Total
336347 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-31323 | 2026-02-13 | N/A | N/A | ||
|
Type confusion in the AMD Secure Processor (ASP) could allow an attacker to pass a malformed argument to the External Global Memory Interconnect Trusted Agent (XGMI TA) leading to a memory safety violation potentially resulting in loss of confidentiality, integrity, or availability.
|
|||||
| CVE-2026-26056 | 2026-02-13 | N/A | 8.8 HIGH | ||
|
Yoke is a Helm-inspired infrastructure-as-code (IaC) package deployer. In 0.19.0 and earlier, a vulnerability exists in the Air Traffic Controller (ATC) component of Yoke. It allows users with CR create/update permissions to execute arbitrary WASM code in the ATC controller context by injecting a malicious URL through the overrides.yoke.cd/flight annotation. The ATC controller downloads and executes the WASM module without proper URL validation, enabling attackers to create arbitrary Kubernetes ...
Show More |
|||||
| CVE-2019-25318 | 2026-02-13 | N/A | 8.8 HIGH | ||
|
AVS Audio Converter 9.1.2.600 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by manipulating the output folder text input. Attackers can craft a malicious payload that overwrites stack memory and triggers a bind shell on port 9999 when the 'Browse' button is clicked.
|
|||||
| CVE-2025-56647 | 2026-02-13 | N/A | 6.5 MEDIUM | ||
|
npm @farmfe/core before 1.7.6 is Missing Origin Validation in WebSocket. The development (hot module reloading) server does not validate origin when connecting to a WebSocket client. This allows attackers to surveil developers running Farm who visit their webpage and steal source code that is leaked by the WebSocket server.
|
|||||
| CVE-2025-54756 | 2026-02-13 | N/A | 8.4 HIGH | ||
|
BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or
series 5 prior to v9.0.166 use a default password that is guessable with
knowledge of the device information. The latest release fixes this
issue for new installations; users of old installations are encouraged
to change all default passwords.
|
|||||
| CVE-2019-25319 | 2026-02-13 | N/A | 9.8 CRITICAL | ||
|
Domain Quester Pro 6.02 contains a stack overflow vulnerability that allows remote attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Attackers can craft a malicious payload targeting the 'Domain Name Keywords' input field to trigger an access violation and execute a bind shell on port 9999.
|
|||||
| CVE-2023-31313 | 2026-02-13 | N/A | 7.2 HIGH | ||
|
An unintended proxy or intermediary in the AMD power management firmware (PMFW) could allow a privileged attacker to send malformed messages to the system management unit (SMU) potentially resulting in arbitrary code execution.
|
|||||
| CVE-2026-1104 | 2026-02-13 | N/A | 8.8 HIGH | ||
|
The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to unauthorized backup creation and download due to a missing capability check on REST API endpoints in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to create and download full-site backup archives containing the entire WordPress installation, including database exports and configuration files.
|
|||||
| CVE-2019-25332 | 2026-02-13 | N/A | 8.4 HIGH | ||
|
FTP Commander Pro 8.03 contains a local stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting the EIP register through a custom command input. Attackers can craft a malicious payload of 4108 bytes to overwrite memory and execute shellcode, demonstrating remote code execution potential.
|
|||||
| CVE-2025-67432 | 2026-02-13 | N/A | 7.5 HIGH | ||
|
A stack overflow in the ZBarcode_Encode function of Monkeybread Software MBS DynaPDF Plugin v21.3.1.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.
|
|||||
| CVE-2025-52533 | 2026-02-13 | N/A | N/A | ||
|
Improper Access Control in an on-chip debug interface could allow a privileged attacker to enable a debug interface and potentially compromise data confidentiality or integrity.
|
|||||
| CVE-2026-23112 | 2026-02-13 | N/A | N/A | ||
|
In the Linux kernel, the following vulnerability has been resolved:
nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec
nvmet_tcp_build_pdu_iovec() could walk past cmd->req.sg when a PDU
length or offset exceeds sg_cnt and then use bogus sg->length/offset
values, leading to _copy_to_iter() GPF/KASAN. Guard sg_idx, remaining
entries, and sg->length/offset before building the bvec.
|
|||||
| CVE-2019-25328 | 2026-02-13 | N/A | 7.5 HIGH | ||
|
XnConvert 1.82 contains a denial of service vulnerability in its registration code input field that allows attackers to crash the application. Attackers can generate a 9000-byte buffer of repeated characters and paste it into the registration code field to trigger an application crash.
|
|||||
| CVE-2019-25327 | 2026-02-13 | N/A | 9.8 CRITICAL | ||
|
Prime95 version 29.8 build 6 contains a buffer overflow vulnerability in the user ID input field that allows remote attackers to execute arbitrary code. Attackers can craft a malicious payload and paste it into the PrimeNet user ID and proxy host fields to trigger a bind shell on port 3110.
|
|||||
| CVE-2024-36319 | 2026-02-13 | N/A | N/A | ||
|
Debug code left active in AMD's Video Decoder Engine Firmware (VCN FW) could allow a attacker to submit a maliciously crafted command causing the VCN FW to perform read/writes HW registers, potentially impacting confidentiality, integrity and availabilability of the system.
|
|||||
| CVE-2025-59473 | 1 Expressionengine | 1 Expressionengine | 2026-02-13 | N/A | 7.2 HIGH |
|
SQL Injection vulnerability in the Structure for Admin authenticated user
|
|||||
| CVE-2024-43468 | 1 Microsoft | 3 Configuration Manager 2403, Configuration Manager 2409, Configuration Manager 2503 | 2026-02-13 | N/A | 9.8 CRITICAL |
|
Microsoft Configuration Manager Remote Code Execution Vulnerability
|
|||||
| CVE-2026-20700 | 1 Apple | 6 Ipados, Iphone Os, Macos and 3 more | 2026-02-13 | N/A | 7.8 HIGH |
|
A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 26.3, tvOS 26.3, macOS Tahoe 26.3, visionOS 26.3, iOS 26.3 and iPadOS 26.3. An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 and CVE-2025-43529 were also issued in response to ...
Show More |
|||||
| CVE-2025-40536 | 1 Solarwinds | 1 Web Help Desk | 2026-02-13 | N/A | 8.1 HIGH |
|
SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality.
|
|||||
| CVE-2025-15556 | 1 Notepad-plus-plus | 1 Notepad\+\+ | 2026-02-13 | N/A | 7.5 HIGH |
|
Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update metadata and installers are not cryptographically verified. An attacker able to intercept or redirect update traffic can cause the updater to download and execute an attacker-controlled installer, resulting in arbitrary code execution with the privileges of the user.
|
|||||
| CVE-2026-26257 | 2026-02-13 | N/A | N/A | ||
|
Rejected reason: Not used
|
|||||
| CVE-2026-26256 | 2026-02-13 | N/A | N/A | ||
|
Rejected reason: Not used
|
|||||
| CVE-2026-26255 | 2026-02-13 | N/A | N/A | ||
|
Rejected reason: Not used
|
|||||
| CVE-2026-26254 | 2026-02-13 | N/A | N/A | ||
|
Rejected reason: Not used
|
|||||
| CVE-2026-26253 | 2026-02-13 | N/A | N/A | ||
|
Rejected reason: Not used
|
|||||
| CVE-2026-26252 | 2026-02-13 | N/A | N/A | ||
|
Rejected reason: Not used
|
|||||
| CVE-2026-26251 | 2026-02-13 | N/A | N/A | ||
|
Rejected reason: Not used
|
|||||
| CVE-2026-26250 | 2026-02-13 | N/A | N/A | ||
|
Rejected reason: Not used
|
|||||
| CVE-2026-26249 | 2026-02-13 | N/A | N/A | ||
|
Rejected reason: Not used
|
|||||
| CVE-2026-20663 | 1 Apple | 2 Ipados, Iphone Os | 2026-02-12 | N/A | 3.3 LOW |
|
The issue was resolved by sanitizing logging. This issue is fixed in iOS 26.3 and iPadOS 26.3, iOS 18.7.5 and iPadOS 18.7.5. An app may be able to enumerate a user's installed apps.
|
|||||
| CVE-2025-64074 | 2026-02-12 | N/A | 5.3 MEDIUM | ||
|
A path-traversal vulnerability in the logout functionality of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to delete arbitrary files on the host by supplying a crafted session cookie value.
|
|||||
| CVE-2026-20625 | 1 Apple | 2 Macos, Visionos | 2026-02-12 | N/A | 5.5 MEDIUM |
|
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.3, macOS Sonoma 14.8.4, visionOS 26.3. An app may be able to access sensitive user data.
|
|||||
| CVE-2026-20626 | 1 Apple | 4 Ipados, Iphone Os, Macos and 1 more | 2026-02-12 | N/A | 7.8 HIGH |
|
This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. A malicious app may be able to gain root privileges.
|
|||||
| CVE-2026-20630 | 1 Apple | 1 Macos | 2026-02-12 | N/A | 5.5 MEDIUM |
|
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.3. An app may be able to access protected user data.
|
|||||
| CVE-2026-20635 | 1 Apple | 7 Ipados, Iphone Os, Macos and 4 more | 2026-02-12 | N/A | 4.3 MEDIUM |
|
The issue was addressed with improved memory handling. This issue is fixed in watchOS 26.3, tvOS 26.3, macOS Tahoe 26.3, iOS 18.7.5 and iPadOS 18.7.5, visionOS 26.3, iOS 26.3 and iPadOS 26.3, Safari 26.3. Processing maliciously crafted web content may lead to an unexpected process crash.
|
|||||
| CVE-2026-20644 | 1 Apple | 5 Ipados, Iphone Os, Macos and 2 more | 2026-02-12 | N/A | 6.5 MEDIUM |
|
The issue was addressed with improved memory handling. This issue is fixed in macOS Tahoe 26.3, iOS 18.7.5 and iPadOS 18.7.5, visionOS 26.3, iOS 26.3 and iPadOS 26.3, Safari 26.3. Processing maliciously crafted web content may lead to an unexpected process crash.
|
|||||
| CVE-2020-0919 | 1 Microsoft | 1 Windows App | 2026-02-12 | 4.6 MEDIUM | 7.8 HIGH |
|
An elevation of privilege vulnerability exists in Remote Desktop App for Mac in the way it allows an attacker to load unsigned binaries, aka 'Microsoft Remote Desktop App for Mac Elevation of Privilege Vulnerability'.
|
|||||
| CVE-2026-1458 | 1 Gitlab | 1 Gitlab | 2026-02-12 | N/A | 6.5 MEDIUM |
|
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an unauthenticated user to cause denial of service by uploading malicious files.
|
|||||
| CVE-2026-1456 | 1 Gitlab | 1 Gitlab | 2026-02-12 | N/A | 6.5 MEDIUM |
|
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to cause denial of service through CPU exhaustion by submitting specially crafted markdown files that trigger exponential processing in markdown preview.
|
|||||
| CVE-2026-1080 | 1 Gitlab | 1 Gitlab | 2026-02-12 | N/A | 4.3 MEDIUM |
|
GitLab has remediated an issue in GitLab EE affecting all versions from 16.7 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to access iteration data from private descendant groups by querying the iterations API endpoint.
|
|||||