| CVE ID | Published | Description | Score | Severity | |
|---|---|---|---|---|---|
CVE-2026-2314 |
2026-02-11 19h15 +00:00 |
Heap buffer overflow in Codecs in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to ... |
8.8 |
High |
|
CVE-2026-25084 |
2026-02-11 17h16 +00:00 |
Authentication for ZLAN5143D can be bypassed by directly accessing internal URLs.... |
9.8 |
Critical |
|
CVE-2026-24789 |
2026-02-11 17h16 +00:00 |
An unprotected API endpoint allows an attacker to remotely change the device password without provid... |
9.8 |
Critical |
|
CVE-2025-64075 |
2026-02-11 16h15 +00:00 |
A path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2... |
10 |
Critical |
|
CVE-2026-2249 |
2026-02-11 15h16 +00:00 |
METIS DFS devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint... |
9.8 |
Critical |
|
CVE-2026-2248 |
2026-02-11 15h16 +00:00 |
METIS WIC devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint... |
9.8 |
Critical |
|
CVE-2026-0910 |
2026-02-11 14h16 +00:00 |
The wpForo Forum plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, a... |
8.8 |
High |
|
CVE-2025-8668 |
2026-02-11 14h16 +00:00 |
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab... |
9.4 |
Critical |
|
CVE-2025-8025 |
2026-02-11 13h15 +00:00 |
Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Busi... |
9.8 |
Critical |
|
CVE-2026-1560 |
2026-02-11 09h15 +00:00 |
The Custom Block Builder – Lazy Blocks plugin for WordPress is vulnerable to Remote Code Execution... |
8.8 |
High |