Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-2321 — Google Chrome Ozone Use-After-Free Heap Corruption

Use after free in Ozone in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted H…

linux_kernel chrome macos windows | Remote | Memory Corruption
Feb 11, 2026 Feb 25, 2026
Feb 11, 2026
Feb 25, 2026
6.5 MEDIUM
CVE-2026-2320 — Google Chrome File Input UI Spoofing Vulnerability

Inappropriate implementation in File input in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafte…

linux_kernel chrome macos windows edge_chromium | Remote | Misconfiguration
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
7.5 HIGH
CVE-2026-2319 — Google Chrome DevTools Race Condition Object Corruption Vulnerability

Race in DevTools in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures and install a malicious extension to potentially exploit obje…

linux_kernel chrome macos windows edge_chromium | Remote | Race Condition
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
6.5 MEDIUM
CVE-2026-2318 — Google Chrome PictureInPicture UI Spoofing Vulnerability

Inappropriate implementation in PictureInPicture in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a …

linux_kernel chrome macos windows | Remote | Misconfiguration
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
6.5 MEDIUM
CVE-2026-2317 — Google Chrome Animation Cross-Origin Data Leak Vulnerability

Inappropriate implementation in Animation in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

linux_kernel chrome macos windows edge_chromium | Remote | Information Disclosure
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
6.5 MEDIUM
CVE-2026-2316 — Google Chrome UI Spoofing Vulnerability

Insufficient policy enforcement in Frames in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

linux_kernel chrome macos windows edge_chromium | Remote | Misconfiguration
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
8.8 HIGH
CVE-2026-2315 — Google Chrome WebGPU Out-of-Bounds Memory Access Vulnerability

Inappropriate implementation in WebGPU in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security…

linux_kernel chrome macos windows | Remote | Memory Corruption
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
8.8 HIGH
CVE-2026-2314 — Google Chrome Heap Buffer Overflow Vulnerability

Heap buffer overflow in Codecs in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

linux_kernel chrome macos windows edge_chromium | Remote | Memory Corruption
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
8.8 HIGH
CVE-2026-2313 — Google Chrome CSS Use-After-Free Heap Corruption Vulnerability

Use after free in CSS in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

linux_kernel chrome macos windows edge_chromium | Remote | Memory Corruption
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
6.1 MEDIUM
CVE-2025-70297 — Mealie XSS Stored Vulnerability

A stored cross-site scripting (XSS) vulnerability in the recipe asset upload and media serving component in Mealie 3.3.1 allows remote authenticated users to inject arbitrary web script or HTML via a…

mealie | Remote | Cross-Site Scripting
Feb 11, 2026 Feb 23, 2026
Feb 11, 2026
Feb 23, 2026
5.4 MEDIUM
CVE-2025-70296 — Mealie Stored HTML Injection Vulnerability

A stored HTML injection vulnerability in the Recipe Notes rendering component in Mealie 3.3.1 allows remote authenticated users to inject arbitrary HTML, resulting in user interface redressing within…

mealie | Remote | Cross-Site Scripting
Feb 11, 2026 Feb 23, 2026
Feb 11, 2026
Feb 23, 2026
7.5 HIGH
CVE-2025-69873 — Ajv Regular Expression Denial of Service (ReDoS)

ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Poi…

ajv ajv | Remote | Denial of Service
Feb 11, 2026 Mar 02, 2026
Feb 11, 2026
Mar 02, 2026
9.8 CRITICAL
CVE-2025-69872 — DiskCache Python Pickle Deserialization Code Execution Vulnerability

DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache directory can achieve arbitrary code execution when a victim app…

Remote | Misconfiguration
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
8.1 HIGH
CVE-2025-69871 — MedusaJS Promotion Module Unauthenticated Race Condition Vulnerability

A race condition vulnerability exists in MedusaJS Medusa v2.12.2 and earlier in the registerUsage() function of the promotion module. The function performs a non-atomic read-check-update operation wh…

Remote | Race Condition
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
8.0 HIGH
CVE-2026-2361 — Improper search_path protection in PostgreSQL Anonymizer 2.5 allows any user with create …

PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a temporary view based on a function containing malicious code. When the anon.get_tablesampl…

anonymizer | Authorization
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
8.0 HIGH
CVE-2026-2360 — Improper search_path protection in PostgreSQL Anonymizer 2.5 allows any user to gain supe…

PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a custom operator in the public schema and place malicious code in that operator. This opera…

anonymizer | Authentication
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
6.6 MEDIUM
CVE-2026-0229 — PAN-OS: Denial of Service in Advanced DNS Security Feature

A denial-of-service (DoS) vulnerability in the Advanced DNS Security (ADNS) feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a malic…

pan-os | Remote | Denial of Service
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
1.3 LOW
CVE-2026-0228 — PAN-OS: Improper Validation of Terminal Server Agent Certificate

An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server Agents on Windows to PAN-OS using expired certificates even if the PAN-OS configuration would not no…

pan-os prisma_access | Remote | Misconfiguration
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
9.8 CRITICAL
CVE-2025-70085 — OpenSatKit Stack Buffer Overflow

An issue was discovered in OpenSatKit 2.2.1. The EventErrStr buffer has a fixed size of 256 bytes. The code uses sprintf to format two filenames (Source1Filename and the string returned by FileUtil_F…

opensatkit | Remote | Memory Corruption
Feb 11, 2026 Feb 17, 2026
Feb 11, 2026
Feb 17, 2026
7.5 HIGH
CVE-2025-70084 — OpenSatKit Directory Traversal Vulnerability

Directory traversal vulnerability in OpenSatKit 2.2.1 allows attackers to gain access to sensitive information or delete arbitrary files via crafted value to the FileUtil_GetFileInfo function.

opensatkit | Remote | Path Traversal
Feb 11, 2026 Feb 17, 2026
Feb 11, 2026
Feb 17, 2026
Showing 20 of 5071 Results