CVE Feed

    Dashboard / CVE

    5.1
    Medium

    CVE-2019-25316

    Last Modified: 15 Apr 2026

    GOautodial 4.0 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the event title parameter. Attackers can exploit the CreateEvent.php endpoint by sending crafted POST requests with XSS payloads to execute arbitrary JavaScript in victim browsers.

    Published: 11 Feb 2026
    5.1
    Medium

    CVE-2019-25315

    Last Modified: 15 Apr 2026

    WordPress Server Log Viewer 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through unfiltered log file paths. Attackers can add log files with embedded XSS payloads that will execute when viewed in the WordPress admin interface.

    Published: 11 Feb 2026
    4.8
    Medium

    CVE-2019-25314

    Last Modified: 15 Apr 2026

    Yoast Duplicate-Post WordPress Plugin 3.2.3 contains a persistent cross-site scripting vulnerability in plugin settings parameters. Attackers can inject malicious scripts into title prefix, suffix, menu order, and blacklist fields to execute arbitrary JavaScript in admin interfaces.

    Published: 11 Feb 2026
    5.1
    Medium

    CVE-2019-25312

    Last Modified: 5 Mar 2026

    InoERP 0.7.2 contains a persistent cross-site scripting vulnerability in the comment section that allows unauthenticated attackers to inject malicious scripts. Attackers can submit comments with JavaScript payloads that execute in other users' browsers, potentially stealing cookies and session information.

    Published: 11 Feb 2026
    5.1
    Medium

    CVE-2019-25311

    Last Modified: 12 Mar 2026

    thesystem version 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through multiple server data input fields. Attackers can submit crafted script payloads in operating_system, system_owner, system_username, system_password, system_description, and server_name parameters to execute arbitrary JavaScript in victim browsers.

    Published: 11 Feb 2026
    8.5
    High

    CVE-2019-25310

    Last Modified: 15 Apr 2026

    ActiveFax Server 6.92 Build 0316 contains an unquoted service path vulnerability in the ActiveFaxServiceNT service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be launched with elevated administrative privileges.

    Published: 11 Feb 2026
    8.5
    High

    CVE-2019-25309

    Last Modified: 15 Apr 2026

    Zilab Remote Console Server 3.2.9 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious executables that will be run with LocalSystem permissions.

    Published: 11 Feb 2026
    8.5
    High

    CVE-2019-25308

    Last Modified: 5 Mar 2026

    Mikogo 5.2.2.150317 contains an unquoted service path vulnerability in the Mikogo-Service Windows service configuration. Attackers can exploit the unquoted path to inject and execute malicious code with LocalSystem privileges by placing executable files in specific path locations.

    Published: 11 Feb 2026
    8.5
    High

    CVE-2019-25307

    Last Modified: 15 Apr 2026

    WorkgroupMail 7.5.1 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be run with LocalSystem privileges during service startup.

    Published: 11 Feb 2026
    8.5
    High

    CVE-2019-25306

    Last Modified: 15 Apr 2026

    BlackMoon FTP Server 3.1.2.1731 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to insert malicious code that would execute with LocalSystem account permissions during service startup.

    Published: 11 Feb 2026
    5.1
    Medium

    CVE-2018-25157

    Last Modified: 15 Apr 2026

    Phraseanet 4.0.3 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through crafted file names during document uploads. Attackers can upload files with embedded SVG scripts that execute in the browser, potentially stealing cookies or redirecting users when the file is viewed.

    Published: 11 Feb 2026
    8.6
    High

    CVE-2026-2344

    Last Modified: 18 Apr 2026

    A vulnerability in Plunet Plunet BusinessManager allows unauthorized actions being performed on behalf of privileged users.This issue affects Plunet BusinessManager: 10.15.1

    Published: 11 Feb 2026
    3.6
    Low

    CVE-2026-2345

    Last Modified: 17 Apr 2026

    Proctorio Chrome Extension is a browser extension used for online proctoring. The extension contains multiple window.addEventListener('message', ...) handlers that do not properly validate the origin of incoming messages. Specifically, an internal messaging bridge processes messages based solely on the presence of a fromWebsite property without verifying the event.origin attribute.

    Published: 11 Feb 2026
    7
    High

    CVE-2025-61969

    Last Modified: 15 Apr 2026

    Incorrect permission assignment in AMD µProf may allow a local user-privileged attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

    Published: 11 Feb 2026
    7.3
    High

    CVE-2025-52541

    Last Modified: 15 Apr 2026

    A DLL hijacking vulnerability in Vivado could allow a local attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

    Published: 11 Feb 2026
    7.1
    High

    CVE-2023-20548

    Last Modified: 5 Mar 2026

    A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to corrupt memory resulting in loss of integrity, confidentiality, or availability.

    Published: 11 Feb 2026
    7.1
    High

    CVE-2023-31324

    Last Modified: 5 Mar 2026

    A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify External Global Memory Interconnect Trusted Agent (XGMI TA) commands as they are processed potentially resulting in loss of confidentiality, integrity, or availability.

    Published: 11 Feb 2026
    6.9
    Medium

    CVE-2025-48518

    Last Modified: 15 Apr 2026

    Improper input validation in AMD Graphics Driver could allow a local attacker to write out of bounds, potentially resulting in loss of integrity or denial of service.

    Published: 11 Feb 2026
    7
    High

    CVE-2024-36320

    Last Modified: 15 Apr 2026

    Integer Overflow within atihdwt6.sys can allow a local attacker to cause out of bound read/write potentially leading to loss of confidentiality, integrity and availability

    Published: 11 Feb 2026
    8.7
    High

    CVE-2023-20514

    Last Modified: 15 Apr 2026

    Improper handling of parameters in the AMD Secure Processor (ASP) could allow a privileged attacker to pass an arbitrary memory value to functions in the trusted execution environment resulting in arbitrary code execution

    Published: 11 Feb 2026
    8.8
    High

    CVE-2024-36324

    Last Modified: 15 Apr 2026

    Improper input validation in AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, potentially leading to arbitrary code execution.

    Published: 11 Feb 2026
    6
    Medium

    CVE-2025-48508

    Last Modified: 15 Apr 2026

    Improper Hardware reset flow logic in the GPU GFX Hardware IP block could allow a privileged attacker in a guest virtual machine to control reset operation potentially causing host or GPU crash or reset resulting in denial of service.

    Published: 11 Feb 2026
    5.5
    Medium

    CVE-2024-36316

    Last Modified: 15 Apr 2026

    The integer overflow vulnerability within AMD Graphics driver could allow an attacker to bypass size checks potentially resulting in a denial of service

    Published: 11 Feb 2026
    7.8
    High

    CVE-2025-48503

    Last Modified: 15 Apr 2026

    A DLL hijacking vulnerability in the AMD Software Installer could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

    Published: 11 Feb 2026
    9.8
    Critical

    CVE-2026-2249

    Last Modified: 18 Apr 2026

    METIS DFS devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote attacker to execute arbitrary operating system commands with 'daemon' privileges. This results in the compromise of the software, granting unauthorized access to modify configuration, read and alter sensitive data, or disrupt services.

    Published: 11 Feb 2026
    9.8
    Critical

    CVE-2026-2248

    Last Modified: 17 Apr 2026

    METIS WIC devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote attacker to execute arbitrary operating system commands with root (UID 0) privileges. This results in full system compromise, allowing unauthorized access to modify system configuration, read sensitive data, or disrupt device operations

    Published: 11 Feb 2026
    7.5
    High

    CVE-2026-2250

    Last Modified: 17 Apr 2026

    The /dbviewer/ web endpoint in METIS WIC devices is exposed without authentication. A remote attacker can access and export the internal telemetry SQLite database containing sensitive operational data. Additionally, the application is configured with debug mode enabled, causing malformed requests to return verbose Django tracebacks that disclose backend source code, local file paths, and system configuration.

    Published: 11 Feb 2026
    9.8
    Critical

    CVE-2025-12059

    Last Modified: 4 Jun 2026

    Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Logo Software Industry and Trade Inc. Logo j-Platform allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Logo j-Platform: from 3.29.6.4 before 3.34.8.9.

    Published: 11 Feb 2026
    7
    High

    CVE-2026-1226

    Last Modified: 17 Apr 2026

    CWE‑94: Improper Control of Generation of Code vulnerability exists that could cause execution of untrusted or unintended code within the application when maliciously crafted design content is processed through a TGML graphics file.

    Published: 11 Feb 2026
    7
    High

    CVE-2026-1227

    Last Modified: 17 Apr 2026

    CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized disclosure of local files, interaction within the EBO system, or denial of service conditions when a local user uploads a specially crafted TGML graphics file to the EBO server from Workstation.

    Published: 11 Feb 2026
    9.4
    Critical

    CVE-2025-8668

    Last Modified: 5 Jun 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard allows Reflected XSS. This issue affects Turboard: from 2025.07 before 2026.02.  NOTE: This CVE record updated after the vendor implemented mitigations.

    Published: 11 Feb 2026
    8.7
    High

    CVE-2026-2337

    Last Modified: 17 Apr 2026

    A vulnerability in Plunet Plunet BusinessManager allows session hijacking, data theft, unauthorized actions on behalf of the user.This issue affects Plunet BusinessManager: 10.15.1.

    Published: 11 Feb 2026
    8.8
    High

    CVE-2026-0910

    Last Modified: 15 Apr 2026

    The wpForo Forum plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.13 via deserialization of untrusted input in the 'wpforo_display_array_data' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.

    Published: 11 Feb 2026
    1.7
    Low

    CVE-2024-56807

    Last Modified: 12 Feb 2026

    An out-of-bounds read vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local network access, they can then exploit the vulnerability to obtain secret data. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.6 ( 2024/08/02 ) and later

    Published: 11 Feb 2026
    2
    Low

    CVE-2024-56808

    Last Modified: 12 Feb 2026

    A command injection vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local network access who have also gained a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.6 ( 2024/08/02 ) and later

    Published: 11 Feb 2026
    0.6
    Low

    CVE-2025-30266

    Last Modified: 11 Feb 2026

    A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later

    Published: 11 Feb 2026
    0.6
    Low

    CVE-2025-30269

    Last Modified: 11 Feb 2026

    A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to obtain secret data or modify memory. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later

    Published: 11 Feb 2026
    4.9
    Medium

    CVE-2025-30276

    Last Modified: 11 Feb 2026

    An out-of-bounds write vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify or corrupt memory. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later

    Published: 11 Feb 2026
    5.1
    Medium

    CVE-2025-47205

    Last Modified: 27 Feb 2026

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.8.3332 build 20251128 and later QuTS hero h5.2.8.3321 build 20251117 and later

    Published: 11 Feb 2026
    1.3
    Low

    CVE-2025-47209

    Last Modified: 11 Feb 2026

    A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later

    Published: 11 Feb 2026
    1.3
    Low

    CVE-2025-48722

    Last Modified: 11 Feb 2026

    A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later

    Published: 11 Feb 2026
    0.6
    Low

    CVE-2025-48723

    Last Modified: 11 Feb 2026

    A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later

    Published: 11 Feb 2026
    0.6
    Low

    CVE-2025-48724

    Last Modified: 11 Feb 2026

    A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later

    Published: 11 Feb 2026
    0.6
    Low

    CVE-2025-48725

    Last Modified: 11 Feb 2026

    A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: QuTS hero h5.3.2.3354 build 20251225 and later

    Published: 11 Feb 2026
    0.6
    Low

    CVE-2025-52868

    Last Modified: 11 Feb 2026

    A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later

    Published: 11 Feb 2026
    9.8
    Critical

    CVE-2025-8025

    Last Modified: 5 Jun 2026

    Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Business Solutions Dinosoft ERP allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Dinosoft ERP: from < 3.0.1 through 11022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 11 Feb 2026
    0.6
    Low

    CVE-2025-52869

    Last Modified: 12 Feb 2026

    A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later

    Published: 11 Feb 2026
    0.6
    Low

    CVE-2025-52870

    Last Modified: 12 Feb 2026

    A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later

    Published: 11 Feb 2026
    0.6
    Low

    CVE-2025-53598

    Last Modified: 12 Feb 2026

    A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later

    Published: 11 Feb 2026
    1.3
    Low

    CVE-2025-54146

    Last Modified: 12 Feb 2026

    A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later

    Published: 11 Feb 2026