memory Interconnect Trusted Agent (XGMI TA) leading to a memory safety vio…

| Memory Corruption
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
4.6 MEDIUM
CVE-2023-20601 — Cisco RAS TA Driver Buffer Overflow

Improper input validation within RAS TA Driver can allow a local attacker to access out-of-bounds memory, potentially resulting in a denial-of-service condition.

| Memory Corruption
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
8.8 HIGH
CVE-2025-61880 — Infoblox NIOS Deserialization Remote Code Execution

In Infoblox NIOS through 9.0.7, insecure deserialization can result in remote code execution.

nios | Remote | Information Disclosure
Feb 12, 2026 Feb 19, 2026
Feb 12, 2026
Feb 19, 2026
7.7 HIGH
CVE-2025-61879 — Infoblox NIOS Privilege Escalation File Write Vulnerability

In Infoblox NIOS through 9.0.7, a High-Privileged User Can Trigger an Arbitrary File Write via the Account Creation Mechanism.

nios | Remote | Authorization
Feb 12, 2026 Feb 19, 2026
Feb 12, 2026
Feb 19, 2026
7.5 HIGH
CVE-2025-55210 — FreePBX API has a Privilege Escalation Error in GraphQL Allowing Authenticated Users to A…

FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to 17.0.5 and 16.0.17, FreePBX module api (PBX API) is vulnerable to privilege escalation by authentica…

freepbx | Remote | Authentication
Feb 12, 2026 Feb 27, 2026
Feb 12, 2026
Feb 27, 2026
8.6 HIGH
CVE-2025-54756 — BrightSign Players Use of Default Credentials

BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 use a default password that is guessable with knowledge of the device information. The latest rele…

| Authentication
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
9.2 CRITICAL
CVE-2026-26217 — Crawl4AI < 0.8.0 Docker API Local File Inclusion via file URL Handling

Crawl4AI versions prior to 0.8.0 contain a local file inclusion vulnerability in the Docker API deployment. The /execute_js, /screenshot, /pdf, and /html endpoints accept file:// URLs, allowing unaut…

crawl4ai | Remote | Path Traversal
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
10.0 CRITICAL
CVE-2026-26216 — Crawl4AI < 0.8.0 Docker API Unauthenticated Remote Code Execution via Hooks Parameter

Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks parameter containing Python code that is executed usin…

crawl4ai | Remote | Injection
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
9.1 CRITICAL
CVE-2026-26214 — Xiaomi Galaxy FDS Android SDK <= 3.0.8 TLS Hostname Verification Disabled Enables MITM

Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android) version 3.0.8 and prior disable TLS hostname verification when HTTPS is enabled (the default configuration). In GalaxyFDSClientImpl.createHttpCl…

Remote | Misconfiguration
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
7.5 HIGH
CVE-2025-70886 — Halo Denial of Service (DoS) Vulnerability

An issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the public comment submission endpoint

halo | Remote | Denial of Service
Feb 12, 2026 Feb 18, 2026
Feb 12, 2026
Feb 18, 2026
4.3 MEDIUM
CVE-2025-69752 — Ideagen Q-Pulse Authentication Bypass

An issue in the "My Details" user profile functionality of Ideagen Q-Pulse 7.1.0.32 allows an authenticated user to view other users' profile information by modifying the objectKey HTTP parameter in …

Remote | Authorization
Feb 12, 2026 Feb 18, 2026
Feb 12, 2026
Feb 18, 2026
Showing 20 of 5064 Results