CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2025-70083

    Last Modified: 17 Feb 2026

    An issue was discovered in OpenSatKit 2.2.1. The DirName field in the telecommand is provided by the ground segment and must be treated as untrusted input. The program copies DirName into the local buffer DirWithSep using strcpy. The size of this buffer is OS_MAX_PATH_LEN. If the length of DirName is greater than or equal to OS_MAX_PATH_LEN, a stack buffer overflow occurs, overwriting adjacent stack memory. The path length check (FileUtil_AppendPathSep) is performed after the strcpy operation, meaning the validation occurs too late and cannot prevent the overflow.

    Published: 11 Feb 2026
    6.1
    Medium

    CVE-2025-70297

    Last Modified: 23 Feb 2026

    A stored cross-site scripting (XSS) vulnerability in the recipe asset upload and media serving component in Mealie 3.3.1 allows remote authenticated users to inject arbitrary web script or HTML via an uploaded SVG file that is served as image/svg+xml and rendered by a victim s browser.

    Published: 11 Feb 2026
    5.3
    Medium

    CVE-2025-64074

    Last Modified: 15 Apr 2026

    A path-traversal vulnerability in the logout functionality of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to delete arbitrary files on the host by supplying a crafted session cookie value.

    Published: 11 Feb 2026
    5.3
    Medium

    CVE-2024-26479

    Last Modified: 26 Feb 2026

    An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the Command execution function.

    Published: 11 Feb 2026
    7
    High

    CVE-2026-26158

    Last Modified: 2 Jun 2026

    A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction directory by crafting a malicious tar archive containing unvalidated hardlink or symlink entries. If the tar archive is extracted with elevated privileges, this flaw can lead to privilege escalation, enabling an attacker to gain unauthorized access to critical system files.

    Published: 11 Feb 2026
    5.4
    Medium

    CVE-2025-70296

    Last Modified: 23 Feb 2026

    A stored HTML injection vulnerability in the Recipe Notes rendering component in Mealie 3.3.1 allows remote authenticated users to inject arbitrary HTML, resulting in user interface redressing within the recipe view.

    Published: 11 Feb 2026
    9.8
    Critical

    CVE-2025-70085

    Last Modified: 17 Feb 2026

    An issue was discovered in OpenSatKit 2.2.1. The EventErrStr buffer has a fixed size of 256 bytes. The code uses sprintf to format two filenames (Source1Filename and the string returned by FileUtil_FileStateStr) into this buffer without any length checking and without using bounded format specifiers such as %.*s. If the filename length approaches OS_MAX_PATH_LEN (commonly 64-256 bytes), the combined formatted string together with constant text can exceed 256 bytes, resulting in a stack buffer overflow. Such unsafe sprintf calls are scattered across multiple functions in file.c, including FILE_ConcatenateCmd() and ConcatenateFiles(), all of which fail to validate the output length.

    Published: 11 Feb 2026
    7.5
    High

    CVE-2025-70084

    Last Modified: 17 Feb 2026

    Directory traversal vulnerability in OpenSatKit 2.2.1 allows attackers to gain access to sensitive information or delete arbitrary files via crafted value to the FileUtil_GetFileInfo function.

    Published: 11 Feb 2026
    9.8
    Critical

    CVE-2025-69872

    Last Modified: 15 Apr 2026

    DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache directory can achieve arbitrary code execution when a victim application reads from the cache.

    Published: 11 Feb 2026
    9.8
    Critical

    CVE-2025-67135

    Last Modified: 15 Apr 2026

    Weak Security in the PF-50 1.2 keyfob of PGST PG107 Alarm System 1.25.05.hf allows attackers to compromise access control via a code replay attack.

    Published: 11 Feb 2026
    8.8
    High

    CVE-2025-65480

    Last Modified: 15 Apr 2026

    An issue was discovered in Pacom Unison Client 5.13.1. Authenticated users can inject malicious scripts in the Report Templates which are executed when certain script conditions are fulfilled, leading to Remote Code Execution.

    Published: 11 Feb 2026
    8.1
    High

    CVE-2025-65128

    Last Modified: 15 Apr 2026

    A missing authentication mechanism in the web management API components of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows unauthenticated attackers on the local network to modify router and network configurations. By invoking operations whose names end with "*_nocommit" and supplying the parameters expected by the invoked function, an attacker can change configuration data, including SSID, Wi-Fi credentials, and administrative passwords, without authentication or an existing session.

    Published: 11 Feb 2026
    7.5
    High

    CVE-2024-26480

    Last Modified: 28 Feb 2026

    An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the admin parameter.

    Published: 11 Feb 2026
    4.3
    Medium

    CVE-2024-50618

    Last Modified: 17 Feb 2026

    A Use of Single-factor Authentication vulnerability in the Authentication component of CIPPlanner CIPAce before 9.17 allows attackers to bypass a protection mechanism. When the system is configured to allow login with internal accounts, an attacker can possibly obtain full authentication if the secret in a single-factor authentication scheme gets compromised.

    Published: 11 Feb 2026
    9.8
    Critical

    CVE-2025-69874

    Last Modified: 3 Apr 2026

    nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary files outside the intended extraction directory via a crafted tar archive containing path traversal sequence.

    Published: 11 Feb 2026
    7.5
    High

    CVE-2024-50617

    Last Modified: 13 Feb 2026

    Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow attackers to download unauthorized files. An authenticated user can easily change the file id parameter or pass the physical file path in the URL query string to retrieve the files. (Retrieval is not intended without correct data access configured for documents.)

    Published: 11 Feb 2026
    10
    Critical

    CVE-2025-64075

    Last Modified: 15 Apr 2026

    A path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to bypass authentication and perform administrative actions by supplying a crafted session cookie value.

    Published: 11 Feb 2026
    8.8
    High

    CVE-2024-50619

    Last Modified: 13 Feb 2026

    Vulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attackers to escalate their access levels. A low-privileged authenticated user can gain access to other people's accounts by tampering with the client's user id to change their account information. A low-privileged authenticated user can elevate his or her system privileges by modifying the information of a user role that is disabled in the client.

    Published: 11 Feb 2026
    6.5
    Medium

    CVE-2026-2436

    Last Modified: 21 Apr 2026

    A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup_server_disconnect()` function frees connection objects prematurely, even if a TLS handshake is still pending. If the handshake completes after the connection object has been freed, a dangling pointer is accessed, leading to a server crash and a Denial of Service.

    Published: 11 Feb 2026
    7.5
    High

    CVE-2025-70029

    Last Modified: 1 Apr 2026

    An issue in Sunbird-Ed SunbirdEd-portal v1.13.4 allows attackers to obtain sensitive information. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in HTTP request options

    Published: 11 Feb 2026
    8.1
    High

    CVE-2025-69871

    Last Modified: 15 Apr 2026

    A race condition vulnerability exists in MedusaJS Medusa v2.12.2 and earlier in the registerUsage() function of the promotion module. The function performs a non-atomic read-check-update operation when enforcing promotion usage limits. This allows unauthenticated remote attackers to bypass usage limits by sending concurrent checkout requests, resulting in unlimited redemptions of limited-use promotional codes and potential financial loss.

    Published: 11 Feb 2026
    6.9
    Medium

    CVE-2026-25872

    Last Modified: 18 Apr 2026

    JUNG Smart Panel KNX firmware version L1.12.22 and prior contain an unauthenticated path traversal vulnerability in the embedded web interface. The application fails to properly validate file path input, allowing remote, unauthenticated attackers to access arbitrary files on the underlying filesystem within the context of the web server. This may result in disclosure of system configuration files and other sensitive information.

    Published: 10 Feb 2026
    6.9
    Medium

    CVE-2026-25870

    Last Modified: 15 Apr 2026

    DoraCMS version 3.1 and prior contains a server-side request forgery (SSRF) vulnerability in its UEditor remote image fetch functionality. The application accepts user-supplied URLs and performs server-side HTTP or HTTPS requests without sufficient validation or destination restrictions. The implementation does not enforce allowlists, block internal or private IP address ranges, or apply request timeouts or response size limits. An attacker can abuse this behavior to induce the server to issue outbound requests to arbitrary hosts, including internal network resources, potentially enabling internal network scanning and denial of service through resource exhaustion.

    Published: 10 Feb 2026
    3.7
    Low

    CVE-2026-26013

    Last Modified: 18 Apr 2026

    LangChain is a framework for building agents and LLM-powered applications. Prior to 1.2.11, the ChatOpenAI.get_num_tokens_from_messages() method fetches arbitrary image_url values without validation when computing token counts for vision-enabled models. This allows attackers to trigger Server-Side Request Forgery (SSRF) attacks by providing malicious image URLs in user input. This vulnerability is fixed in 1.2.11.

    Published: 10 Feb 2026
    8.2
    High

    CVE-2026-26007

    Last Modified: 18 Apr 2026

    cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5.

    Published: 10 Feb 2026
    6.5
    Medium

    CVE-2026-26006

    Last Modified: 17 Apr 2026

    AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. The autogpt before 0.6.32 is vulnerable to Regular Expression Denial of Service due to the use of regex at Code Extraction Block. The two Regex are used containing the corresponding dangerous patterns \s+[\s\S]*? and \s+(.*?). They share a common characteristic — the combination of two adjacent quantifiers that can match the same space character (\s). As a result, an attacker can supply a long sequence of space characters to trigger excessive regex backtracking, potentially leading to a Denial of Service (DoS). This vulnerability is fixed in 0.6.32.

    Published: 10 Feb 2026
    6.7
    Medium

    CVE-2025-12699

    Last Modified: 15 Apr 2026

    The ZOLL ePCR IOS application reflects unsanitized user input into a WebView. Attacker-controlled strings placed into PCR fields (run number, incident, call sign, notes) are interpreted as HTML/JS when the app prints or renders that content. In the proof of concept (POC), injected scripts return local file content, which would allow arbitrary local file reads from the app's runtime context. These local files contain device and user data within the ePCR medical application, and if exposed, would allow an attacker to access protected health information (PHI) or device telemetry.

    Published: 10 Feb 2026
    8.7
    High

    CVE-2026-1507

    Last Modified: 17 Apr 2026

    The affected products are vulnerable to an uncaught exception that could allow an unauthenticated attacker to remotely crash core PI services resulting in a denial-of-service.

    Published: 10 Feb 2026
    5.7
    Medium

    CVE-2026-1495

    Last Modified: 18 Apr 2026

    The vulnerability, if exploited, could allow an attacker with Event Log Reader (S-1-5-32-573) privileges to obtain proxy details, including URL and proxy credentials, from the PI to CONNECT event log files. This could enable unauthorized access to the proxy server.

    Published: 10 Feb 2026
    4.6
    Medium

    CVE-2026-1763

    Last Modified: 17 Apr 2026

    Vulnerability in GE Vernova Enervista UR Setup on Windows.This issue affects Enervista: 8.6 and previous versions.

    Published: 10 Feb 2026
    2.9
    Low

    CVE-2026-1762

    Last Modified: 16 Apr 2026

    A vulnerability in GE Vernova Enervista UR Setup on Windows allows File Manipulation.This issue affects Enervista: 8.6 and prior versions.

    Published: 10 Feb 2026
    7.3
    High

    CVE-2025-29951

    Last Modified: 15 Apr 2026

    A buffer overflow in the AMD Secure Processor (ASP) bootloader could allow an attacker to overwrite memory, potentially resulting in privilege escalation and arbitrary code execution.

    Published: 10 Feb 2026
    4.6
    Medium

    CVE-2024-36311

    Last Modified: 15 Apr 2026

    A Time-of-check time-of-use (TOCTOU) race condition in the SMM communications buffer could allow a privileged attacker to bypass input validation and perform an out of bounds read or write, potentially resulting in loss of confidentiality, integrity, or availability.

    Published: 10 Feb 2026
    5.4
    Medium

    CVE-2025-48515

    Last Modified: 15 Apr 2026

    Insufficient parameter sanitization in AMD Secure Processor (ASP) Boot Loader could allow an attacker with access to SPIROM upgrade to overwrite the memory, potentially resulting in arbitrary code execution.

    Published: 10 Feb 2026
    1.8
    Low

    CVE-2021-26410

    Last Modified: 15 Apr 2026

    Improper syscall input validation in ASP (AMD Secure Processor) may force the kernel into reading syscall parameter values from its own memory space allowing an attacker to infer the contents of the kernel memory leading to potential information disclosure.

    Published: 10 Feb 2026
    7.1
    High

    CVE-2021-26381

    Last Modified: 15 Apr 2026

    Improper system call parameter validation in the Trusted OS may allow a malicious driver to perform mapping or unmapping operations on a large number of pages, potentially resulting in kernel memory corruption.

    Published: 10 Feb 2026
    4.8
    Medium

    CVE-2025-29949

    Last Modified: 15 Apr 2026

    Insufficient input parameter sanitization in AMD Secure Processor (ASP) Boot Loader (legacy recovery mode only) could allow an attacker to write out-of-bounds to corrupt Secure DRAM potentially resulting in denial of service.

    Published: 10 Feb 2026
    7.8
    High

    CVE-2026-21349

    Last Modified: 18 Apr 2026

    Lightroom Desktop versions 15.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Feb 2026
    5.5
    Medium

    CVE-2026-21348

    Last Modified: 17 Apr 2026

    Substance3D - Modeler versions 1.22.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Feb 2026
    7
    High

    CVE-2024-36355

    Last Modified: 15 Apr 2026

    Improper input validation in the SMM handler could allow an attacker with Ring0 access to write to SMRAM and modify execution flow for S3 (sleep) wake up, potentially resulting in arbitrary code execution.

    Published: 10 Feb 2026
    4.6
    Medium

    CVE-2024-36310

    Last Modified: 15 Apr 2026

    Improper input validation in the SMM communications buffer could allow a privileged attacker to perform an out of bounds read or write to SMRAM potentially resulting in loss of confidentiality or integrity.

    Published: 10 Feb 2026
    4.5
    Medium

    CVE-2025-29946

    Last Modified: 15 Apr 2026

    Insufficient or Incomplete Data Removal in Hardware Component in SEV firmware doesn't fully flush IOMMU. This can potentially lead to a loss of confidentiality and integrity in guest memory.

    Published: 10 Feb 2026
    1.8
    Low

    CVE-2025-0029

    Last Modified: 15 Apr 2026

    Improper handling of error condition during host-induced faults can allow a local high-privileged attack to selectively drop guest DMA writes, potentially resulting in a loss of SEV-SNP guest memory integrity

    Published: 10 Feb 2026
    4.6
    Medium

    CVE-2025-0031

    Last Modified: 15 Apr 2026

    A use after free in the SEV firmware could allow a malicous hypervisor to activate a migrated guest with the SINGLE_SOCKET policy on a different socket than the migration agent potentially resulting in loss of integrity.

    Published: 10 Feb 2026
    4
    Medium

    CVE-2025-48514

    Last Modified: 15 Apr 2026

    Insufficient Granularity of Access Control in SEV firmware can allow a privileged attacker to create a SEV-ES Guest to attack SNP guest, potentially resulting in a loss of confidentiality.

    Published: 10 Feb 2026
    4.8
    Medium

    CVE-2025-54514

    Last Modified: 15 Apr 2026

    Improper isolation of shared resources on a system on a chip by a malicious local attacker with high privileges could potentially lead to a partial loss of integrity.

    Published: 10 Feb 2026
    1.8
    Low

    CVE-2025-48509

    Last Modified: 15 Apr 2026

    Missing Checks in certain functions related to RMP initialization can allow a local admin privileged attacker to cause misidentification of I/O memory, potentially resulting in a loss of guest memory integrity

    Published: 10 Feb 2026
    5.3
    Medium

    CVE-2025-52534

    Last Modified: 15 Apr 2026

    Improper bound check within AMD CPU microcode can allow a malicious guest to write to host memory, potentially resulting in loss of integrity.

    Published: 10 Feb 2026
    6.8
    Medium

    CVE-2025-0012

    Last Modified: 15 Apr 2026

    Improper handling of overlap between the segmented reverse map table (RMP) and system management mode (SMM) memory could allow a privileged attacker corrupt or partially infer SMM memory resulting in loss of integrity or confidentiality.

    Published: 10 Feb 2026
    6.9
    Medium

    CVE-2025-29939

    Last Modified: 15 Apr 2026

    Improper access control in secure encrypted virtualization (SEV) could allow a privileged attacker to write to the reverse map page (RMP) during secure nested paging (SNP) initialization, potentially resulting in a loss of guest memory confidentiality and integrity.

    Published: 10 Feb 2026