Common Vulnerabilities and Exposures (CVE)

CVE-2025-70954

Feb 13, 2026 21:22:03 UTC

A Null Pointer Dereference vulnerability exists in the TON Virtual Machine (TVM) within the TON Blockchain before v2025.06. The issue is located in the execution logic of the INMSGPARAM instruction, where the program fails to validate if a ...

CVE-2025-70956

Feb 13, 2026 21:15:43 UTC

A State Pollution vulnerability was discovered in the TON Virtual Machine (TVM) before v2025.04. The issue exists in the RUNVM instruction logic (VmState::run_child_vm), which is responsible for initializing child virtual machines. The oper...

CVE-2026-26268

Feb 13, 2026 21:12:35 UTC

Cursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in versions prior to 2.5. A malicious agent (ie prompt injection) could write to improperly protected .git settings, including...

CVE-2025-1790

Feb 13, 2026 21:11:48 UTC

Local privilege escalation in Genetec Sipelia Plugin. An authenticated low-privileged Windows user could exploit this vulnerability to gain elevated privileges on the affected system.

CVE-2026-26269

Feb 13, 2026 21:11:26 UTC

Vim is an open source, command line text editor. Prior to 9.1.2148, a stack buffer overflow vulnerability exists in Vim's NetBeans integration when processing the specialKeys command, affecting Vim builds that enable and use the NetBeans fe...

CVE-2025-70093

Feb 13, 2026 21:04:14 UTC

An issue in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code via returning a crafted AJAX response.

CVE-2025-70121

Feb 13, 2026 21:00:54 UTC

An array index out of bounds vulnerability in the AMF component of free5GC v4.0.1 allows remote attackers to cause a denial of service via a crafted 5GS Mobile Identity in a NAS Registration Request message. The issue occurs in the GetSUCI ...

CVE-2025-70122

Feb 13, 2026 20:59:50 UTC

A heap buffer overflow vulnerability in the UPF component of free5GC v4.0.1 allows remote attackers to cause a denial of service via a crafted PFCP Session Modification Request. The issue occurs in the SDFFilterFields.UnmarshalBinary functi...

CVE-2025-70123

Feb 13, 2026 20:58:52 UTC

An improper input validation and protocol compliance vulnerability in free5GC v4.0.1 allows remote attackers to cause a denial of service. The UPF incorrectly accepts a malformed PFCP Association Setup Request, violating 3GPP TS 29.244. Thi...

CVE-2026-20616

Feb 13, 2026 20:55:28 UTC

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Tahoe 26.3, macOS Sonoma 14.8.4, visionOS 26.3. Processing a maliciously crafted USD file may lead to unexp...

CVE-2026-25828

Feb 13, 2026 20:54:07 UTC

grub-btrfs through 2026-01-31 (on Arch Linux and derivative distributions) allows initramfs OS command injection because it does not sanitize the $root parameter to resolve_device().

CVE-2025-60710

Feb 13, 2026 20:46:20 UTC

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.

CVE-2025-64657

Feb 13, 2026 20:46:20 UTC

Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a network.

CVE-2025-30398

Feb 13, 2026 20:46:19 UTC

Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network.

CVE-2025-62459

Feb 13, 2026 20:46:18 UTC

Microsoft Defender Portal Spoofing Vulnerability