Common Vulnerabilities and Exposures (CVE)

CVE-2022-43551

Feb 13, 2026 19:43:56 UTC

A vulnerability exists in curl <7.87.0 HSTS check that could be bypassed to trick it to keep using HTTP. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provide...

CVE-2023-28322

Feb 13, 2026 19:43:18 UTC

An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has bee...

CVE-2026-20646

Feb 13, 2026 19:43:11 UTC

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.3. A malicious app may be able to read sensitive location information.

CVE-2026-20667

Feb 13, 2026 19:41:07 UTC

A logic issue was addressed with improved checks. This issue is fixed in watchOS 26.3, macOS Tahoe 26.3, macOS Sonoma 14.8.4, macOS Sequoia 15.7.4, iOS 26.3 and iPadOS 26.3. An app may be able to break out of its sandbox.

CVE-2025-29795

Feb 13, 2026 19:39:12 UTC

Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.

CVE-2025-24053

Feb 13, 2026 19:39:11 UTC

Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.

CVE-2025-30392

Feb 13, 2026 19:39:11 UTC

Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.

CVE-2025-26634

Feb 13, 2026 19:39:10 UTC

Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges over a network.

CVE-2025-26645

Feb 13, 2026 19:39:10 UTC

Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2025-26643

Feb 13, 2026 19:39:09 UTC

The UI performs the wrong action in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVE-2025-26633

Feb 13, 2026 19:39:08 UTC

Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.

CVE-2025-26631

Feb 13, 2026 19:39:08 UTC

Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally.

CVE-2025-26630

Feb 13, 2026 19:39:07 UTC

Use after free in Microsoft Office Access allows an unauthorized attacker to execute code locally.

CVE-2025-26629

Feb 13, 2026 19:39:07 UTC

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-26627

Feb 13, 2026 19:39:06 UTC

Improper neutralization of special elements used in a command ('command injection') in Azure Arc allows an authorized attacker to elevate privileges locally.