Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.3 HIGH
CVE-2025-40905 — WWW::OAuth 1.000 and earlier for Perl uses insecure rand() function for cryptographic fun…

WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions.

Remote | Cryptography
Feb 13, 2026 Feb 17, 2026
Feb 13, 2026
Feb 17, 2026
6.0 MEDIUM
CVE-2024-21961 — Intel PCIe Link Buffer Overflow Vulnerability

Improper restriction of operations within the bounds of a memory buffer in PCIe® Link could allow an attacker with access to a guest virtual machine to potentially perform a denial of service attack …

Remote | Memory Corruption
Feb 13, 2026 Feb 13, 2026
Feb 13, 2026
Feb 13, 2026
5.4 MEDIUM
CVE-2026-26188 — Solspace Freeform plugin affected by Stored Cross-Site Scripting (XSS) in Freeform Craft …

Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building tool. An authenticated, low-privilege user (able to create/edit forms) can inject arbitrary HTML/JS into the Craft Control…

freeform | Remote | Cross-Site Scripting
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
5.5 MEDIUM
CVE-2025-70092 — OpenSourcePOS XSS Vulnerability in Item Kits Function

A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Item Na…

open_source_point_of_sale | Remote | Cross-Site Scripting
Feb 12, 2026 Feb 18, 2026
Feb 12, 2026
Feb 18, 2026
9.8 CRITICAL
CVE-2020-37167 — ClamAV ClamBC < 0.103.0-rc - 'ClamBC' Executable Regular Expression Error

ClamAV versions prior to 0.103.0-rc contain a vulnerability in function name processing through the ClamBC bytecode interpreter that allows attackers to manipulate bytecode function names. Attackers …

clamav | Remote | Injection
Feb 12, 2026 Feb 27, 2026
Feb 12, 2026
Feb 27, 2026
7.5 HIGH
CVE-2019-25342 — Centova Cast 3.2.12 - Denial of Service

Centova Cast 3.2.12 contains a denial of service vulnerability that allows attackers to overwhelm the system by repeatedly calling the database export API endpoint. Attackers can trigger 100% CPU loa…

Remote | Denial of Service
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
7.5 HIGH
CVE-2019-25341 — iNetTools for iOS 8.20 - 'Whois' Denial of Service

iNetTools for iOS 8.20 contains a denial of service vulnerability in the Whois feature that allows attackers to crash the application by manipulating input. Attackers can paste a specially crafted 98…

Remote | Denial of Service
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
7.5 HIGH
CVE-2019-25340 — SpotAuditor 5.3.2 - 'Base64' Denial Of Service

SpotAuditor 5.3.2 contains a denial of service vulnerability in its Base64 decryption feature that allows attackers to crash the application by supplying an oversized buffer. Attackers can generate a…

spotauditor | Remote | Denial of Service
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
7.5 HIGH
CVE-2019-25339 — GHIA CamIP 1.2 for iOS - 'Password' Denial of Service

GHIA CamIP 1.2 for iOS contains a denial of service vulnerability in the password input field that allows attackers to crash the application. Attackers can paste a 33-character buffer of repeated cha…

Remote | Denial of Service
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
7.5 HIGH
CVE-2019-25338 — Dokuwiki 2018-04-22b - Username Enumeration

DokuWiki 2018-04-22b contains a username enumeration vulnerability in its password reset functionality that allows attackers to identify valid user accounts. Attackers can submit different usernames …

dokuwiki | Remote | Information Disclosure
Feb 12, 2026 Mar 02, 2026
Feb 12, 2026
Mar 02, 2026
9.8 CRITICAL
CVE-2019-25337 — OwnCloud 8.1.8 - Username Disclosure

OwnCloud 8.1.8 contains a username enumeration vulnerability that allows remote attackers to discover user accounts by manipulating the share.php endpoint. Attackers can send crafted GET requests to …

owncloud | Remote | Information Disclosure
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
8.4 HIGH
CVE-2019-25336 — SpotAuditor 5.3.2 - 'Base64' Local Buffer Overflow (SEH)

SpotAuditor 5.3.2 contains a local buffer overflow vulnerability in the Base64 Encrypted Password tool that allows attackers to execute arbitrary code by crafting a malicious payload. Attackers can g…

spotauditor | Memory Corruption
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
8.8 HIGH
CVE-2019-25335 — PRO-7070 Hazır Profesyonel Web Sitesi 1.0 - Authentication Bypass

PRO-7070 Hazır Profesyonel Web Sitesi version 1.0 contains an authentication bypass vulnerability in the administration panel login page. Attackers can bypass authentication by using '=' 'or' as both…

Remote | Authentication
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
6.7 MEDIUM
CVE-2019-25334 — Product Key Explorer 4.2.0.0 - 'Name' Denial of Service

Product Key Explorer 4.2.0.0 contains a denial of service vulnerability that allows local attackers to crash the application by overflowing the registration name input field. Attackers can create a s…

product_key_explorer | Denial of Service
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
8.7 HIGH
CVE-2019-25333 — Bullwark Momentum Series JAWS 1.0 - 'Momentum Series JAWS' Improper Limitation of a Pathn…

Bullwark Momentum Series JAWS 1.0 contains a directory traversal vulnerability that allows unauthenticated attackers to access system files by manipulating HTTP request paths. Attackers can exploit t…

Remote | Path Traversal
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
8.4 HIGH
CVE-2019-25332 — FTP Commander Pro 8.03 - Local Stack Overflow

FTP Commander Pro 8.03 contains a local stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting the EIP register through a custom command input. Attackers can craf…

| Memory Corruption
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
8.4 HIGH
CVE-2019-25331 — AVS Audio Converter 9.1 - 'Exit folder' Buffer Overflow

AVS Audio Converter 9.1 contains a local buffer overflow vulnerability that allows local attackers to overwrite CPU registers by manipulating the 'Exit folder' input field. Attackers can craft a spec…

avs_audio_converter | Memory Corruption
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
7.5 HIGH
CVE-2019-25330 — SurfOffline Professional 2.2.0.103 - 'Project Name' Denial of Service (SEH)

SurfOffline Professional 2.2.0.103 contains a structured exception handler (SEH) overflow vulnerability that allows attackers to crash the application by manipulating the project name input. Attacker…

Remote | Memory Corruption
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
7.5 HIGH
CVE-2019-25329 — FTP Navigator 8.03 - 'Custom Command' Denial of Service (SEH)

FTP Navigator 8.03 contains a denial of service vulnerability that allows attackers to crash the application by overwriting Structured Exception Handler (SEH) with malicious input. Attackers can gene…

ftp_navigator | Remote | Memory Corruption
Feb 12, 2026 Mar 03, 2026
Feb 12, 2026
Mar 03, 2026
7.5 HIGH
CVE-2019-25328 — XnConvert 1.82 - Denial of Service

XnConvert 1.82 contains a denial of service vulnerability in its registration code input field that allows attackers to crash the application. Attackers can generate a 9000-byte buffer of repeated ch…

Remote | Denial of Service
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
Showing 20 of 4989 Results