6

CVSS4.0

CVE-2025-48019 -

A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receives maliciously crafted packets, Vnet/IP software stack process may be terminated. The affected products and versions are as follows: Vnet/IP Interface Package (for CENTUMโ€ฆ

๐Ÿ“… Published: Feb. 13, 2026, 4:51 a.m. ๐Ÿ”„ Last Modified: March 2, 2026, 3:34 p.m.

6

CVSS4.0

CVE-2025-1924 -

A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receive maliciously crafted packets, a DoS attack may cause Vnet/IP communication functions to stop or arbitrary programs to be executed. The affected products and versions areโ€ฆ

๐Ÿ“… Published: Feb. 13, 2026, 4:46 a.m. ๐Ÿ”„ Last Modified: March 2, 2026, 3:33 p.m.

8.7

CVSS4.0

CVE-2026-25108 - OS Command Injection in FileZen Antivirus Check Option Allowing Arbitrary Command Execution

FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command.

๐Ÿ“… Published: Feb. 13, 2026, 3:39 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 8 p.m.

6.2

CVSS4.0

CVE-2026-1721 - Reflected Cross-Site Scripting (XSS) vulnerability in AI Playground site

Summary A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the AI Playground's OAuth callback handler. The `error_description` query parameter was directly interpolated into an HTML script tag without proper escaping, allowing attackers to execute arbitrary JavaScript in the coโ€ฆ

๐Ÿ“… Published: Feb. 13, 2026, 1:46 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 8 p.m.

7.7

CVSS4.0

CVE-2025-9293 - Insufficient Certificate Validation in Multiple Mobile Applications Allows Man in the Middle Intercโ€ฆ

A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS communication. An attacker in a privileged network position may be able to intercept or modify traffic if they can position themselves within the commuโ€ฆ

๐Ÿ“… Published: Feb. 13, 2026, 12:22 a.m. ๐Ÿ”„ Last Modified: April 1, 2026, 8:49 p.m.

2

CVSS4.0

CVE-2025-9292 - Permissive Web Security Policy Allows Cross-Origin Access Control Bypass on Omada Cloud Controllers

A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. Exploitation requires the presence of an existing client-side injection vulnerability and user access to the affected web interface. Successful explโ€ฆ

๐Ÿ“… Published: Feb. 13, 2026, 12:21 a.m. ๐Ÿ”„ Last Modified: April 1, 2026, 8:52 p.m.

5.3

CVSS3.1

CVE-2026-2443 - Libsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information disclosure

A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build configurations, this could allow a remote attacker to access portions of server memoโ€ฆ

๐Ÿ“… Published: Feb. 13, 2026, midnight ๐Ÿ”„ Last Modified: April 16, 2026, 7 a.m.

8.8

CVSS3.1

CVE-2025-70866 -

LavaLite CMS 10.1.0 is vulnerable to Incorrect Access Control. An authenticated user with low-level privileges (User role) can directly access the admin backend by logging in through /admin/login. The vulnerability exists because the admin and user authentication guards share the same user providerโ€ฆ

๐Ÿ“… Published: Feb. 13, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 19, 2026, 7:35 p.m.

7.5

CVSS3.1

CVE-2025-70957 -

A Denial of Service (DoS) vulnerability was discovered in the TON Lite Server before v2024.09. The vulnerability arises from the handling of external arguments passed to locally executed "get methods." An attacker can inject a constructed Continuation object (an internal TVM type) that is normally โ€ฆ

๐Ÿ“… Published: Feb. 13, 2026, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-70956 -

A State Pollution vulnerability was discovered in the TON Virtual Machine (TVM) before v2025.04. The issue exists in the RUNVM instruction logic (VmState::run_child_vm), which is responsible for initializing child virtual machines. The operation moves critical resources (specifically libraries and โ€ฆ

๐Ÿ“… Published: Feb. 13, 2026, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 348542
Page 1585 of 34,855
ยซ previous page ยป next page
Filters