Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2025-48022 — Yokogawa Electric Corporation Vnet/IP Interface Package Denial of Service (DoS) Vulnerabi…

A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receives maliciously crafted packets, Vnet/IP software stack process may be …

Feb 13, 2026 Mar 02, 2026
Feb 13, 2026
Mar 02, 2026
6.5 MEDIUM
CVE-2025-48021 — Yokogawa Electric Corporation Vnet/IP Interface Package Denial of Service

A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receives maliciously crafted packets, Vnet/IP software stack process may be …

Feb 13, 2026 Mar 02, 2026
Feb 13, 2026
Mar 02, 2026
4.3 MEDIUM
CVE-2025-15520 — RegistrationMagic <= 6.0.7.2 - Subscriber+ Sensitive Data Disclosure

The RegistrationMagic WordPress plugin before 6.0.7.2 checks nonces but not capabilities, allowing for the disclosure of some sensitive data to subscribers and above.

registrationmagic | Remote | Authorization
Feb 13, 2026 Feb 13, 2026
Feb 13, 2026
Feb 13, 2026
6.5 MEDIUM
CVE-2025-48020 — Yokogawa Electric Corporation Vnet/IP Interface Package Denial of Service

A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receives maliciously crafted packets, Vnet/IP software stack process may be …

Feb 13, 2026 Mar 02, 2026
Feb 13, 2026
Mar 02, 2026
6.5 MEDIUM
CVE-2025-48019 — Yokogawa Electric Corporation Vnet/IP Interface Package Denial of Service Vulnerability

A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receives maliciously crafted packets, Vnet/IP software stack process may be …

Feb 13, 2026 Mar 02, 2026
Feb 13, 2026
Mar 02, 2026
8.2 HIGH
CVE-2025-1924 — Yokogawa Vnet/IP Interface Package Remote DoS and Execution of Arbitrary Code Vulnerabili…

A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receive maliciously crafted packets, a DoS attack may cause Vnet/IP communic…

Feb 13, 2026 Mar 02, 2026
Feb 13, 2026
Mar 02, 2026
8.8 HIGH
CVE-2026-25108 — Soliton Systems K.K FileZen OS Command Injection Vulnerability - [Actively Exploited]

FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command.

filezen | CISA KEV Remote | Injection
Feb 13, 2026 Feb 24, 2026
Feb 13, 2026
Feb 24, 2026
6.2 MEDIUM
CVE-2026-1721 — Reflected Cross-Site Scripting (XSS) vulnerability in AI Playground site

Summary A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the AI Playground's OAuth callback handler. The `error_description` query parameter was directly interpolated into an H…

Remote | Cross-Site Scripting
Feb 13, 2026 Feb 27, 2026
Feb 13, 2026
Feb 27, 2026
7.7 HIGH
CVE-2025-9293 — Insufficient Certificate Validation in Multiple Mobile Applications Allows Man in the Mid…

A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS communication. An attacker in a privileged network …

Remote | Cryptography
Feb 13, 2026 Feb 13, 2026
Feb 13, 2026
Feb 13, 2026
2.0 LOW
CVE-2025-9292 — Permissive Web Security Policy Allows Cross-Origin Access Control Bypass on Omada Cloud C…

A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. Exploitation requires the presence of an existing…

Remote | Misconfiguration
Feb 13, 2026 Feb 13, 2026
Feb 13, 2026
Feb 13, 2026
7.3 HIGH
CVE-2025-40905 — WWW::OAuth 1.000 and earlier for Perl uses insecure rand() function for cryptographic fun…

WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions.

Remote | Cryptography
Feb 13, 2026 Feb 17, 2026
Feb 13, 2026
Feb 17, 2026
6.0 MEDIUM
CVE-2024-21961 — Intel PCIe Link Buffer Overflow Vulnerability

Improper restriction of operations within the bounds of a memory buffer in PCIe® Link could allow an attacker with access to a guest virtual machine to potentially perform a denial of service attack …

Remote | Memory Corruption
Feb 13, 2026 Feb 13, 2026
Feb 13, 2026
Feb 13, 2026
5.4 MEDIUM
CVE-2026-26188 — Solspace Freeform plugin affected by Stored Cross-Site Scripting (XSS) in Freeform Craft …

Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building tool. An authenticated, low-privilege user (able to create/edit forms) can inject arbitrary HTML/JS into the Craft Control…

freeform | Remote | Cross-Site Scripting
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
5.5 MEDIUM
CVE-2025-70092 — OpenSourcePOS XSS Vulnerability in Item Kits Function

A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Item Na…

open_source_point_of_sale | Remote | Cross-Site Scripting
Feb 12, 2026 Feb 18, 2026
Feb 12, 2026
Feb 18, 2026
9.8 CRITICAL
CVE-2020-37167 — ClamAV ClamBC < 0.103.0-rc - 'ClamBC' Executable Regular Expression Error

ClamAV versions prior to 0.103.0-rc contain a vulnerability in function name processing through the ClamBC bytecode interpreter that allows attackers to manipulate bytecode function names. Attackers …

clamav | Remote | Injection
Feb 12, 2026 Feb 27, 2026
Feb 12, 2026
Feb 27, 2026
7.5 HIGH
CVE-2019-25342 — Centova Cast 3.2.12 - Denial of Service

Centova Cast 3.2.12 contains a denial of service vulnerability that allows attackers to overwhelm the system by repeatedly calling the database export API endpoint. Attackers can trigger 100% CPU loa…

Remote | Denial of Service
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
7.5 HIGH
CVE-2019-25341 — iNetTools for iOS 8.20 - 'Whois' Denial of Service

iNetTools for iOS 8.20 contains a denial of service vulnerability in the Whois feature that allows attackers to crash the application by manipulating input. Attackers can paste a specially crafted 98…

Remote | Denial of Service
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
7.5 HIGH
CVE-2019-25340 — SpotAuditor 5.3.2 - 'Base64' Denial Of Service

SpotAuditor 5.3.2 contains a denial of service vulnerability in its Base64 decryption feature that allows attackers to crash the application by supplying an oversized buffer. Attackers can generate a…

spotauditor | Remote | Denial of Service
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
7.5 HIGH
CVE-2019-25339 — GHIA CamIP 1.2 for iOS - 'Password' Denial of Service

GHIA CamIP 1.2 for iOS contains a denial of service vulnerability in the password input field that allows attackers to crash the application. Attackers can paste a 33-character buffer of repeated cha…

Remote | Denial of Service
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
7.5 HIGH
CVE-2019-25338 — Dokuwiki 2018-04-22b - Username Enumeration

DokuWiki 2018-04-22b contains a username enumeration vulnerability in its password reset functionality that allows attackers to identify valid user accounts. Attackers can submit different usernames …

dokuwiki | Remote | Information Disclosure
Feb 12, 2026 Mar 02, 2026
Feb 12, 2026
Mar 02, 2026
Showing 20 of 5011 Results