Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2025-65127 — ZBT WE2001 Session Validation Bypass

A lack of session validation in the web API component of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote unauthenticated attackers to access administrative information-retrieval func…

Remote | Authentication
Feb 11, 2026 Feb 17, 2026
Feb 11, 2026
Feb 17, 2026
5.8 MEDIUM
CVE-2025-13391 — Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) <= 4.9…

The Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'uni_cp…

Remote | Authorization
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
7.5 HIGH
CVE-2026-25869 — MiniGal Nano <= 0.3.5 Path Traversal via dir Parameter

MiniGal Nano versions 0.3.5 and prior contain a path traversal vulnerability in index.php via the dir parameter. The application appends user-controlled input to the photos directory and attempts to …

nano minigal_nano | Remote | Path Traversal
Feb 11, 2026 Feb 26, 2026
Feb 11, 2026
Feb 26, 2026
6.1 MEDIUM
CVE-2026-25868 — MiniGal Nano <= 0.3.5 Reflected XSS via dir Parameter

MiniGal Nano version 0.3.5 and prior contain a reflected cross-site scripting (XSS) vulnerability in index.php via the dir parameter. The application constructs $currentdir from user-controlled input…

nano minigal_nano | Remote | Cross-Site Scripting
Feb 11, 2026 Feb 26, 2026
Feb 11, 2026
Feb 26, 2026
8.7 HIGH
CVE-2026-1837 — libjxl: Out-of-bounds write in grayscale color transformation when using LCMS2

A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after that data from another uninitialized unallocated region is copied to pixel data…

libjxl | Remote | Memory Corruption
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
10.0 CRITICAL
CVE-2025-64075 — ZBT WE2001 Path Traversal Authentication Bypass

A path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to bypass authentication and perform administrative actions by…

Remote | Path Traversal
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
2.3 LOW
CVE-2025-12474 — libjxl: Uninitialized memory read in decoder due to incorrect optimization in patch handl…

A specially-crafted file can cause libjxl's decoder to read pixel data from uninitialized (but allocated) memory. This can be done by causing the decoder to reference an outside-image-bound area in …

libjxl | Remote | Memory Corruption
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
3.6 LOW
CVE-2026-2345 — Insufficient Origin Validation in Proctorio Chrome Extension postMessage Handlers

Proctorio Chrome Extension is a browser extension used for online proctoring. The extension contains multiple window.addEventListener('message', ...) handlers that do not properly validate the origin…

| Cross-Site Scripting
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
8.6 HIGH
CVE-2026-2344 — Stored XSS on Plunet BusinessManager

A vulnerability in Plunet Plunet BusinessManager allows unauthorized actions being performed on behalf of privileged users.This issue affects Plunet BusinessManager: 10.15.1

Remote | Authorization
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
7.5 HIGH
CVE-2026-2250 — Unauthenticated Data Export and Source Code Disclosure via /dbviewer/ in METIS WIC

The /dbviewer/ web endpoint in METIS WIC devices is exposed without authentication. A remote attacker can access and export the internal telemetry SQLite database containing sensitive operational dat…

Remote | Authentication
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
9.8 CRITICAL
CVE-2026-2249 — Unauthenticated Remote Command Execution via Web Console in METIS DFS

METIS DFS devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote attacker to execute …

Remote | Authentication
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
9.8 CRITICAL
CVE-2026-2248 — Unauthenticated Remote Root Shell Access via Web Console in METIS WIC

METIS WIC devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote attacker to execute …

Remote | Authentication
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
7.0 HIGH
CVE-2025-61969 — AMD µProf Privilege Escalation Vulnerability

Incorrect permission assignment in AMD µProf may allow a local user-privileged attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

| Authorization
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
7.3 HIGH
CVE-2025-52541 — Vivado DLL Hijacking Privilege Escalation Vulnerability

A DLL hijacking vulnerability in Vivado could allow a local attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

| Misconfiguration
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
6.9 MEDIUM
CVE-2025-48518 — AMD Graphics Driver Out-of-Bounds Write Vulnerability

Improper input validation in AMD Graphics Driver could allow a local attacker to write out of bounds, potentially resulting in loss of integrity or denial of service.

| Memory Corruption
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
6.0 MEDIUM
CVE-2025-48508 — AMD GPU GFX Hardware IP Block Privilege Escalation Vulnerability

Improper Hardware reset flow logic in the GPU GFX Hardware IP block could allow a privileged attacker in a guest virtual machine to control reset operation potentially causing host or GPU crash or re…

| Denial of Service
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
7.8 HIGH
CVE-2025-48503 — AMD Software Installer DLL Hijacking Vulnerability

A DLL hijacking vulnerability in the AMD Software Installer could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

| Misconfiguration
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
9.8 CRITICAL
CVE-2025-12059 — Improper Access Control in Logo Software's Logo j-Platform

Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Logo Software Industry and Trade Inc. Logo j-Platform allows Exploiting Incorrectly Configured Access …

Remote | Misconfiguration
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
8.8 HIGH
CVE-2024-36324 — AMD Graphics Driver Pointer Validation Vulnerability

Improper input validation in AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, potentially leading to arbitrary code execution.

| Memory Corruption
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
7.0 HIGH
CVE-2024-36320 — ATIHdwt6.sys Integer Overflow Vulnerability

Integer Overflow within atihdwt6.sys can allow a local attacker to cause out of bound read/write potentially leading to loss of confidentiality, integrity and availability

| Memory Corruption
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
Showing 20 of 5071 Results