Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-21438 — webtransport-go affected by a Memory Exhaustion Attack due to Missing Cleanup of Streams …

webtransport-go is an implementation of the WebTransport protocol. Prior to 0.10.0, an attacker can cause unbounded memory consumption repeatedly creating and closing many WebTransport streams. Close…

webtransport-go | Remote | Denial of Service
Feb 12, 2026 Feb 19, 2026
Feb 12, 2026
Feb 19, 2026
7.5 HIGH
CVE-2026-21435 — webtransport-go CloseWithError can block indefinitely

webtransport-go is an implementation of the WebTransport protocol. Prior to v0.10.0, an attacker can cause a denial of service in webtransport-go by preventing or indefinitely delaying WebTransport s…

webtransport-go | Remote | Denial of Service
Feb 12, 2026 Feb 19, 2026
Feb 12, 2026
Feb 19, 2026
7.5 HIGH
CVE-2026-21434 — webtransport-go affected by Memory Exhaustion Attack due to Missing Length Check in WT_CL…

webtransport-go is an implementation of the WebTransport protocol. From 0.3.0 to 0.9.0, an attacker can cause excessive memory consumption in webtransport-go's session implementation by sending a WT_…

webtransport-go | Remote | Memory Corruption
Feb 12, 2026 Feb 19, 2026
Feb 12, 2026
Feb 19, 2026
9.8 CRITICAL
CVE-2025-70981 — CordysCRM SQL Injection Vulnerability

CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds parameter.

cordys_crm | Remote | Injection
Feb 12, 2026 Feb 18, 2026
Feb 12, 2026
Feb 18, 2026
7.5 HIGH
CVE-2025-69807 — Bareiron Buffer Overflow Denial of Service

p2r3 Bareiron commit: 8e4d4020d is vulnerable to Buffer Overflow, which allows unauthenticated remote attackers to cause a denial of service via a packet sent to the server.

bareiron | Remote | Memory Corruption
Feb 12, 2026 Feb 23, 2026
Feb 12, 2026
Feb 23, 2026
7.5 HIGH
CVE-2025-69806 — Bareiron Out-of-bounds Read

p2r3 bareiron commit: 8e4d4020d contains an Out-of-bounds Read, which allows unauthenticated remote attackers to get relative information leakage via a packet sent to the server

bareiron | Remote | Information Disclosure
Feb 12, 2026 Feb 23, 2026
Feb 12, 2026
Feb 23, 2026
7.8 HIGH
CVE-2025-63421 — Filosoft Comerc.32 Local Code Execution

An issue in filosoft Comerc.32 Commercial Invoicing v.16.0.0.3 allows a local attacker to execute arbitrary code via the comeinst.exe file

Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
7.3 HIGH
CVE-2025-54519 — Doc Nav DLL Hijacking Privilege Escalation Vulnerability

A DLL hijacking vulnerability in Doc Nav could allow a local attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

| Misconfiguration
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
8.7 HIGH
CVE-2025-52533 — Xilinx Spartan Debug Interface Privilege Escalation

Improper Access Control in an on-chip debug interface could allow a privileged attacker to enable a debug interface and potentially compromise data confidentiality or integrity.

Remote | Authorization
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
6.3 MEDIUM
CVE-2024-36319 — AMD VCN Firmware Register Write Vulnerability

Debug code left active in AMD's Video Decoder Engine Firmware (VCN FW) could allow a attacker to submit a maliciously crafted command causing the VCN FW to perform read/writes HW registers, potential…

| Misconfiguration
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
8.4 HIGH
CVE-2023-31323 — AMD Secure Processor ASP Type Confusion Vulnerability

Type confusion in the AMD Secure Processor (ASP) could allow an attacker to pass a malformed argument to the External Global Memory Interconnect Trusted Agent (XGMI TA) leading to a memory safety vio…

| Memory Corruption
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
4.6 MEDIUM
CVE-2023-20601 — Cisco RAS TA Driver Buffer Overflow

Improper input validation within RAS TA Driver can allow a local attacker to access out-of-bounds memory, potentially resulting in a denial-of-service condition.

| Memory Corruption
Feb 12, 2026 Feb 13, 2026
Feb 12, 2026
Feb 13, 2026
Showing 20 of 5352 Results