7.5

CVSS3.1

CVE-2025-70886 -

An issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the public comment submission endpoint

๐Ÿ“… Published: Feb. 12, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 18, 2026, 3:45 p.m.

7.5

CVSS3.1

CVE-2025-69807 -

p2r3 Bareiron commit: 8e4d4020d is vulnerable to Buffer Overflow, which allows unauthenticated remote attackers to cause a denial of service via a packet sent to the server.

๐Ÿ“… Published: Feb. 12, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 23, 2026, 5:20 p.m.

9.8

CVSS3.1

CVE-2025-70314 -

webfsd 1.21 is vulnerable to a Buffer Overflow via a crafted request. This is due to the filename variable

๐Ÿ“… Published: Feb. 12, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 18, 2026, 7:53 p.m.

7.8

CVSS3.1

CVE-2025-63421 -

An issue in filosoft Comerc.32 Commercial Invoicing v.16.0.0.3 allows a local attacker to execute arbitrary code via the comeinst.exe file

๐Ÿ“… Published: Feb. 12, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 13, 2026, 9:35 p.m.

9.8

CVSS3.1

CVE-2025-70981 -

CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds parameter.

๐Ÿ“… Published: Feb. 12, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 18, 2026, 7:54 p.m.

4.3

CVSS3.1

CVE-2025-69752 -

An issue in the "My Details" user profile functionality of Ideagen Q-Pulse 7.1.0.32 allows an authenticated user to view other users' profile information by modifying the objectKey HTTP parameter in the My Details page URL.

๐Ÿ“… Published: Feb. 12, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 18, 2026, 3:18 p.m.

7.5

CVSS3.1

CVE-2025-67432 -

A stack overflow in the ZBarcode_Encode function of Monkeybread Software MBS DynaPDF Plugin v21.3.1.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

๐Ÿ“… Published: Feb. 12, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 13, 2026, 9:35 p.m.

5.5

CVSS3.1

CVE-2025-70092 -

A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Item Name parameter.

๐Ÿ“… Published: Feb. 12, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 18, 2026, 3:45 p.m.

7.5

CVSS3.1

CVE-2025-67433 -

A heap buffer overflow in the processRequest function of Open TFTP Server MultiThreaded v1.7 allows attackers to cause a Denial of Service (DoS) via a crafted DATA packet.

๐Ÿ“… Published: Feb. 12, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 26, 2026, 10:20 p.m.

9

CVSS3.1

CVE-2025-69634 -

Cross Site Request Forgery vulnerability in Dolibarr ERP & CRM v.22.0.9 allows a remote attacker to escalate privileges via the notes field in perms.php NOTE: this is disputed by a third party who indicates that exploitation can only occur if an unprivileged user knows the token of an admin user.

๐Ÿ“… Published: Feb. 12, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 14, 2026, 5:16 a.m.
Total resulsts: 343975
Page 1145 of 34,398
ยซ previous page ยป next page
Filters