Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.5 MEDIUM
CVE-2025-70347 — MQuickJS Denial of Service Vulnerability

An issue in mquickjs before commit 74b7e (2026-01-15) allows a local attacker to cause a denial of service via a crafted file to the get_mblock_size function at mquickjs.c.

| Denial of Service
Feb 10, 2026 Feb 18, 2026
Feb 10, 2026
Feb 18, 2026
5.9 MEDIUM
CVE-2025-68686 — Fortinet FortiOS Sensitive Information Exposure

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, For…

fortios | Remote | Information Disclosure
Feb 10, 2026 Feb 12, 2026
Feb 10, 2026
Feb 12, 2026
7.2 HIGH
CVE-2025-64157 — Fortinet FortiOS Format String Vulnerability

A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0 all versions allows an authe…

fortios | Remote | Injection
Feb 10, 2026 Feb 12, 2026
Feb 10, 2026
Feb 12, 2026
7.1 HIGH
CVE-2025-62676 — Fortinet FortiClient Link Following File Write Vulnerability

An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.4, FortiClientWindows 7.2.0 through 7.2.12, For…

forticlient forticlientwindows | Path Traversal
Feb 10, 2026 Feb 12, 2026
Feb 10, 2026
Feb 12, 2026
4.2 MEDIUM
CVE-2025-62439 — Fortinet FortiOS Improper Verification of Source of a Communication Channel Vulnerability

An Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, For…

fortios | Authorization
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
5.8 MEDIUM
CVE-2025-55018 — Fortinet FortiOS HTTP Request Smuggling Vulnerability

An inconsistent interpretation of http requests ('http request smuggling') vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, Fo…

fortios | Remote | Injection
Feb 10, 2026 Feb 23, 2026
Feb 10, 2026
Feb 23, 2026
9.6 CRITICAL
CVE-2025-52436 — Fortinet FortiSandbox Cross-Site Scripting Vulnerability

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4…

fortisandbox | Remote | Cross-Site Scripting
Feb 10, 2026 Feb 18, 2026
Feb 10, 2026
Feb 18, 2026
5.5 MEDIUM
CVE-2025-15572 — wasm3 NewCodePage memory leak

A vulnerability has been found in wasm3 up to 0.5.0. The affected element is the function NewCodePage. The manipulation leads to memory leak. The attack must be carried out locally. The exploit has b…

wasm3 | Memory Corruption
Feb 10, 2026 Feb 12, 2026
Feb 10, 2026
Feb 12, 2026
7.5 HIGH
CVE-2025-11004 — Reflected XSS vulnerability in Simplicity Device Manager tool

The Simplicity Device Manager Tool has a Reflected XSS (Cross-site-scripting) vulnerability in several API endpoints. The attacker needs to be on the same network to execute this attack. These APIs c…

Remote | Cross-Site Scripting
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
5.5 MEDIUM
CVE-2024-54192 — Tcpreplay Denial of Service Vulnerability

An issue inTcpreplay v4.5.1 allows a local attacker to cause a denial of service via a crafted file to the tcpedit_dlt_getplugin function at src/tcpedit/plugins/dlt_utils.c.

| Denial of Service
Feb 10, 2026 Feb 18, 2026
Feb 10, 2026
Feb 18, 2026
8.8 HIGH
CVE-2025-7636 — SQLi in Ergosis Security Systems' ZEUS PDKS

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ergosis Security Systems Computer Industry and Trade Inc. ZEUS PDKS allows SQL Injection.This iss…

Remote | Injection
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
8.8 HIGH
CVE-2025-7347 — IDOR in Dinibh Puzzle's Dinibh Patrol Tracking System

Authorization Bypass Through User-Controlled Key vulnerability in Dinibh Puzzle Software Solutions Dinibh Patrol Tracking System allows Exploitation of Trusted Identifiers.This issue affects Dinibh P…

Remote | Authorization
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
5.5 MEDIUM
CVE-2025-15571 — ckolivas lrzip stream.c ucompthread null pointer dereference

A security vulnerability has been detected in ckolivas lrzip up to 0.651. This vulnerability affects the function ucompthread of the file stream.c. Such manipulation leads to null pointer dereference…

lrzip | Denial of Service
Feb 10, 2026 Feb 27, 2026
Feb 10, 2026
Feb 27, 2026
8.7 HIGH
CVE-2025-6967 — Authentication Bypass in Sarman Soft's CMS

Execution After Redirect (EAR) vulnerability in Sarman Soft Software and Technology Services Industry and Trade Ltd. Co. CMS allows JSON Hijacking (aka JavaScript Hijacking), Authentication Bypass.Th…

Remote | Authentication
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
7.8 HIGH
CVE-2025-15570 — ckolivas lrzip stream.c lzma_decompress_buf use after free

A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the function lzma_decompress_buf of the file stream.c. Performing a manipulation results in use after free. Attacking locally is …

lrzip | Memory Corruption
Feb 10, 2026 Feb 27, 2026
Feb 10, 2026
Feb 27, 2026
7.3 HIGH
CVE-2025-15569 — Artifex MuPDF win_main.c get_system_dpi uncontrolled search path

A flaw has been found in Artifex MuPDF up to 1.26.1 on Windows. The impacted element is the function get_system_dpi of the file platform/x11/win_main.c. This manipulation causes uncontrolled search p…

mupdf | Path Traversal
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
5.0 MEDIUM
CVE-2025-11537 — Keycloak-server: sensitive headers shown in the http access logs

A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre-defined 'long' pattern), sensitive headers including Authorization and Cookie …

| Information Disclosure
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
7.5 HIGH
CVE-2026-2268 — Ninja Forms <= 3.14.0 - Unauthenticated Information Disclosure in nf_ajax_submit AJAX Act…

The Ninja Forms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.0. This is due to the unsafe application of the `ninja_forms_merge_tags…

ninja_forms | Remote | Information Disclosure
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
8.5 HIGH
CVE-2026-25656 — SINEC NMS Privilege Escalation Vulnerability

A vulnerability has been identified in SINEC NMS (All versions), User Management Component (UMC) (All versions < V2.15.2.1). The affected application permits improper modification of a configuration …

Feb 10, 2026 Feb 12, 2026
Feb 10, 2026
Feb 12, 2026
8.5 HIGH
CVE-2026-25655 — SINEC NMS Privilege Escalation Remote Code Execution Vulnerability

A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP2). The affected application permits improper modification of a configuration file by a low-privileged user. This could allow …

sinec_nms | Misconfiguration
Feb 10, 2026 Feb 12, 2026
Feb 10, 2026
Feb 12, 2026
Showing 20 of 5117 Results