Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
2.5 LOW
CVE-2026-0872 — Improper Certificate Validation vulnerability in Thales SafeNet Agent for Windows Logon

Improper Certificate Validation vulnerability in Thales SafeNet Agent for Windows Logon on Windows allows Signature Spoofing by Improper Validation.This issue affects SafeNet Agent for Windows Logon:…

safenet_agent_for_windows_logon | Remote | Cryptography
Feb 13, 2026 Feb 13, 2026
Feb 13, 2026
Feb 13, 2026
6.5 MEDIUM
CVE-2025-48023 — Yokogawa Electric Corporation Vnet/IP Interface Package Denial of Service (DoS)

A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receives maliciously crafted packets, Vnet/IP software stack process may be …

Feb 13, 2026 Mar 02, 2026
Feb 13, 2026
Mar 02, 2026
6.5 MEDIUM
CVE-2025-48022 — Yokogawa Electric Corporation Vnet/IP Interface Package Denial of Service (DoS) Vulnerabi…

A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receives maliciously crafted packets, Vnet/IP software stack process may be …

Feb 13, 2026 Mar 02, 2026
Feb 13, 2026
Mar 02, 2026
6.5 MEDIUM
CVE-2025-48021 — Yokogawa Electric Corporation Vnet/IP Interface Package Denial of Service

A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receives maliciously crafted packets, Vnet/IP software stack process may be …

Feb 13, 2026 Mar 02, 2026
Feb 13, 2026
Mar 02, 2026
4.3 MEDIUM
CVE-2025-15520 — RegistrationMagic <= 6.0.7.2 - Subscriber+ Sensitive Data Disclosure

The RegistrationMagic WordPress plugin before 6.0.7.2 checks nonces but not capabilities, allowing for the disclosure of some sensitive data to subscribers and above.

registrationmagic | Remote | Authorization
Feb 13, 2026 Feb 13, 2026
Feb 13, 2026
Feb 13, 2026
6.5 MEDIUM
CVE-2025-48020 — Yokogawa Electric Corporation Vnet/IP Interface Package Denial of Service

A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receives maliciously crafted packets, Vnet/IP software stack process may be …

Feb 13, 2026 Mar 02, 2026
Feb 13, 2026
Mar 02, 2026
6.5 MEDIUM
CVE-2025-48019 — Yokogawa Electric Corporation Vnet/IP Interface Package Denial of Service Vulnerability

A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receives maliciously crafted packets, Vnet/IP software stack process may be …

Feb 13, 2026 Mar 02, 2026
Feb 13, 2026
Mar 02, 2026
8.2 HIGH
CVE-2025-1924 — Yokogawa Vnet/IP Interface Package Remote DoS and Execution of Arbitrary Code Vulnerabili…

A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receive maliciously crafted packets, a DoS attack may cause Vnet/IP communic…

Feb 13, 2026 Mar 02, 2026
Feb 13, 2026
Mar 02, 2026
8.8 HIGH
CVE-2026-25108 — Soliton Systems K.K FileZen OS Command Injection Vulnerability - [Actively Exploited]

FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command.

filezen | CISA KEV Remote | Injection
Feb 13, 2026 Feb 24, 2026
Feb 13, 2026
Feb 24, 2026
6.2 MEDIUM
CVE-2026-1721 — Reflected Cross-Site Scripting (XSS) vulnerability in AI Playground site

Summary A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the AI Playground's OAuth callback handler. The `error_description` query parameter was directly interpolated into an H…

Remote | Cross-Site Scripting
Feb 13, 2026 Feb 27, 2026
Feb 13, 2026
Feb 27, 2026
7.7 HIGH
CVE-2025-9293 — Insufficient Certificate Validation in Multiple Mobile Applications Allows Man in the Mid…

A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS communication. An attacker in a privileged network …

Remote | Cryptography
Feb 13, 2026 Feb 13, 2026
Feb 13, 2026
Feb 13, 2026
2.0 LOW
CVE-2025-9292 — Permissive Web Security Policy Allows Cross-Origin Access Control Bypass on Omada Cloud C…

A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. Exploitation requires the presence of an existing…

Remote | Misconfiguration
Feb 13, 2026 Feb 13, 2026
Feb 13, 2026
Feb 13, 2026
7.3 HIGH
CVE-2025-40905 — WWW::OAuth 1.000 and earlier for Perl uses insecure rand() function for cryptographic fun…

WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions.

Remote | Cryptography
Feb 13, 2026 Feb 17, 2026
Feb 13, 2026
Feb 17, 2026
6.0 MEDIUM
CVE-2024-21961 — Intel PCIe Link Buffer Overflow Vulnerability

Improper restriction of operations within the bounds of a memory buffer in PCIe® Link could allow an attacker with access to a guest virtual machine to potentially perform a denial of service attack …

Remote | Memory Corruption
Feb 13, 2026 Feb 13, 2026
Feb 13, 2026
Feb 13, 2026
5.4 MEDIUM
CVE-2026-26188 — Solspace Freeform plugin affected by Stored Cross-Site Scripting (XSS) in Freeform Craft …

Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building tool. An authenticated, low-privilege user (able to create/edit forms) can inject arbitrary HTML/JS into the Craft Control…

freeform | Remote | Cross-Site Scripting
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
5.5 MEDIUM
CVE-2025-70092 — OpenSourcePOS XSS Vulnerability in Item Kits Function

A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Item Na…

open_source_point_of_sale | Remote | Cross-Site Scripting
Feb 12, 2026 Feb 18, 2026
Feb 12, 2026
Feb 18, 2026
9.8 CRITICAL
CVE-2020-37167 — ClamAV ClamBC < 0.103.0-rc - 'ClamBC' Executable Regular Expression Error

ClamAV versions prior to 0.103.0-rc contain a vulnerability in function name processing through the ClamBC bytecode interpreter that allows attackers to manipulate bytecode function names. Attackers …

clamav | Remote | Injection
Feb 12, 2026 Feb 27, 2026
Feb 12, 2026
Feb 27, 2026
7.5 HIGH
CVE-2019-25342 — Centova Cast 3.2.12 - Denial of Service

Centova Cast 3.2.12 contains a denial of service vulnerability that allows attackers to overwhelm the system by repeatedly calling the database export API endpoint. Attackers can trigger 100% CPU loa…

Remote | Denial of Service
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
7.5 HIGH
CVE-2019-25341 — iNetTools for iOS 8.20 - 'Whois' Denial of Service

iNetTools for iOS 8.20 contains a denial of service vulnerability in the Whois feature that allows attackers to crash the application by manipulating input. Attackers can paste a specially crafted 98…

Remote | Denial of Service
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
7.5 HIGH
CVE-2019-25340 — SpotAuditor 5.3.2 - 'Base64' Denial Of Service

SpotAuditor 5.3.2 contains a denial of service vulnerability in its Base64 decryption feature that allows attackers to crash the application by supplying an oversized buffer. Attackers can generate a…

spotauditor | Remote | Denial of Service
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
Showing 20 of 5013 Results