Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2025-69874 — Nanotar Path Traversal Vulnerability

nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary files outside the intended extraction directory via a crafted…

Remote | Path Traversal
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
8.8 HIGH
CVE-2025-65480 — Pacom Unison Client Remote Code Execution Vulnerability

An issue was discovered in Pacom Unison Client 5.13.1. Authenticated users can inject malicious scripts in the Report Templates which are executed when certain script conditions are fulfilled, leadin…

Remote | Cross-Site Scripting
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
9.1 CRITICAL
CVE-2025-65128 — Shenzhen Zhibotong Electronics ZBT WE2001 Unauthenticated Configuration Modification Vuln…

A missing authentication mechanism in the web management API components of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows unauthenticated attackers on the local network to modify router an…

Remote | Authentication
Feb 11, 2026 Feb 17, 2026
Feb 11, 2026
Feb 17, 2026
9.8 CRITICAL
CVE-2026-25084 — ZLAN Information Technology ZLAN5143D Missing Authentication for Critical Function

Authentication for ZLAN5143D can be bypassed by directly accessing internal URLs.

Remote | Authentication
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
9.8 CRITICAL
CVE-2026-24789 — ZLAN Information Technology ZLAN5143D Missing Authentication for Critical Function

An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication.

Remote | Authentication
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
7.5 HIGH
CVE-2025-65127 — ZBT WE2001 Session Validation Bypass

A lack of session validation in the web API component of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote unauthenticated attackers to access administrative information-retrieval func…

Remote | Authentication
Feb 11, 2026 Feb 17, 2026
Feb 11, 2026
Feb 17, 2026
5.8 MEDIUM
CVE-2025-13391 — Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) <= 4.9…

The Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'uni_cp…

Remote | Authorization
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
7.5 HIGH
CVE-2026-25869 — MiniGal Nano <= 0.3.5 Path Traversal via dir Parameter

MiniGal Nano versions 0.3.5 and prior contain a path traversal vulnerability in index.php via the dir parameter. The application appends user-controlled input to the photos directory and attempts to …

nano minigal_nano | Remote | Path Traversal
Feb 11, 2026 Feb 26, 2026
Feb 11, 2026
Feb 26, 2026
6.1 MEDIUM
CVE-2026-25868 — MiniGal Nano <= 0.3.5 Reflected XSS via dir Parameter

MiniGal Nano version 0.3.5 and prior contain a reflected cross-site scripting (XSS) vulnerability in index.php via the dir parameter. The application constructs $currentdir from user-controlled input…

nano minigal_nano | Remote | Cross-Site Scripting
Feb 11, 2026 Feb 26, 2026
Feb 11, 2026
Feb 26, 2026
8.7 HIGH
CVE-2026-1837 — libjxl: Out-of-bounds write in grayscale color transformation when using LCMS2

A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after that data from another uninitialized unallocated region is copied to pixel data…

libjxl | Remote | Memory Corruption
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
10.0 CRITICAL
CVE-2025-64075 — ZBT WE2001 Path Traversal Authentication Bypass

A path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to bypass authentication and perform administrative actions by…

Remote | Path Traversal
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
2.3 LOW
CVE-2025-12474 — libjxl: Uninitialized memory read in decoder due to incorrect optimization in patch handl…

A specially-crafted file can cause libjxl's decoder to read pixel data from uninitialized (but allocated) memory. This can be done by causing the decoder to reference an outside-image-bound area in …

libjxl | Remote | Memory Corruption
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
3.6 LOW
CVE-2026-2345 — Insufficient Origin Validation in Proctorio Chrome Extension postMessage Handlers

Proctorio Chrome Extension is a browser extension used for online proctoring. The extension contains multiple window.addEventListener('message', ...) handlers that do not properly validate the origin…

| Cross-Site Scripting
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
8.6 HIGH
CVE-2026-2344 — Stored XSS on Plunet BusinessManager

A vulnerability in Plunet Plunet BusinessManager allows unauthorized actions being performed on behalf of privileged users.This issue affects Plunet BusinessManager: 10.15.1

Remote | Authorization
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
7.5 HIGH
CVE-2026-2250 — Unauthenticated Data Export and Source Code Disclosure via /dbviewer/ in METIS WIC

The /dbviewer/ web endpoint in METIS WIC devices is exposed without authentication. A remote attacker can access and export the internal telemetry SQLite database containing sensitive operational dat…

Remote | Authentication
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
9.8 CRITICAL
CVE-2026-2249 — Unauthenticated Remote Command Execution via Web Console in METIS DFS

METIS DFS devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote attacker to execute …

Remote | Authentication
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
9.8 CRITICAL
CVE-2026-2248 — Unauthenticated Remote Root Shell Access via Web Console in METIS WIC

METIS WIC devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote attacker to execute …

Remote | Authentication
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
7.0 HIGH
CVE-2025-61969 — AMD µProf Privilege Escalation Vulnerability

Incorrect permission assignment in AMD µProf may allow a local user-privileged attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

| Authorization
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
7.3 HIGH
CVE-2025-52541 — Vivado DLL Hijacking Privilege Escalation Vulnerability

A DLL hijacking vulnerability in Vivado could allow a local attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

| Misconfiguration
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
6.9 MEDIUM
CVE-2025-48518 — AMD Graphics Driver Out-of-Bounds Write Vulnerability

Improper input validation in AMD Graphics Driver could allow a local attacker to write out of bounds, potentially resulting in loss of integrity or denial of service.

| Memory Corruption
Feb 11, 2026 Feb 11, 2026
Feb 11, 2026
Feb 11, 2026
Showing 20 of 5070 Results