9.3

CVSS4.0

CVE-2026-26218 - newbee-mall Default Seeded Administrator Credentials Allow Account Takeover

newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisioned with a predictable default password. Deployments that initialize or reset the database using the provided schema and fail to change the default administrative credentials may…

πŸ“… Published: Feb. 12, 2026, 6:38 p.m. πŸ”„ Last Modified: March 5, 2026, 1:30 a.m.

5.3

CVSS3.1

CVE-2026-21438 - webtransport-go affected by a Memory Exhaustion Attack due to Missing Cleanup of Streams Map

webtransport-go is an implementation of the WebTransport protocol. Prior to 0.10.0, an attacker can cause unbounded memory consumption repeatedly creating and closing many WebTransport streams. Closed streams were not removed from an internal session map, preventing garbage collection of their reso…

πŸ“… Published: Feb. 12, 2026, 6:25 p.m. πŸ”„ Last Modified: Feb. 19, 2026, 10:50 p.m.

5.3

CVSS3.1

CVE-2026-21435 - webtransport-go CloseWithError can block indefinitely

webtransport-go is an implementation of the WebTransport protocol. Prior to v0.10.0, an attacker can cause a denial of service in webtransport-go by preventing or indefinitely delaying WebTransport session closure. A malicious peer can withhold QUIC flow control credit on the CONNECT stream, blocki…

πŸ“… Published: Feb. 12, 2026, 6:22 p.m. πŸ”„ Last Modified: Feb. 19, 2026, 10:51 p.m.

5.3

CVSS3.1

CVE-2026-21434 - webtransport-go affected by Memory Exhaustion Attack due to Missing Length Check in WT_CLOSE_SESSIO…

webtransport-go is an implementation of the WebTransport protocol. From 0.3.0 to 0.9.0, an attacker can cause excessive memory consumption in webtransport-go's session implementation by sending a WT_CLOSE_SESSION capsule containing an excessively large Application Error Message. The implementation …

πŸ“… Published: Feb. 12, 2026, 6:18 p.m. πŸ”„ Last Modified: Feb. 19, 2026, 10:53 p.m.

7.3

CVSS3.1

CVE-2025-54519 -

A DLL hijacking vulnerability in Doc Nav could allow a local attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

πŸ“… Published: Feb. 12, 2026, 5:46 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 9:35 p.m.

8.4

CVSS4.0

CVE-2023-31323 -

Type confusion in the AMD Secure Processor (ASP) could allow an attacker to pass a malformed argument to the External Global Memory Interconnect Trusted Agent (XGMI TA) leading to a memory safety violation potentially resulting in loss of confidentiality, integrity, or availability.

πŸ“… Published: Feb. 12, 2026, 5:45 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 9:35 p.m.

6.3

CVSS4.0

CVE-2024-36319 -

Debug code left active in AMD's Video Decoder Engine Firmware (VCN FW) could allow a attacker to submit a maliciously crafted command causing the VCN FW to perform read/writes HW registers, potentially impacting confidentiality, integrity and availabilability of the system.

πŸ“… Published: Feb. 12, 2026, 5:41 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 2:44 p.m.

4.6

CVSS4.0

CVE-2023-20601 -

Improper input validation within RAS TA Driver can allow a local attacker to access out-of-bounds memory, potentially resulting in a denial-of-service condition.

πŸ“… Published: Feb. 12, 2026, 5:31 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 9:35 p.m.

8.7

CVSS4.0

CVE-2025-52533 -

Improper Access Control in an on-chip debug interface could allow a privileged attacker to enable a debug interface and potentially compromise data confidentiality or integrity.

πŸ“… Published: Feb. 12, 2026, 5:11 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 2:44 p.m.

8.6

CVSS4.0

CVE-2025-54756 - BrightSign Players Use of Default Credentials

BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 use a default password that is guessable with knowledge of the device information. The latest release fixes this issue for new installations; users of old installations are encouraged to change al…

πŸ“… Published: Feb. 12, 2026, 4:34 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 9:35 p.m.
Total resulsts: 343935
Page 1135 of 34,394
Β« previous page Β» next page
Filters