Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2025-70121 — Free5GC AMF Array Index Out of Bounds Denial of Service

An array index out of bounds vulnerability in the AMF component of free5GC v4.0.1 allows remote attackers to cause a denial of service via a crafted 5GS Mobile Identity in a NAS Registration Request …

free5gc | Remote | Denial of Service
Feb 13, 2026 Feb 18, 2026
Feb 13, 2026
Feb 18, 2026
5.8 MEDIUM
CVE-2025-1790 — Genetec Sipelia Plugin Privilege Escalation Vulnerability

Local privilege escalation in Genetec Sipelia Plugin. An authenticated low-privileged Windows user could exploit this vulnerability to gain elevated privileges on the affected system.

| Authorization
Feb 13, 2026 Feb 13, 2026
Feb 13, 2026
Feb 13, 2026
10.0 CRITICAL
CVE-2026-26221 — Hyland OnBase Timer Services Unauthenticated .NET Remoting RCE

Hyland OnBase contains an unauthenticated .NET Remoting exposure in the OnBase Workflow Timer Service (Hyland.Core.Workflow.NTService.exe). An attacker who can reach the service can send crafted .NET…

onbase | Remote | Information Disclosure
Feb 13, 2026 Feb 13, 2026
Feb 13, 2026
Feb 13, 2026
6.5 MEDIUM
CVE-2025-70095 — OpenSourcePOS Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted …

open_source_point_of_sale | Remote | Cross-Site Scripting
Feb 13, 2026 Feb 17, 2026
Feb 13, 2026
Feb 17, 2026
6.5 MEDIUM
CVE-2025-70094 — OpenSourcePOS Cross-Site Scripting (XSS) Vulnerability

A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into…

open_source_point_of_sale | Remote | Cross-Site Scripting
Feb 13, 2026 Feb 17, 2026
Feb 13, 2026
Feb 17, 2026
7.4 HIGH
CVE-2025-70093 — OpenSourcePOS Remote Code Execution (RCE)

An issue in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code via returning a crafted AJAX response.

open_source_point_of_sale | Remote | Injection
Feb 13, 2026 Feb 17, 2026
Feb 13, 2026
Feb 17, 2026
6.5 MEDIUM
CVE-2025-70091 — OpenSourcePOS XSS Vulnerability

A cross-site scripting (XSS) vulnerability in the Customers function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Phone N…

open_source_point_of_sale | Remote | Cross-Site Scripting
Feb 13, 2026 Feb 17, 2026
Feb 13, 2026
Feb 17, 2026
4.3 MEDIUM
CVE-2026-25531 — Kanboard TaskCreationController::duplicateProjects() endpoint does not validate user perm…

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, The fix for CVE-2023-33968 is incomplete. The TaskCreationController::duplicateProjects() endpoint does not val…

kanboard | Remote | Authorization
Feb 13, 2026 Feb 13, 2026
Feb 13, 2026
Feb 13, 2026
5.1 MEDIUM
CVE-2026-1578 — HP App – Potential Cross-Site Scripting

HP App for Android is potentially vulnerable to cross-site scripting (XSS) when using an outdated version of the application via mobile devices. HP is releasing updates to mitigate these potential vu…

| Cross-Site Scripting
Feb 13, 2026 Feb 13, 2026
Feb 13, 2026
Feb 13, 2026
0.0 NA
CVE-2026-23112 — nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec nvmet_tcp_build_pdu_iovec() could walk past cmd->req.sg when a PDU leng…

linux_kernel | Memory Corruption
Feb 13, 2026 Feb 13, 2026
Feb 13, 2026
Feb 13, 2026
0.0 NA
CVE-2026-23111 — netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate()

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate() nft_map_catchall_activate() has an inverted eleme…

linux_kernel | Memory Corruption
Feb 13, 2026 Feb 13, 2026
Feb 13, 2026
Feb 13, 2026
8.3 HIGH
CVE-2026-1619 — IDOR in Universal Sotware's FlexCity/Kiosk

Authorization Bypass Through User-Controlled Key vulnerability in Universal Software Inc. FlexCity/Kiosk allows Exploitation of Trusted Identifiers.This issue affects FlexCity/Kiosk: from 1.0 before …

flexcity | Remote | Authorization
Feb 13, 2026 Mar 02, 2026
Feb 13, 2026
Mar 02, 2026
8.8 HIGH
CVE-2026-1618 — Admin Account Takeover in Universal Sotware's FlexCity/Kiosk

Authentication Bypass Using an Alternate Path or Channel vulnerability in Universal Software Inc. FlexCity/Kiosk allows Privilege Escalation.This issue affects FlexCity/Kiosk: from 1.0 before 1.0.36.

flexcity | Remote | Authentication
Feb 13, 2026 Mar 02, 2026
Feb 13, 2026
Mar 02, 2026
8.8 HIGH
CVE-2025-14349 — Business Logic Error in Universal Software's FlexCity/Kiosk

Privilege Defined With Unsafe Actions, Missing Authentication for Critical Function vulnerability in Universal Software Inc. FlexCity/Kiosk allows Accessing Functionality Not Properly Constrained by …

flexcity | Remote | Authorization
Feb 13, 2026 Mar 02, 2026
Feb 13, 2026
Mar 02, 2026
5.3 MEDIUM
CVE-2026-2443 — Libsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information d…

A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. I…

Remote | Memory Corruption
Feb 13, 2026 Feb 13, 2026
Feb 13, 2026
Feb 13, 2026
7.3 HIGH
CVE-2025-33042 — Apache Avro Java SDK: Code injection on Java generated code

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK:…

avro | Remote | Injection
Feb 13, 2026 Feb 20, 2026
Feb 13, 2026
Feb 20, 2026
4.3 MEDIUM
CVE-2026-22892 — Insufficient Authorization in Mattermost Jira Plugin Allows Unauthorized Access to Post A…

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to validate user permissions when creating Jira issues from Mattermost posts, which allows an authenticated attacker wi…

mattermost_server | Remote | Authorization
Feb 13, 2026 Feb 18, 2026
Feb 13, 2026
Feb 18, 2026
3.1 LOW
CVE-2026-20796 — Time-of-check time-of-use vulnerability in common teams API

Mattermost versions 10.11.x <= 10.11.9 fail to properly validate channel membership at the time of data retrieval which allows a deactivated user to learn team names they should not have access to vi…

mattermost_server | Remote | Race Condition
Feb 13, 2026 Feb 23, 2026
Feb 13, 2026
Feb 23, 2026
2.5 LOW
CVE-2026-0872 — Improper Certificate Validation vulnerability in Thales SafeNet Agent for Windows Logon

Improper Certificate Validation vulnerability in Thales SafeNet Agent for Windows Logon on Windows allows Signature Spoofing by Improper Validation.This issue affects SafeNet Agent for Windows Logon:…

safenet_agent_for_windows_logon | Remote | Cryptography
Feb 13, 2026 Feb 13, 2026
Feb 13, 2026
Feb 13, 2026
6.5 MEDIUM
CVE-2025-48023 — Yokogawa Electric Corporation Vnet/IP Interface Package Denial of Service (DoS)

A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receives maliciously crafted packets, Vnet/IP software stack process may be …

Feb 13, 2026 Mar 02, 2026
Feb 13, 2026
Mar 02, 2026
Showing 20 of 5026 Results