Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.7 MEDIUM
CVE-2025-24851 — Intel Ethernet Controller E810 Denial of Service Vulnerability

Uncaught exception in the firmware for some 100GbE Intel(R) Ethernet Controller E810 before version cvl fw 1.7.8.x within Ring 0: Bare Metal OS may allow a denial of service. System software adversar…

| Denial of Service
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
5.6 MEDIUM
CVE-2025-22885 — TDX Module Firmware Buffer Overflow Privilege Escalation Vulnerability

Improper buffer restrictions in the firmware for the TDX Module may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enabl…

| Memory Corruption
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
6.7 MEDIUM
CVE-2025-22849 — Intel(R) Optane(TM) PMem Management Software Privilege Escalation

Incorrect default permissions for the Intel(R) Optane(TM) PMem management software before versions CR_MGMT_01.00.00.3584, CR_MGMT_02.00.00.4052, CR_MGMT_03.00.00.0538 within Ring 3: User Applications…

| Authorization
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
7.5 HIGH
CVE-2025-22453 — Ring 3: SysFwUpdt Privilege Escalation Vulnerability

Improper input validation for some Server Firmware Update Utility(SysFwUpdt) before version 16.0.12 within Ring 3: User Applications may allow an escalation of privilege. System software adversary wi…

| Injection
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
6.7 MEDIUM
CVE-2025-20106 — "Intel VTune Profiler Uncontrolled Search Path Privilege Escalation"

Uncontrolled search path in some software installer for some VTune(TM) Profiler software and Intel(R) oneAPI Base Toolkits before version 2025.0. within Ring 3: User Applications may allow an escalat…

| Path Traversal
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
8.2 HIGH
CVE-2025-20080 — Intel(R) AMT and Intel(R) Standard Manageability Null Pointer Dereference Denial of Servi…

Null pointer dereference in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability within Ring 0: Kernel may allow a denial of service. Network adversary with an unauthenticated user …

Remote | Denial of Service
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
6.7 MEDIUM
CVE-2025-20070 — Intel Optane PMem Management Software Privilege Escalation Vulnerability

Improper conditions check for the Intel(R) Optane(TM) PMem management software before versions CR_MGMT_02.00.00.4052, CR_MGMT_03.00.00.0538 within Ring 3: User Applications may allow an escalation of…

| Authorization
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
8.1 HIGH
CVE-2026-22153 — Fortinet FortiOS Authentication Bypass

An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauthenticated attacker to bypass LDAP authentication of Agent…

fortios | Remote | Authentication
Feb 10, 2026 Feb 12, 2026
Feb 10, 2026
Feb 12, 2026
7.2 HIGH
CVE-2026-21743 — Fortinet FortiAuthenticator Missing Authorization Vulnerability

A missing authorization vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions…

fortiauthenticator | Remote | Authorization
Feb 10, 2026 Feb 12, 2026
Feb 10, 2026
Feb 12, 2026
9.8 CRITICAL
CVE-2026-1774 — CASL Ability, versions 2.4.0 through 6.7.4, contains a prototype pollution vulnerability.

CASL Ability, versions 2.4.0 through 6.7.4, contains a prototype pollution vulnerability.

Remote | Misconfiguration
Feb 10, 2026 Feb 11, 2026
Feb 10, 2026
Feb 11, 2026
8.6 HIGH
CVE-2026-1603 — Ivanti Endpoint Manager Authentication Bypass Vulnerability

An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.

endpoint_manager | Remote | Authentication
Feb 10, 2026 Feb 12, 2026
Feb 10, 2026
Feb 12, 2026
6.5 MEDIUM
CVE-2026-1602 — Ivanti Endpoint Manager SQL Injection Vulnerability

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

endpoint_manager | Remote | Injection
Feb 10, 2026 Feb 12, 2026
Feb 10, 2026
Feb 12, 2026
5.5 MEDIUM
CVE-2025-70347 — MQuickJS Denial of Service Vulnerability

An issue in mquickjs before commit 74b7e (2026-01-15) allows a local attacker to cause a denial of service via a crafted file to the get_mblock_size function at mquickjs.c.

| Denial of Service
Feb 10, 2026 Feb 18, 2026
Feb 10, 2026
Feb 18, 2026
5.9 MEDIUM
CVE-2025-68686 — Fortinet FortiOS Sensitive Information Exposure

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, For…

fortios | Remote | Information Disclosure
Feb 10, 2026 Feb 12, 2026
Feb 10, 2026
Feb 12, 2026
7.2 HIGH
CVE-2025-64157 — Fortinet FortiOS Format String Vulnerability

A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0 all versions allows an authe…

fortios | Remote | Injection
Feb 10, 2026 Feb 12, 2026
Feb 10, 2026
Feb 12, 2026
7.1 HIGH
CVE-2025-62676 — Fortinet FortiClient Link Following File Write Vulnerability

An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.4, FortiClientWindows 7.2.0 through 7.2.12, For…

forticlient forticlientwindows | Path Traversal
Feb 10, 2026 Feb 12, 2026
Feb 10, 2026
Feb 12, 2026
4.2 MEDIUM
CVE-2025-62439 — Fortinet FortiOS Improper Verification of Source of a Communication Channel Vulnerability

An Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, For…

fortios | Authorization
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
5.8 MEDIUM
CVE-2025-55018 — Fortinet FortiOS HTTP Request Smuggling Vulnerability

An inconsistent interpretation of http requests ('http request smuggling') vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, Fo…

fortios | Remote | Injection
Feb 10, 2026 Feb 23, 2026
Feb 10, 2026
Feb 23, 2026
9.6 CRITICAL
CVE-2025-52436 — Fortinet FortiSandbox Cross-Site Scripting Vulnerability

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4…

fortisandbox | Remote | Cross-Site Scripting
Feb 10, 2026 Feb 18, 2026
Feb 10, 2026
Feb 18, 2026
5.5 MEDIUM
CVE-2025-15572 — wasm3 NewCodePage memory leak

A vulnerability has been found in wasm3 up to 0.5.0. The affected element is the function NewCodePage. The manipulation leads to memory leak. The attack must be carried out locally. The exploit has b…

wasm3 | Memory Corruption
Feb 10, 2026 Feb 12, 2026
Feb 10, 2026
Feb 12, 2026
Showing 20 of 5094 Results