Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-20846 — GDI+ Denial of Service Vulnerability

Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.

Feb 10, 2026 Feb 11, 2026
Feb 10, 2026
Feb 11, 2026
8.8 HIGH
CVE-2026-20841 — Windows Notepad App Remote Code Execution Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code locally.

window_notepad windows_notepad | Remote | Injection
Feb 10, 2026 Feb 25, 2026
Feb 10, 2026
Feb 25, 2026
6.9 MEDIUM
CVE-2026-1997 — Certain HP OfficeJet Pro Printers - Information Disclosure

Certain HP OfficeJet Pro printers may expose information if Cross‑Origin Resource Sharing (CORS) is misconfigured, potentially allowing unauthorized web origins to access device resource. CORS is di…

Feb 10, 2026 Feb 12, 2026
Feb 10, 2026
Feb 12, 2026
6.9 MEDIUM
CVE-2026-1996 — Certain HP OfficeJet Pro Printers – Denial of Service

Certain HP OfficeJet Pro printers may be vulnerable to potential denial of service when the IPP requests are mishandled, failing to establish a TCP connection.

Feb 10, 2026 Feb 24, 2026
Feb 10, 2026
Feb 24, 2026
7.2 HIGH
CVE-2026-0653 — Insecure Access Control on TP-Link Tapo D235 and C260

On TP-Link Tapo C260 v1, a guest‑level authenticated user can bypass intended access restrictions by sending crafted requests to a synchronization endpoint. This allows modification of protected devi…

tapo_c260_firmware tapo_c260 | Remote | Authorization
Feb 10, 2026 Feb 13, 2026
Feb 10, 2026
Feb 13, 2026
8.8 HIGH
CVE-2026-0652 — Remote Code Execution on TP-Link Tapo C260 by Guest User

On TP-Link Tapo C260 v1, command injection vulnerability exists due to improper sanitization in certain POST parameters during configuration synchronization. An authenticated attacker can execute arb…

tapo_c260_firmware tapo_c260 | Remote | Injection
Feb 10, 2026 Feb 13, 2026
Feb 10, 2026
Feb 13, 2026
7.8 HIGH
CVE-2026-0651 — Path Traversal on TP-Link Tapo D235 and C260 via Local https

On TP-Link Tapo C260 v1, path traversal is possible due to improper handling of specific GET request paths via https, allowing local unauthenticated probing of filesystem paths. An attacker on the lo…

tapo_c260_firmware tapo_c260 | Path Traversal
Feb 10, 2026 Feb 13, 2026
Feb 10, 2026
Feb 13, 2026
4.3 MEDIUM
CVE-2026-25530 — Kanboard is missing authorization check in getSwimlane API allows cross-project data acce…

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, the getSwimlane API method lacks project-level authorization, allowing authenticated users to access swimlane d…

kanboard | Remote | Authorization
Feb 10, 2026 Feb 13, 2026
Feb 10, 2026
Feb 13, 2026
8.0 HIGH
CVE-2026-24885 — Kanboard Affected by Cross-Site Request Forgery (CSRF) via Content-Type Misconfiguration …

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a Cross-Site Request Forgery (CSRF) vulnerability exists in the ProjectPermissionController within the Kanboard…

kanboard | Remote | Cross-Site Request Forgery
Feb 10, 2026 Feb 13, 2026
Feb 10, 2026
Feb 13, 2026
6.7 MEDIUM
CVE-2025-36522 — Intel Chipset Software Local Privilege Escalation

Incorrect default permissions for some Intel(R) Chipset Software before version 10.1.20266.8668 or later. within Ring 3: User Applications may allow an escalation of privilege. System software advers…

| Authorization
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
6.7 MEDIUM
CVE-2025-36511 — Intel Memory and Storage Tool Privilege Escalation Vulnerability

Incorrect default permissions for some Intel(R) Memory and Storage Tool before version 2.5.2 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an a…

| Misconfiguration
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
6.7 MEDIUM
CVE-2025-35999 — Intel(R) Server Boards and Intel(R) Server Systems System Firmware Update Utility (SysFwU…

Incorrect permission assignment for critical resource for some System Firmware Update Utility (SysFwUpdt) for Intel(R) Server Boards and Intel(R) Server Systems Based before version 16.0.12. within R…

| Authorization
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
7.9 HIGH
CVE-2025-35998 — Intel Quick Assist Technology Alternate Hardware Interface Privilege Escalation

Missing protection mechanism for alternate hardware interface in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within Ring 0: Kernel may allow an escalation of privilege. System so…

| Authorization
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
5.7 MEDIUM
CVE-2025-35992 — Intel NPU Driver Denial of Service Vulnerability

Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combin…

| Denial of Service
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
3.3 LOW
CVE-2025-33030 — Intel NPU Driver Privilege Escalation Vulnerability

Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated u…

| Authorization
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
2.8 LOW
CVE-2025-32739 — Intel Graphics Drivers and LTS Kernels Ring 1 Denial of Service Vulnerability

Improper conditions check in some firmware for some Intel(R) Graphics Drivers and Intel LTS kernels within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with a…

| Denial of Service
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
6.8 MEDIUM
CVE-2025-32735 — Intel NPU Driver Denial of Service

Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combin…

| Denial of Service
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
5.6 MEDIUM
CVE-2025-32467 — VMware TDX Uninitialized Variable Information Disclosure Vulnerability

Use of uninitialized variable for some TDX Module before version tdx1.5 within Ring 0: Hypervisor may allow an information disclosure. Authorized adversary with a privileged user combined with a high…

| Information Disclosure
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
6.7 MEDIUM
CVE-2025-32453 — Intel Graphics Driver Privileged Process Escalation of Privilege

Incorrect default permissions for some Intel(R) Graphics Driver software within Ring 2: Privileged Process may allow an escalation of privilege. Unprivileged software adversary with an authenticated …

| Authorization
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
6.7 MEDIUM
CVE-2025-32452 — Ring AI Playground Local Privilege Escalation

Uncontrolled search path for some AI Playground before version 2.6.1 beta within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated …

| Path Traversal
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
Showing 20 of 5086 Results