Vulnerabilities
Vulnerable Software
Security Vulnerabilities - Known exploited
CVE-2026-2441
Known exploited
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVSS Score
8.8
EPSS Score
0.22
Published
2026-02-13
CVE-2026-25108
Known exploited
FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command.
CVSS Score
8.7
EPSS Score
0.05
Published
2026-02-13
CVE-2026-20700
Known exploited
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 and CVE-2025-43529 were also issued in response to this report.
CVSS Score
7.8
EPSS Score
0.013
Published
2026-02-11
CVE-2026-21533
Known exploited
Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
CVSS Score
7.8
EPSS Score
0.038
Published
2026-02-10
CVE-2026-21519
Known exploited
Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVSS Score
7.8
EPSS Score
0.024
Published
2026-02-10
CVE-2026-21525
Known exploited
Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.
CVSS Score
6.2
EPSS Score
0.05
Published
2026-02-10
CVE-2026-21510
Known exploited
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
CVSS Score
8.8
EPSS Score
0.258
Published
2026-02-10
CVE-2026-21513
Known exploited
Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.
CVSS Score
8.8
EPSS Score
0.154
Published
2026-02-10
CVE-2026-21514
Known exploited
Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.
CVSS Score
7.8
EPSS Score
0.015
Published
2026-02-10
CVE-2026-1603
Known exploited
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.
CVSS Score
8.6
EPSS Score
0.806
Published
2026-02-10


Contact Us

Shodan ® - All rights reserved