Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2025-48518 — AMD Graphics Driver Out-of-Bounds Write Vulnerability

Improper input validation in AMD Graphics Driver could allow a local attacker to write out of bounds, potentially resulting in loss of integrity or denial of service.

| Memory Corruption
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
6.0 MEDIUM
CVE-2025-48508 — AMD GPU GFX Hardware IP Block Privilege Escalation Vulnerability

Improper Hardware reset flow logic in the GPU GFX Hardware IP block could allow a privileged attacker in a guest virtual machine to control reset operation potentially causing host or GPU crash or re…

| Denial of Service
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
7.8 HIGH
CVE-2025-48503 — AMD Software Installer DLL Hijacking Vulnerability

A DLL hijacking vulnerability in the AMD Software Installer could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

| Misconfiguration
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
9.8 CRITICAL
CVE-2025-12059 — Improper Access Control in Logo Software's Logo j-Platform

Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Logo Software Industry and Trade Inc. Logo j-Platform allows Exploiting Incorrectly Configured Access …

Remote | Misconfiguration
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
8.8 HIGH
CVE-2024-36324 — AMD Graphics Driver Pointer Validation Vulnerability

Improper input validation in AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, potentially leading to arbitrary code execution.

| Memory Corruption
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
7.0 HIGH
CVE-2024-36320 — ATIHdwt6.sys Integer Overflow Vulnerability

Integer Overflow within atihdwt6.sys can allow a local attacker to cause out of bound read/write potentially leading to loss of confidentiality, integrity and availability

| Memory Corruption
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
5.5 MEDIUM
CVE-2024-36316 — AMD Graphics Integer Overflow Denial of Service Vulnerability

The integer overflow vulnerability within AMD Graphics driver could allow an attacker to bypass size checks potentially resulting in a denial of service

| Denial of Service
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
7.8 HIGH
CVE-2023-31324 — AMD Secure Processor ASP TOCTOU Race Condition

A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify External Global Memory Interconnect Trusted Agent (XGMI TA) commands as they ar…

Feb 11, 2026 Mar 05, 2026
Feb 11, 2026
Mar 05, 2026
7.8 HIGH
CVE-2023-20548 — AMD Secure Processor TOCTOU Race Condition Vulnerability

A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to corrupt memory resulting in loss of integrity, confidentiality, or availability.

Feb 11, 2026 Mar 05, 2026
Feb 11, 2026
Mar 05, 2026
8.7 HIGH
CVE-2023-20514 — AMD Secure Processor (ASP) Code Execution Vulnerability

Improper handling of parameters in the AMD Secure Processor (ASP) could allow a privileged attacker to pass an arbitrary memory value to functions in the trusted execution environment resulting in ar…

| Memory Corruption
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
6.4 MEDIUM
CVE-2019-25317 — Kimai 2- persistent cross-site scripting (XSS)

Kimai 2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into timesheet descriptions. Attackers can insert SVG-based XSS payloads in the desc…

kimai | Remote | Cross-Site Scripting
Feb 11, 2026 Feb 19, 2026
Feb 11, 2026
Feb 19, 2026
6.4 MEDIUM
CVE-2019-25316 — GOautodial 4.0 - 'CreateEvent' Persistent Cross-Site Scripting

GOautodial 4.0 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the event title parameter. Attackers can exploit the Cr…

goautodial goautodial_api | Remote | Cross-Site Scripting
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
6.4 MEDIUM
CVE-2019-25315 — WP Server Log Viewer 1.0 - 'logfile' Persistent Cross-Site Scripting

WordPress Server Log Viewer 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through unfiltered log file paths. Attackers can add log fil…

Remote | Cross-Site Scripting
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
6.4 MEDIUM
CVE-2019-25314 — Duplicate-Post 3.2.3 - Persistent Cross-Site Scripting

Yoast Duplicate-Post WordPress Plugin 3.2.3 contains a persistent cross-site scripting vulnerability in plugin settings parameters. Attackers can inject malicious scripts into title prefix, suffix, m…

duplicate_post | Remote | Cross-Site Scripting
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
6.4 MEDIUM
CVE-2019-25312 — InoERP 0.7.2 - Persistent Cross-Site Scripting

InoERP 0.7.2 contains a persistent cross-site scripting vulnerability in the comment section that allows unauthenticated attackers to inject malicious scripts. Attackers can submit comments with Java…

inoerp | Remote | Cross-Site Scripting
Feb 11, 2026 Mar 02, 2026
Feb 11, 2026
Mar 02, 2026
6.4 MEDIUM
CVE-2019-25311 — thesystem Persistent XSS

thesystem version 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through multiple server data input fields. Attackers can submit crafte…

password_management_application | Remote | Cross-Site Scripting
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
8.5 HIGH
CVE-2019-25310 — ActiveFax Server 6.92 Build 0316 - 'ActiveFaxServiceNT' Unquoted Service Path

ActiveFax Server 6.92 Build 0316 contains an unquoted service path vulnerability in the ActiveFaxServiceNT service that allows local attackers to potentially execute arbitrary code. Attackers can exp…

| Misconfiguration
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
8.5 HIGH
CVE-2019-25309 — Zilab Remote Console Server 3.2.9 - 'Zilab Remote Console Server' Unquoted Service Path

Zilab Remote Console Server 3.2.9 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can expl…

| Misconfiguration
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
8.5 HIGH
CVE-2019-25308 — Mikogo 5.2.2.150317 - 'Mikogo-Service' Unquoted Service Path

Mikogo 5.2.2.150317 contains an unquoted service path vulnerability in the Mikogo-Service Windows service configuration. Attackers can exploit the unquoted path to inject and execute malicious code w…

mikogo | Misconfiguration
Feb 11, 2026 Feb 26, 2026
Feb 11, 2026
Feb 26, 2026
8.5 HIGH
CVE-2019-25307 — WorkgroupMail 7.5.1 - 'WorkgroupMail' Unquoted Service Path

WorkgroupMail 7.5.1 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the u…

| Misconfiguration
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
Showing 20 of 5092 Results