Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2019-25327 — Prime95 Version 29.8 build 6 - Buffer Overflow (SEH)

Prime95 version 29.8 build 6 contains a buffer overflow vulnerability in the user ID input field that allows remote attackers to execute arbitrary code. Attackers can craft a malicious payload and pa…

prime95 | Remote | Memory Corruption
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
8.8 HIGH
CVE-2019-25325 — Thrive Smart Home 1.1 - 'Smart Home' Improper Limitation of a Pathname to a Restricted Di…

Thrive Smart Home 1.1 contains an SQL injection vulnerability in the checklogin.php endpoint that allows unauthenticated attackers to bypass authentication by manipulating the 'user' POST parameter. …

smart_home_firmware | Remote | Injection
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
6.1 MEDIUM
CVE-2019-25324 — RICOH Web Image Monitor 1.09 - HTML Injection

RICOH Web Image Monitor 1.09 contains an HTML injection vulnerability in the address configuration CGI script that allows attackers to inject malicious HTML code. Attackers can exploit the entryNameI…

Remote | Cross-Site Scripting
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
6.1 MEDIUM
CVE-2019-25323 — Heatmiser Netmonitor 3.03 - HTML Injection

Heatmiser Netmonitor v3.03 contains an HTML injection vulnerability in the outputSetup.htm page that allows attackers to inject malicious HTML code through the outputtitle parameter. Attackers can cr…

Remote | Injection
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
9.3 CRITICAL
CVE-2019-25322 — Heatmiser Netmonitor 3.03 - Hardcoded Credentials

Heatmiser Netmonitor 3.03 contains a hardcoded credentials vulnerability in the networkSetup.htm page with predictable admin login credentials. Attackers can access the device by using the hard-coded…

Remote | Authentication
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
9.8 CRITICAL
CVE-2019-25321 — FTP Navigator 8.03 - Stack Overflow (SEH)

FTP Navigator 8.03 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Attackers can craft a malicious…

ftp_navigator | Remote | Memory Corruption
Feb 12, 2026 Mar 03, 2026
Feb 12, 2026
Mar 03, 2026
8.8 HIGH
CVE-2019-25320 — elearning-script 1.0 - Authentication Bypass

E Learning Script 1.0 contains an authentication bypass vulnerability that allows attackers to access the dashboard without valid credentials by manipulating login parameters. Attackers can exploit t…

Remote | Authentication
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
9.8 CRITICAL
CVE-2019-25319 — Domain Quester Pro 6.02 - Stack Overflow (SEH)

Domain Quester Pro 6.02 contains a stack overflow vulnerability that allows remote attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Attackers can craft…

Remote | Memory Corruption
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
8.8 HIGH
CVE-2019-25318 — AVS Audio Converter 9.1.2.600 - Stack Overflow

AVS Audio Converter 9.1.2.600 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by manipulating the output folder text input. Attackers can craft a malicious pay…

avs_audio_converter | Remote | Memory Corruption
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
8.5 HIGH
CVE-2026-26225 — Intego Personal Backup Task File Privilege Escalation

Intego Personal Backup, a macOS backup utility that allows users to create scheduled backups and bootable system clones, contains a local privilege escalation vulnerability. Backup task definitions a…

| Path Traversal
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
8.5 HIGH
CVE-2026-26224 — Intego Log Reporter TOCTOU Local Privilege Escalation

Intego Log Reporter, a macOS diagnostic utility bundled with Intego security products that collects system and application logs for support analysis, contains a local privilege escalation vulnerabili…

| Race Condition
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
5.3 MEDIUM
CVE-2026-26185 — Directus Affected by User Enumeration via Password Reset Timing Attack

Directus is a real-time API and App dashboard for managing SQL database content. Before 11.14.1, a timing-based user enumeration vulnerability exists in the password reset functionality. When an inva…

directus | Remote | Authentication
Feb 12, 2026 Feb 20, 2026
Feb 12, 2026
Feb 20, 2026
7.5 HIGH
CVE-2026-26076 — ntpd-rs affected by excessive CPU load from malformed packets

ntpd-rs is a full-featured implementation of the Network Time Protocol. Prior to 1.7.1, an attacker can remotely induce moderate increases (2-4 times above normal) in cpu usage. When having NTS enabl…

ntpd-rs | Remote | Denial of Service
Feb 12, 2026 Feb 23, 2026
Feb 12, 2026
Feb 23, 2026
6.9 MEDIUM
CVE-2026-26075 — Cross-Site Request Forgery (CSRF) in FastGPT

FastGPT is an AI Agent building platform. Due to the fact that FastGPT's web page acquisition nodes, HTTP nodes, etc. need to initiate data acquisition requests from the server, there are certain sec…

fastgpt | Remote | Server-Side Request Forgery
Feb 12, 2026 Feb 23, 2026
Feb 12, 2026
Feb 23, 2026
9.1 CRITICAL
CVE-2026-26069 — Scraparr Readarr Integration exposes sensitive values as metric labels.

Scraparr is a Prometheus Exporter for various components of the *arr Suite. From 3.0.0-beta to before 3.0.2, when the Readarr integration was enabled, the exporter exposed the configured Readarr API …

scraparr | Remote | Information Disclosure
Feb 12, 2026 Feb 23, 2026
Feb 12, 2026
Feb 23, 2026
9.9 CRITICAL
CVE-2026-26068 — emp3r0r Agent-Controlled Metadata to Operator RCE (tmux Command Injection)

emp3r0r is a stealth-focused C2 designed by Linux users for Linux environments. Prior to 3.21.1, untrusted agent metadata (Transport, Hostname) is accepted during check-in and later interpolated into…

emp3r0r | Remote | Injection
Feb 12, 2026 Feb 25, 2026
Feb 12, 2026
Feb 25, 2026
8.8 HIGH
CVE-2026-26056 — Arbitrary WASM Code Execution via AnnotationOverrideFlight Injection in Yoke ATC

Yoke is a Helm-inspired infrastructure-as-code (IaC) package deployer. In 0.19.0 and earlier, a vulnerability exists in the Air Traffic Controller (ATC) component of Yoke. It allows users with CR cre…

Remote | Injection
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
7.5 HIGH
CVE-2026-26055 — Unauthenticated Admission Webhook Endpoints in Yoke ATC

Yoke is a Helm-inspired infrastructure-as-code (IaC) package deployer. In 0.19.0 and earlier, a vulnerability exists in the Air Traffic Controller (ATC) component of Yoke. The ATC webhook endpoints l…

Remote | Authentication
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
5.4 MEDIUM
CVE-2026-25828 — Grub-Btrfs Command Injection Vulnerability

grub-btrfs through 2026-01-31 (on Arch Linux and derivative distributions) allows initramfs OS command injection because it does not sanitize the $root parameter to resolve_device(). NOTE: a third pa…

Remote | Injection
Feb 12, 2026 Mar 04, 2026
Feb 12, 2026
Mar 04, 2026
9.8 CRITICAL
CVE-2026-1358 — Airleader Master Unrestricted Upload of File with Dangerous Type

Airleader Master versions 6.381 and prior allow for file uploads without restriction to multiple webpages running maximum privileges. This could allow an unauthenticated user to potentially obtain …

Remote | Authentication
Feb 12, 2026 Mar 03, 2026
Feb 12, 2026
Mar 03, 2026
Showing 20 of 4989 Results