Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2020-37104 — ASTPP 4.0.1 VoIP Billing - Database Backup Download

ASTPP 4.0.1 contains an information disclosure vulnerability that allows unauthenticated attackers to download database backup files by predicting backup filename patterns. Attackers can generate a l…

astpp | Remote | Information Disclosure
Feb 11, 2026 Feb 20, 2026
Feb 11, 2026
Feb 20, 2026
5.1 MEDIUM
CVE-2019-25313 — FlexNet Publisher 11.12.1 - Cross-Site Request Forgery (Add Local Admin)

FlexNet Publisher 11.12.1 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without authentication. Attackers can craft a malicious HTML…

flexnet_publisher flexnet_publisher | Remote | Cross-Site Request Forgery
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
4.3 MEDIUM
CVE-2024-50618 — CIPPlanner CIPAce Single-Factor Authentication Bypass Vulnerability

A Use of Single-factor Authentication vulnerability in the Authentication component of CIPPlanner CIPAce before 9.17 allows attackers to bypass a protection mechanism. When the system is configured t…

cipace | Remote | Authentication
Feb 11, 2026 Feb 17, 2026
Feb 11, 2026
Feb 17, 2026
7.5 HIGH
CVE-2024-26480 — Statping-ng Information Disclosure

An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the admin parameter.

statping-ng | Remote | Information Disclosure
Feb 11, 2026 Feb 28, 2026
Feb 11, 2026
Feb 28, 2026
5.3 MEDIUM
CVE-2024-26479 — Statping-ng Command Execution Information Disclosure

An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the Command execution function.

statping-ng | Remote | Information Disclosure
Feb 11, 2026 Feb 26, 2026
Feb 11, 2026
Feb 26, 2026
5.3 MEDIUM
CVE-2024-26478 — Statping-ng Information Disclosure

An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the /api/users endpoint.

statping-ng | Remote | Information Disclosure
Feb 11, 2026 Feb 26, 2026
Feb 11, 2026
Feb 26, 2026
7.5 HIGH
CVE-2024-26477 — Statping-ng Information Disclosure

An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the api parameter of the oauth, amazon_sns, export endpoints.

statping-ng | Remote | Information Disclosure
Feb 11, 2026 Feb 26, 2026
Feb 11, 2026
Feb 26, 2026
5.4 MEDIUM
CVE-2026-2323 — Google Chrome UI Spoofing Vulnerability

Inappropriate implementation in Downloads in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

linux_kernel chrome macos windows edge_chromium | Remote | Misconfiguration
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
5.4 MEDIUM
CVE-2026-2322 — Google Chrome UI Spoofing Vulnerability

Inappropriate implementation in File input in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafte…

linux_kernel chrome macos windows edge_chromium | Remote | Misconfiguration
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
8.8 HIGH
CVE-2026-2321 — Google Chrome Ozone Use-After-Free Heap Corruption

Use after free in Ozone in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted H…

linux_kernel chrome macos windows | Remote | Memory Corruption
Feb 11, 2026 Feb 25, 2026
Feb 11, 2026
Feb 25, 2026
6.5 MEDIUM
CVE-2026-2320 — Google Chrome File Input UI Spoofing Vulnerability

Inappropriate implementation in File input in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafte…

linux_kernel chrome macos windows edge_chromium | Remote | Misconfiguration
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
7.5 HIGH
CVE-2026-2319 — Google Chrome DevTools Race Condition Object Corruption Vulnerability

Race in DevTools in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures and install a malicious extension to potentially exploit obje…

linux_kernel chrome macos windows edge_chromium | Remote | Race Condition
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
6.5 MEDIUM
CVE-2026-2318 — Google Chrome PictureInPicture UI Spoofing Vulnerability

Inappropriate implementation in PictureInPicture in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a …

linux_kernel chrome macos windows | Remote | Misconfiguration
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
6.5 MEDIUM
CVE-2026-2317 — Google Chrome Animation Cross-Origin Data Leak Vulnerability

Inappropriate implementation in Animation in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

linux_kernel chrome macos windows edge_chromium | Remote | Information Disclosure
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
6.5 MEDIUM
CVE-2026-2316 — Google Chrome UI Spoofing Vulnerability

Insufficient policy enforcement in Frames in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

linux_kernel chrome macos windows edge_chromium | Remote | Misconfiguration
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
8.8 HIGH
CVE-2026-2315 — Google Chrome WebGPU Out-of-Bounds Memory Access Vulnerability

Inappropriate implementation in WebGPU in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security…

linux_kernel chrome macos windows | Remote | Memory Corruption
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
8.8 HIGH
CVE-2026-2314 — Google Chrome Heap Buffer Overflow Vulnerability

Heap buffer overflow in Codecs in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

linux_kernel chrome macos windows edge_chromium | Remote | Memory Corruption
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
8.8 HIGH
CVE-2026-2313 — Google Chrome CSS Use-After-Free Heap Corruption Vulnerability

Use after free in CSS in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

linux_kernel chrome macos windows edge_chromium | Remote | Memory Corruption
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
6.1 MEDIUM
CVE-2025-70297 — Mealie XSS Stored Vulnerability

A stored cross-site scripting (XSS) vulnerability in the recipe asset upload and media serving component in Mealie 3.3.1 allows remote authenticated users to inject arbitrary web script or HTML via a…

mealie | Remote | Cross-Site Scripting
Feb 11, 2026 Feb 23, 2026
Feb 11, 2026
Feb 23, 2026
5.4 MEDIUM
CVE-2025-70296 — Mealie Stored HTML Injection Vulnerability

A stored HTML injection vulnerability in the Recipe Notes rendering component in Mealie 3.3.1 allows remote authenticated users to inject arbitrary HTML, resulting in user interface redressing within…

mealie | Remote | Cross-Site Scripting
Feb 11, 2026 Feb 23, 2026
Feb 11, 2026
Feb 23, 2026
Showing 20 of 5087 Results