8.7

CVSS4.0

CVE-2026-25108 -

FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command.

πŸ“… Published: Feb. 13, 2026, 3:39 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 2:44 p.m.

6.2

CVSS4.0

CVE-2026-1721 - Reflected Cross-Site Scripting (XSS) vulnerability in AI Playground site

Summary A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the AI Playground's OAuth callback handler. The `error_description` query parameter was directly interpolated into an HTML script tag without proper escaping, allowing attackers to execute arbitrary JavaScript in the co…

πŸ“… Published: Feb. 13, 2026, 1:46 a.m. πŸ”„ Last Modified: Feb. 27, 2026, 3:16 p.m.

7.7

CVSS4.0

CVE-2025-9293 - Insufficient Certificate Validation in Multiple Mobile Applications Allows Man in the Middle Interc…

A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS communication. An attacker in a privileged network position may be able to intercept or modify traffic if they can position themselves within the commu…

πŸ“… Published: Feb. 13, 2026, 12:22 a.m. πŸ”„ Last Modified: April 1, 2026, 8:49 p.m.

2

CVSS4.0

CVE-2025-9292 - Permissive Web Security Policy Allows Cross-Origin Access Control Bypass on Omada Cloud Controllers

A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. Exploitation requires the presence of an existing client-side injection vulnerability and user access to the affected web interface. Successful expl…

πŸ“… Published: Feb. 13, 2026, 12:21 a.m. πŸ”„ Last Modified: April 1, 2026, 8:52 p.m.

10

CVSS3.1

CVE-2025-69770 -

A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execute arbitrary commands via uploading a crafted zip file.

πŸ“… Published: Feb. 13, 2026, midnight πŸ”„ Last Modified: Feb. 13, 2026, 9:43 p.m.

8.8

CVSS3.1

CVE-2026-2441 - chromium-browser: Use after free in CSS

Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: Feb. 13, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 2:44 p.m.

5.3

CVSS3.1

CVE-2026-2443 - Libsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information disclosure

A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build configurations, this could allow a remote attacker to access portions of server memo…

πŸ“… Published: Feb. 13, 2026, midnight πŸ”„ Last Modified: March 23, 2026, 8:16 p.m.

8.8

CVSS3.1

CVE-2025-70866 -

LavaLite CMS 10.1.0 is vulnerable to Incorrect Access Control. An authenticated user with low-level privileges (User role) can directly access the admin backend by logging in through /admin/login. The vulnerability exists because the admin and user authentication guards share the same user provider…

πŸ“… Published: Feb. 13, 2026, midnight πŸ”„ Last Modified: Feb. 19, 2026, 7:35 p.m.

7.5

CVSS3.1

CVE-2025-70122 -

A heap buffer overflow vulnerability in the UPF component of free5GC v4.0.1 allows remote attackers to cause a denial of service via a crafted PFCP Session Modification Request. The issue occurs in the SDFFilterFields.UnmarshalBinary function (sdf-filter.go) when processing a declared length that e…

πŸ“… Published: Feb. 13, 2026, midnight πŸ”„ Last Modified: Feb. 18, 2026, 3:40 p.m.

7.5

CVSS3.1

CVE-2025-70955 -

A Stack Overflow vulnerability was discovered in the TON Virtual Machine (TVM) before v2024.10. The vulnerability stems from the improper handling of vmstate and continuation jump instructions, which allow for continuous dynamic tail calls. An attacker can exploit this by crafting a smart contract …

πŸ“… Published: Feb. 13, 2026, midnight πŸ”„ Last Modified: Feb. 18, 2026, 5:52 p.m.
Total resulsts: 343921
Page 1125 of 34,393
Β« previous page Β» next page
Filters