Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.6 MEDIUM
CVE-2025-27572 — Hypervisor TDX Ring 0 Information Disclosure

Exposure of sensitive information during transient execution for some TDX within Ring 0: Hypervisor may allow an information disclosure. Authorized adversary with a privileged user combined with a hi…

| Information Disclosure
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
6.7 MEDIUM
CVE-2025-27560 — Intel Platform Infinite Loop Denial of Service Vulnerability

Loop with unreachable exit condition ('infinite loop') for some Intel(R) Platform within Ring 0: Kernel may allow a denial of service. System software adversary with a privileged user combined with a…

| Denial of Service
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
5.6 MEDIUM
CVE-2025-27535 — Intel Ethernet Connection E825-C Firmware Denial of Service Vulnerability

Exposed ioctl with insufficient access control in the firmware for some Intel(R) Ethernet Connection E825-C. before version NVM ver. 3.84 within Ring 0: Bare Metal OS may allow a denial of service. S…

| Denial of Service
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
6.7 MEDIUM
CVE-2025-27243 — Intel Ethernet Controller E810 Firmware OOB Write Denial of Service Vulnerability

Out-of-bounds write in the firmware for some Intel(R) Ethernet Controller E810 before version cvl fw 1.7.8.x within Ring 0: Bare Metal OS may allow a denial of service. System software adversary with…

| Memory Corruption
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
8.2 HIGH
CVE-2025-25210 — Ring Server Firmware Update Utility (SysFwUpdt) Privilege Escalation Vulnerability

Improper input validation for some Server Firmware Update Utility(SysFwUpdt) before version 16.0.12 within Ring 3: User Applications may allow an escalation of privilege. System software adversary wi…

| Path Traversal
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
3.3 LOW
CVE-2025-25058 — Intel Ethernet 800-Series ESXi Kernel Mode Driver Ring 1 Information Disclosure

Improper initialization for some ESXi kernel mode driver for the Intel(R) Ethernet 800-Series before version 2.2.2.0 (esxi 8.0) & 2.2.3.0 (esxi 9.0) within Ring 1: Device Drivers may allow an inf…

| Information Disclosure
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
6.7 MEDIUM
CVE-2025-24851 — Intel Ethernet Controller E810 Denial of Service Vulnerability

Uncaught exception in the firmware for some 100GbE Intel(R) Ethernet Controller E810 before version cvl fw 1.7.8.x within Ring 0: Bare Metal OS may allow a denial of service. System software adversar…

| Denial of Service
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
5.6 MEDIUM
CVE-2025-22885 — TDX Module Firmware Buffer Overflow Privilege Escalation Vulnerability

Improper buffer restrictions in the firmware for the TDX Module may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enabl…

| Memory Corruption
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
6.7 MEDIUM
CVE-2025-22849 — Intel(R) Optane(TM) PMem Management Software Privilege Escalation

Incorrect default permissions for the Intel(R) Optane(TM) PMem management software before versions CR_MGMT_01.00.00.3584, CR_MGMT_02.00.00.4052, CR_MGMT_03.00.00.0538 within Ring 3: User Applications…

| Authorization
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
7.5 HIGH
CVE-2025-22453 — Ring 3: SysFwUpdt Privilege Escalation Vulnerability

Improper input validation for some Server Firmware Update Utility(SysFwUpdt) before version 16.0.12 within Ring 3: User Applications may allow an escalation of privilege. System software adversary wi…

| Injection
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
6.7 MEDIUM
CVE-2025-20106 — "Intel VTune Profiler Uncontrolled Search Path Privilege Escalation"

Uncontrolled search path in some software installer for some VTune(TM) Profiler software and Intel(R) oneAPI Base Toolkits before version 2025.0. within Ring 3: User Applications may allow an escalat…

| Path Traversal
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
8.2 HIGH
CVE-2025-20080 — Intel(R) AMT and Intel(R) Standard Manageability Null Pointer Dereference Denial of Servi…

Null pointer dereference in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability within Ring 0: Kernel may allow a denial of service. Network adversary with an unauthenticated user …

Remote | Denial of Service
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
6.7 MEDIUM
CVE-2025-20070 — Intel Optane PMem Management Software Privilege Escalation Vulnerability

Improper conditions check for the Intel(R) Optane(TM) PMem management software before versions CR_MGMT_02.00.00.4052, CR_MGMT_03.00.00.0538 within Ring 3: User Applications may allow an escalation of…

| Authorization
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
8.1 HIGH
CVE-2026-22153 — Fortinet FortiOS Authentication Bypass

An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauthenticated attacker to bypass LDAP authentication of Agent…

fortios | Remote | Authentication
Feb 10, 2026 Feb 12, 2026
Feb 10, 2026
Feb 12, 2026
7.2 HIGH
CVE-2026-21743 — Fortinet FortiAuthenticator Missing Authorization Vulnerability

A missing authorization vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions…

fortiauthenticator | Remote | Authorization
Feb 10, 2026 Feb 12, 2026
Feb 10, 2026
Feb 12, 2026
9.8 CRITICAL
CVE-2026-1774 — CASL Ability, versions 2.4.0 through 6.7.4, contains a prototype pollution vulnerability.

CASL Ability, versions 2.4.0 through 6.7.4, contains a prototype pollution vulnerability.

Remote | Misconfiguration
Feb 10, 2026 Feb 11, 2026
Feb 10, 2026
Feb 11, 2026
8.6 HIGH
CVE-2026-1603 — Ivanti Endpoint Manager Authentication Bypass Vulnerability

An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.

endpoint_manager | Remote | Authentication
Feb 10, 2026 Feb 12, 2026
Feb 10, 2026
Feb 12, 2026
6.5 MEDIUM
CVE-2026-1602 — Ivanti Endpoint Manager SQL Injection Vulnerability

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

endpoint_manager | Remote | Injection
Feb 10, 2026 Feb 12, 2026
Feb 10, 2026
Feb 12, 2026
5.5 MEDIUM
CVE-2025-70347 — MQuickJS Denial of Service Vulnerability

An issue in mquickjs before commit 74b7e (2026-01-15) allows a local attacker to cause a denial of service via a crafted file to the get_mblock_size function at mquickjs.c.

| Denial of Service
Feb 10, 2026 Feb 18, 2026
Feb 10, 2026
Feb 18, 2026
5.9 MEDIUM
CVE-2025-68686 — Fortinet FortiOS Sensitive Information Exposure

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, For…

fortios | Remote | Information Disclosure
Feb 10, 2026 Feb 12, 2026
Feb 10, 2026
Feb 12, 2026
Showing 20 of 5091 Results