Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.3 LOW
CVE-2026-20601 — Apple macOS Keylogger Vulnerability

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.3. An app may be able to monitor keystrokes without user permission.

macos | Authorization
Feb 11, 2026 Mar 04, 2026
Feb 11, 2026
Mar 04, 2026
7.5 HIGH
CVE-2026-1669 — Arbitrary File Read in Keras via HDF5 External Datasets

Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose sensi…

keras | Remote | Path Traversal
Feb 11, 2026 Feb 26, 2026
Feb 11, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2025-67135 — PGST PG107 Alarm System Replay Attack Vulnerability

Weak Security in the PF-50 1.2 keyfob of PGST PG107 Alarm System 1.25.05.hf allows attackers to compromise access control via a code replay attack.

Remote | Authentication
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
5.3 MEDIUM
CVE-2025-64074 — ZBT WE2001 Path Traversal Vulnerability

A path-traversal vulnerability in the logout functionality of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to delete arbitrary files on the host by supplying a crafted s…

Remote | Path Traversal
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
6.0 MEDIUM
CVE-2025-46310 — "Apple macOS Privilege Escalation Vulnerability"

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4. An attacker with root privileges may be able to delete protected system f…

macos | Authorization
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
5.7 MEDIUM
CVE-2025-46305 — Apple HID Device Crash Vulnerability

The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.7.4, iOS 18.7.5 and iPadOS 18.7.5, macOS Sonoma 14.8.4. A malicious HID device may cause an unexpected pro…

macos iphone_os ipados | Memory Corruption
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
5.7 MEDIUM
CVE-2025-46304 — Apple HID Device Crash Vulnerability

The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.7.4, iOS 18.7.5 and iPadOS 18.7.5, macOS Sonoma 14.8.4. A malicious HID device may cause an unexpected pro…

macos iphone_os ipados | Memory Corruption
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
5.7 MEDIUM
CVE-2025-46303 — Apple HID Device Crash Vulnerability

The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.7.4, iOS 18.7.5 and iPadOS 18.7.5, macOS Sonoma 14.8.4. A malicious HID device may cause an unexpected pro…

macos iphone_os ipados | Memory Corruption
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
5.7 MEDIUM
CVE-2025-46302 — Apple HID Device Crash Vulnerability

The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.7.4, iOS 18.7.5 and iPadOS 18.7.5, macOS Sonoma 14.8.4. A malicious HID device may cause an unexpected pro…

macos iphone_os ipados | Memory Corruption
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
5.7 MEDIUM
CVE-2025-46301 — "Apple HID Device Crash Vulnerability"

The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.7.4, iOS 18.7.5 and iPadOS 18.7.5, macOS Sonoma 14.8.4. A malicious HID device may cause an unexpected pro…

macos iphone_os ipados | Memory Corruption
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
5.7 MEDIUM
CVE-2025-46300 — "Apple HID Device Crash Vulnerability"

The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.7.4, iOS 18.7.5 and iPadOS 18.7.5, macOS Sonoma 14.8.4. A malicious HID device may cause an unexpected pro…

macos iphone_os ipados | Memory Corruption
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
7.5 HIGH
CVE-2025-46290 — Apple macOS Denial of Service Vulnerability

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4. A remote attacker may be able to cause a denial-of-service.

macos | Remote | Denial of Service
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
5.5 MEDIUM
CVE-2025-43537 — Apple iOS/PadOS Path Traversal Vulnerability

A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5. Restoring a maliciously crafted backup file may lead to modification of protected sy…

iphone_os ipados | Path Traversal
Feb 11, 2026 Feb 26, 2026
Feb 11, 2026
Feb 26, 2026
5.5 MEDIUM
CVE-2025-43417 — Apple macOS Sonoma Path Handling Vulnerability

A path handling issue was addressed with improved logic. This issue is fixed in macOS Sonoma 14.8.4. An app may be able to access user-sensitive data.

macos | Path Traversal
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
5.5 MEDIUM
CVE-2025-43403 — "Apple macOS Authorization State Management Vulnerability"

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4. An app may be able to access sensitive user data.

macos | Authorization
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
5.3 MEDIUM
CVE-2026-26031 — Frappe LMS affected by unauthorised user was able to access the full list of batch enroll…

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.44.0, security issue was identified in Frappe Learning, where unauthorised users were…

learning | Remote | Authorization
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
7.5 HIGH
CVE-2026-26029 — sf-mcp-server has a Command Injection in query_records tool due to unsafe use of child_pr…

sf-mcp-server is an implementation of Salesforce MCP server for Claude for Desktop. A command injection vulnerability exists in sf-mcp-server due to unsafe use of child_process.exec when constructing…

Remote | Injection
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
6.1 MEDIUM
CVE-2026-26023 — Client‑side DOM XSS in the web chat app of Dify when using echarts

Dify is an open-source LLM app development platform. Prior to 1.13.0, a cross site scripting vulnerability has been found in the web application chat frontend when using echarts. User or llm inputs c…

dify | Remote | Cross-Site Scripting
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
9.8 CRITICAL
CVE-2026-26021 — Prototype pollution in set-in

set-in provides the set value of nested associative structure given array of keys. A prototype pollution vulnerability exists in the the npm package set-in (>=2.0.1, < 2.0.5). Despite a previous fix …

set-in | Remote | Misconfiguration
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
4.1 MEDIUM
CVE-2026-26019 — @langchain/community affected by SSRF Bypass in RecursiveUrlLoader via insufficient URL o…

LangChain is a framework for building LLM-powered applications. Prior to 1.1.14, the RecursiveUrlLoader class in @langchain/community is a web crawler that recursively follows links from a starting U…

langchain_community | Remote | Server-Side Request Forgery
Feb 11, 2026 Feb 19, 2026
Feb 11, 2026
Feb 19, 2026
Showing 20 of 5071 Results