Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.9 MEDIUM
CVE-2025-68686 — Fortinet FortiOS Sensitive Information Exposure

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, For…

fortios | Remote | Information Disclosure
Feb 10, 2026 Feb 12, 2026
Feb 10, 2026
Feb 12, 2026
7.2 HIGH
CVE-2025-64157 — Fortinet FortiOS Format String Vulnerability

A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0 all versions allows an authe…

fortios | Remote | Injection
Feb 10, 2026 Feb 12, 2026
Feb 10, 2026
Feb 12, 2026
7.1 HIGH
CVE-2025-62676 — Fortinet FortiClient Link Following File Write Vulnerability

An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.4, FortiClientWindows 7.2.0 through 7.2.12, For…

forticlient forticlientwindows | Path Traversal
Feb 10, 2026 Feb 12, 2026
Feb 10, 2026
Feb 12, 2026
4.2 MEDIUM
CVE-2025-62439 — Fortinet FortiOS Improper Verification of Source of a Communication Channel Vulnerability

An Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, For…

fortios | Authorization
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
5.8 MEDIUM
CVE-2025-55018 — Fortinet FortiOS HTTP Request Smuggling Vulnerability

An inconsistent interpretation of http requests ('http request smuggling') vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, Fo…

fortios | Remote | Injection
Feb 10, 2026 Feb 23, 2026
Feb 10, 2026
Feb 23, 2026
9.6 CRITICAL
CVE-2025-52436 — Fortinet FortiSandbox Cross-Site Scripting Vulnerability

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4…

fortisandbox | Remote | Cross-Site Scripting
Feb 10, 2026 Feb 18, 2026
Feb 10, 2026
Feb 18, 2026
5.5 MEDIUM
CVE-2025-15572 — wasm3 NewCodePage memory leak

A vulnerability has been found in wasm3 up to 0.5.0. The affected element is the function NewCodePage. The manipulation leads to memory leak. The attack must be carried out locally. The exploit has b…

wasm3 | Memory Corruption
Feb 10, 2026 Feb 12, 2026
Feb 10, 2026
Feb 12, 2026
7.5 HIGH
CVE-2025-11004 — Reflected XSS vulnerability in Simplicity Device Manager tool

The Simplicity Device Manager Tool has a Reflected XSS (Cross-site-scripting) vulnerability in several API endpoints. The attacker needs to be on the same network to execute this attack. These APIs c…

Remote | Cross-Site Scripting
Feb 10, 2026 Feb 10, 2026
Feb 10, 2026
Feb 10, 2026
5.5 MEDIUM
CVE-2024-54192 — Tcpreplay Denial of Service Vulnerability

An issue inTcpreplay v4.5.1 allows a local attacker to cause a denial of service via a crafted file to the tcpedit_dlt_getplugin function at src/tcpedit/plugins/dlt_utils.c.

| Denial of Service
Feb 10, 2026 Feb 18, 2026
Feb 10, 2026
Feb 18, 2026
Showing 20 of 5509 Results