7.5

CVSS3.1

CVE-2025-70886 -

An issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the public comment submission endpoint

πŸ“… Published: Feb. 12, 2026, midnight πŸ”„ Last Modified: Feb. 18, 2026, 3:45 p.m.

5.4

CVSS3.1

CVE-2026-25828 - Unsanitized $root Parameter in grub-btrfs Enables Initramfs Command Injection

grub-btrfs through 2026-01-31 (on Arch Linux and derivative distributions) allows initramfs OS command injection because it does not sanitize the $root parameter to resolve_device(). NOTE: a third party reports "exploitation may not be feasible under normal conditions and may depend on specific imp…

πŸ“… Published: Feb. 12, 2026, midnight πŸ”„ Last Modified: April 16, 2026, 5:15 p.m.

6.1

CVSS3.1

CVE-2025-70845 -

lty628 aidigu v1.9.1 is vulnerable to Cross Site Scripting (XSS) exists in the /setting/ page where the "intro" field is not properly sanitized or escaped.

πŸ“… Published: Feb. 12, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-70314 -

webfsd 1.21 is vulnerable to a Buffer Overflow via a crafted request. This is due to the filename variable

πŸ“… Published: Feb. 12, 2026, midnight πŸ”„ Last Modified: Feb. 18, 2026, 7:53 p.m.

9.8

CVSS3.1

CVE-2025-70981 -

CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds parameter.

πŸ“… Published: Feb. 12, 2026, midnight πŸ”„ Last Modified: Feb. 18, 2026, 7:54 p.m.

7.8

CVSS3.1

CVE-2025-63421 -

An issue in filosoft Comerc.32 Commercial Invoicing v.16.0.0.3 allows a local attacker to execute arbitrary code via the comeinst.exe file

πŸ“… Published: Feb. 12, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-67433 -

A heap buffer overflow in the processRequest function of Open TFTP Server MultiThreaded v1.7 allows attackers to cause a Denial of Service (DoS) via a crafted DATA packet.

πŸ“… Published: Feb. 12, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-56647 -

npm @farmfe/core before 1.7.6 is Missing Origin Validation in WebSocket. The development (hot module reloading) server does not validate origin when connecting to a WebSocket client. This allows attackers to surveil developers running Farm who visit their webpage and steal source code that is leake…

πŸ“… Published: Feb. 12, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-69752 -

An issue in the "My Details" user profile functionality of Ideagen Q-Pulse 7.1.0.32 allows an authenticated user to view other users' profile information by modifying the objectKey HTTP parameter in the My Details page URL.

πŸ“… Published: Feb. 12, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-70092 -

A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Item Name parameter.

πŸ“… Published: Feb. 12, 2026, midnight πŸ”„ Last Modified: Feb. 18, 2026, 3:45 p.m.
Total resulsts: 349182
Page 1664 of 34,919
Β« previous page Β» next page
Filters