Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
1.8 LOW
CVE-2025-48509 — VMware ESXi Missing Checks RMP Initialization Privilege Escalation

Missing Checks in certain functions related to RMP initialization can allow a local admin privileged attacker to cause misidentification of I/O memory, potentially resulting in a loss of guest memory…

| Memory Corruption
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
5.9 MEDIUM
CVE-2025-29952 — AMD SEV Firmware Memory Corruption Vulnerability

Improper Initialization within the AMD Secure Encrypted Virtualization (SEV) firmware can allow an admin privileged attacker to corrupt RMP covered memory, potentially resulting in loss of guest memo…

| Memory Corruption
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
7.3 HIGH
CVE-2025-29951 — AMD Secure Processor ASP Bootloader Buffer Overflow

A buffer overflow in the AMD Secure Processor (ASP) bootloader could allow an attacker to overwrite memory, potentially resulting in privilege escalation and arbitrary code execution.

| Memory Corruption
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
7.1 HIGH
CVE-2025-29950 — Intel Management Engine SMM Stack Overflow Vulnerability

Improper input validation in system management mode (SMM) could allow a privileged attacker to overwrite stack memory leading to arbitrary code execution.

| Memory Corruption
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
4.8 MEDIUM
CVE-2025-29949 — AMD Secure Processor ASP Boot Loader Out-of-Bounds Write Vulnerability

Insufficient input parameter sanitization in AMD Secure Processor (ASP) Boot Loader (legacy recovery mode only) could allow an attacker to write out-of-bounds to corrupt Secure DRAM potentially resul…

| Denial of Service
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
5.9 MEDIUM
CVE-2025-29948 — AMD Secure Encrypted Virtualization (SEV) Hypervisor Privilege Escalation

Improper access control in AMD Secure Encrypted Virtualization (SEV) firmware could allow a malicious hypervisor to bypass RMP protections, potentially resulting in a loss of SEV-SNP guest memory int…

| Authorization
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
4.5 MEDIUM
CVE-2025-29946 — AMD SEV IOMMU Data Remanence Vulnerability

Insufficient or Incomplete Data Removal in Hardware Component in SEV firmware doesn't fully flush IOMMU. This can potentially lead to a loss of confidentiality and integrity in guest memory.

| Memory Corruption
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
6.9 MEDIUM
CVE-2025-29939 — AMD SEV Improper Access Control Denial of Service

Improper access control in secure encrypted virtualization (SEV) could allow a privileged attacker to write to the reverse map page (RMP) during secure nested paging (SNP) initialization, potentially…

| Authorization
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
4.6 MEDIUM
CVE-2025-0031 — "AMD SEV Use-After-Free Hypervisor Escape"

A use after free in the SEV firmware could allow a malicous hypervisor to activate a migrated guest with the SINGLE_SOCKET policy on a different socket than the migration agent potentially resulting …

| Memory Corruption
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
1.8 LOW
CVE-2025-0029 — AMD SEV-SNP Host DMA Write Dropping

Improper handling of error condition during host-induced faults can allow a local high-privileged attack to selectively drop guest DMA writes, potentially resulting in a loss of SEV-SNP guest memory …

| Denial of Service
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
6.8 MEDIUM
CVE-2025-0012 — Intel SMM Memory Corruption Vulnerability

Improper handling of overlap between the segmented reverse map table (RMP) and system management mode (SMM) memory could allow a privileged attacker corrupt or partially infer SMM memory resulting in…

| Memory Corruption
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
7.0 HIGH
CVE-2024-36355 — AMD SMM Arbitrary Code Execution Vulnerability

Improper input validation in the SMM handler could allow an attacker with Ring0 access to write to SMRAM and modify execution flow for S3 (sleep) wake up, potentially resulting in arbitrary code exec…

| Memory Corruption
Feb 10, 2026 Feb 12, 2026
Feb 10, 2026
Feb 12, 2026
4.6 MEDIUM
CVE-2024-36311 — AMD SMM Communications Buffer TOCTOU Race Condition

A Time-of-check time-of-use (TOCTOU) race condition in the SMM communications buffer could allow a privileged attacker to bypass input validation and perform an out of bounds read or write, potential…

| Race Condition
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
4.6 MEDIUM
CVE-2024-36310 — AMD Ryzen SMM Buffer Overflow

Improper input validation in the SMM communications buffer could allow a privileged attacker to perform an out of bounds read or write to SMRAM potentially resulting in loss of confidentiality or int…

| Memory Corruption
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
5.9 MEDIUM
CVE-2024-21953 — Apache Hyper-V IOMMU Data Integrity Vulnerability

Improper input validation in IOMMU could allow a malicious hypervisor to reconfigure IOMMU registers resulting in loss of guest data integrity.

| Misconfiguration
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
1.8 LOW
CVE-2021-26410 — AMD Secure Processor Kernel Information Disclosure Vulnerability

Improper syscall input validation in ASP (AMD Secure Processor) may force the kernel into reading syscall parameter values from its own memory space allowing an attacker to infer the contents of the …

| Information Disclosure
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
7.1 HIGH
CVE-2021-26381 — Citrix Trusted OS Driver Kernel Memory Corruption

Improper system call parameter validation in the Trusted OS may allow a malicious driver to perform mapping or unmapping operations on a large number of pages, potentially resulting in kernel memory …

| Memory Corruption
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
6.9 MEDIUM
CVE-2026-2302 — Unsafe Reflection in Mongoid::Criteria.from_hash

Under specific conditions when processing a maliciously crafted value of type Hash r, Mongoid::Criteria.from_hash may allow for executing arbitrary Ruby code.

Remote | Injection
Feb 10, 2026 Feb 27, 2026
Feb 10, 2026
Feb 27, 2026
9.9 CRITICAL
CVE-2026-26009 — Catalyst Affected by Remote Code Execution as Root via Containerized Install Script Execu…

Catalyst is a platform built for enterprise game server hosts, game communities, and billing panel integrations. Install scripts defined in server templates execute directly on the host operating sys…

Remote | Injection
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
7.1 HIGH
CVE-2026-25613 — An unsafe cast in the MongoDB query planner can result in a segmentation fault.

An authorized user may disable the MongoDB server by issuing a query against a collection that contains an invalid compound wildcard index.

mongodb | Remote | Misconfiguration
Feb 10, 2026 Feb 25, 2026
Feb 10, 2026
Feb 25, 2026
Showing 20 of 5071 Results