VulnFeed
Showing 6183 of 6183 CVEs modified in the last 7 days
CVE-2026-62874
CRITICAL 10

Azure Billing Elevation of Privilege Vulnerability

CVE-2025-64121
CRITICAL 10

Nuvation Energy Multi-Stack Controller Authentication Bypass

CVE-2025-54322
CRITICAL 10

Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. The title and oIP parameters are also used.

CVE-2025-52691
CRITICAL 10

Upload Arbitrary Files

CVE-2025-36939
CRITICAL 10

Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread network could send specially crafted packets to cause a denial of service. These issues include triggerable assertion failures and a stack-based buffer overflow.

CVE-2025-15638
CRITICAL 10

Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt

CVE-2026-96658
CRITICAL 9.9

Foreman: safemode bypass leading to rce

CVE-2026-79798
CRITICAL 9.9

Authenticated SQL Injection Vulnerabilities in ClearPass Policy Manager Web-Based Management Interface

CVE-2026-33396
CRITICAL 9.9

OneUptime has sandbox escape in Synthetic Monitor Playwright runtime allows project members to execute arbitrary commands on Probe

CVE-2026-32306
CRITICAL 9.9

OneUptime ClickHouse SQL Injection via Aggregate Query Parameters

CVE-2026-30957
CRITICAL 9.9

OneUptime Synthetic Monitor RCE via exposed Playwright browser object

CVE-2026-30956
CRITICAL 9.9

OneUptime has authorization bypass via client‑controlled is-multi-tenant-query header

CVE-2025-68897
CRITICAL 9.9

WordPress IF AS Shortcode plugin <= 1.2 - Remote Code Execution (RCE) vulnerability

CVE-2025-68562
CRITICAL 9.9

WordPress MapSVG plugin <= 8.7.3 - Arbitrary File Upload vulnerability

CVE-2025-67924
CRITICAL 9.9

WordPress Corpkit theme <= 2.0 - Arbitrary File Upload vulnerability

CVE-2025-66203
CRITICAL 9.9

StreamVault is Vulnerable to Authenticated Remote Code Execution (RCE) via ytdlpargs Configuration Injection

CVE-2025-64420
CRITICAL 9.9

Coolify members can see private key of root user

CVE-2025-59157
CRITICAL 9.9

Coolify has Git Repository RCE

CVE-2025-31048
CRITICAL 9.9

WordPress Shopo <= 1.1.4 - Arbitrary File Upload Vulnerability

CVE-2026-106446
CRITICAL 9.8

Handlebars: JavaScript Injection via AST Type Confusion in compile (Program.blockParams)

CVE-2026-105192
CRITICAL 9.8

LMCache Unauthenticated RCE in multiprocess mode via pickle deserialization

CVE-2026-104334
CRITICAL 9.8

Langflow OSS is affected by multiple vulnerabilities

CVE-2026-102115
CRITICAL 9.8

Kiteworks Core Authentication Bypass in the Password Reset Workflow

CVE-2026-98365
CRITICAL 9.8

RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access

CVE-2026-98323
CRITICAL 9.8

RDMA/siw: Bound fragmented header copies by the remaining length

CVE-2026-93674
CRITICAL 9.8

Langflow OSS is affected by multiple vulnerabilities

CVE-2026-79805
CRITICAL 9.8

Authenticated Path Traversal Vulnerability Leads to Unauthorized File Access and Modification in ClearPass Policy Manager

CVE-2026-79801
CRITICAL 9.8

Unauthenticated Missing Integrity Verification allows Remote Code Execution in ClearPass Policy Manager Client Agent

CVE-2026-79796
CRITICAL 9.8

Authentication Bypass Vulnerabilities in ClearPass Policy Manager

CVE-2026-76754
CRITICAL 9.8

Unauthenticated SQL Injection Vulnerability leads to Remote Code Execution in ClearPass Policy Manager

CVE-2026-76753
CRITICAL 9.8

Unauthenticated Format String Vulnerability in HPE Networking ClearPass Policy Manager

CVE-2026-76752
CRITICAL 9.8

Authentication Bypass Vulnerabilities in HPE Networking ClearPass Policy Manager Allow Unauthorized Administrative Access

CVE-2026-76751
CRITICAL 9.8

Missing Integrity Verification in the OnGuard Agent of ClearPass Policy Manager Allows Unauthenticated Remote Code Execution

CVE-2026-76750
CRITICAL 9.8

Unauthenticated Deserialization of Untrusted Data allows Remote Code Execution in the Web Interface of HPE Networking ClearPass Policy Manager

CVE-2026-76744
CRITICAL 9.8

Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-S

CVE-2026-76743
CRITICAL 9.8

Authentication Bypass Vulnerability in the Management Interface of AOS-S

CVE-2026-76742
CRITICAL 9.8

Authentication Bypass in the Web Management Interface of AOS-S

CVE-2026-55330
CRITICAL 9.8

In BluetoothCccHandlerCallbackImpl of bluetooth_ccc.cc, there is a possible use-after-free due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2025-69258
CRITICAL 9.8

A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a key executable, leading to execution of attacker-supplied code under the context of SYSTEM on affected installations.

CVE-2025-67911
CRITICAL 9.8

WordPress Newsletters plugin <= 4.11 - PHP Object Injection vulnerability

CVE-2025-62877
CRITICAL 9.8

Harvest may expose OS default ssh login password via SUSE Virtualization Interactive Installer

CVE-2025-57460
CRITICAL 9.8

File upload vulnerability in machsol machpanel 8.0.32 allows attacker to gain a webshell.

CVE-2025-47552
CRITICAL 9.8

WordPress DZS Video Gallery plugin <= 12.37 - PHP Object Injection Vulnerability

CVE-2025-39477
CRITICAL 9.8

WordPress InWave Jobs Plugin <= 3.5.8 - Broken Access Control vulnerability

CVE-2025-23504
CRITICAL 9.8

WordPress Felan Framework plugin <= 1.1.3 - Account Takeover vulnerability

CVE-2025-15444
CRITICAL 9.8

Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium

CVE-2025-15385
CRITICAL 9.8

Insufficient Verification of Data Authenticity vulnerability in TECNO Mobile com.Afmobi.Boomplayer allows Authentication Bypass.This issue affects com.Afmobi.Boomplayer: 7.4.63.

CVE-2025-15029
CRITICAL 9.8

An unauthenticated user is able to introduce SQL Injection using the Awie export module

CVE-2025-15026
CRITICAL 9.8

Unauthenticated configuration import allows administrative account creation using AWIE component

CVE-2025-15018
CRITICAL 9.8

Optional Email <= 1.3.11 - Unauthenticated Privilege Escalation to Account Takeover

CVE-2025-15001
CRITICAL 9.8

FS Registration Password <= 1.0.1 - Unauthenticated Privilege Escalation via Account Takeover

CVE-2025-14996
CRITICAL 9.8

AS Password Field In Default Registration Form <= 2.0.0 - Unauthenticated Privilege Escalation via Account Takeover

CVE-2025-14320
CRITICAL 9.8

XSS in Tegsoft's Online Support Application

CVE-2025-13915
CRITICAL 9.8

Authentication bypass in IBM API Connect

CVE-2025-13618
CRITICAL 9.8

Mentoring <= 1.2.8 - Unauthenticated Privilege Escalation in mentoring_process_registration

CVE-2025-12686
CRITICAL 9.8

Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation OS before 1.3.2-65648 allows remote attackers to execute arbitrary code via unspecified vectors.

CVE-2025-11024
CRITICAL 9.8

SQLi in Akıllı Ticaret's E-Commerce Pack

CVE-2025-6577
CRITICAL 9.8

SQLi in Akilli Commerce's E-Commerce Website

CVE-2025-6254
CRITICAL 9.8

Doctreat Core <= 1.6.8 - Unauthenticated Privilege Escalation

CVE-2026-106501
CRITICAL 9.6

Backstage: Sensitive information exposure in Scaffolder

CVE-2026-106419
CRITICAL 9.6

Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106417
CRITICAL 9.6

Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-106414
CRITICAL 9.6

Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106401
CRITICAL 9.6

Out of bounds write in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106382
CRITICAL 9.6

Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-106375
CRITICAL 9.6

Incomplete cleanup in Dawn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106372
CRITICAL 9.6

Incorrect authorization in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106358
CRITICAL 9.6

Use after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-106329
CRITICAL 9.6

Incorrect authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106323
CRITICAL 9.6

Missing authorization in Chrome for iOS in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106298
CRITICAL 9.6

Use after free in Chrome Tabs in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106281
CRITICAL 9.6

Use after free in Tint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106241
CRITICAL 9.6

Incorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106239
CRITICAL 9.6

Integer overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106237
CRITICAL 9.6

Information leak in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-106234
CRITICAL 9.6

Use after free in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)

CVE-2026-106227
CRITICAL 9.6

Use after free in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106211
CRITICAL 9.6

Use after free in TabStrip in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106197
CRITICAL 9.6

Use after free in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-102322
CRITICAL 9.6

Incorrect Authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

CVE-2026-91140
CRITICAL 9.6

OS command injection in Progress Software Autonomous REST Connector GenAI Agents

CVE-2026-76745
CRITICAL 9.6

Unauthenticated Adjacent Memory Corruption Vulnerabilities Leading to Remote Code Execution in AOS-S

CVE-2026-65669
CRITICAL 9.6

Microsoft SQL Server Elevation of Privilege Vulnerability

CVE-2025-66398
CRITICAL 9.6

Signal K Server has Unauthenticated State Pollution leading to Remote Code Execution (RCE)

CVE-2025-64419
CRITICAL 9.6

Coolify vulnerable to command injection via docker-compose.yaml parameters

CVE-2025-15625
CRITICAL 9.5

Unauthenticated execution of arbitrary SQL queries in Sparx Pro Cloud Server

CVE-2026-102490
CRITICAL 9.4

Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha

CVE-2026-102489
CRITICAL 9.4

Undisclosed RCE in Zammad v6.3 and higher

CVE-2026-102162
CRITICAL 9.4

Security Advisory 0193

CVE-2026-102149
CRITICAL 9.4

Kiteworks Email Protection Gateway Improper Access Control

CVE-2025-64424
CRITICAL 9.4

Colify has command injection vulnerability in project git source

CVE-2025-64393
CRITICAL 9.4

This vulnerability in Veeam Backup & Replication allows a Backup Viewer to execute arbitrary code as SYSTEM on the backup server.

CVE-2025-64125
CRITICAL 9.4

Nuvation Energy nCloud Client-to-Client Communication

CVE-2025-64120
CRITICAL 9.4

Nuvation Energy Multi-Stack Controller OS Command Injection

CVE-2025-59158
CRITICAL 9.4

Coolify has Stored XSS in Project Name

CVE-2025-59156
CRITICAL 9.4

Coolify has Docker Compose Injection issue

CVE-2025-14942
CRITICAL 9.4

Authentication Bypass

CVE-2026-107104
CRITICAL 9.3

Unsafe Deserialization Vulnerability in Manacle Technologies ERP System

CVE-2026-107103
CRITICAL 9.3

SQL Injection Vulnerability in Manacle Technologies ERP System

CVE-2026-107102
CRITICAL 9.3

Account Takeover Vulnerability in Manacle Technologies ERP System

CVE-2026-103416
CRITICAL 9.3

Out-of-bounds write via the TLS 1.3 handshake message cache in NetX Duo in Eclipse ThreadX NetX Duo 6.5.1.202602 allows a handshake message larger than the cache writes past it and on into the rest of the session control block, which holds pointers. A malicious or compromised server can make a TLS 1.3 client produce such a message before certificate authentication completes, so no server certificate is needed to reach it.

CVE-2026-102782
CRITICAL 9.3

Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Simple Membership < 7.4.0

CVE-2026-102159
CRITICAL 9.3

Security Advisory 0190

CVE-2026-102147
CRITICAL 9.3

Kiteworks Core Administrative Account Takeover through Stored Cross-site Scripting (XSS)

CVE-2026-101158
CRITICAL 9.3

Security Advisory 0185

CVE-2026-101157
CRITICAL 9.3

Security Advisory 0192

CVE-2026-96408
CRITICAL 9.3

A code injection vulnerability exists in the upgrade script of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary Perl script or an SQL query on the affected product.

CVE-2026-76746
CRITICAL 9.3

Unauthenticated Adjacent Buffer Overflow Vulnerability Leading to Information Disclosure in AOS-S

CVE-2026-59346
CRITICAL 9.3

VMware Workstation and Fusion VMXNET3 integer-overflow vulnerability

CVE-2026-21589
CRITICAL 9.3

This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be some sensitive files that make this highly severe. This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions. The vulnerability must be addressed for affected versions of: -- Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1 -- Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19 -- Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.7, 7.2.4 -- Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12 -- Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12 -- Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12 -- Crucible, fix versions 4.9.15 -- Fisheye, fix version 4.9.15 -- Exploitation requires prior knowledge of the target file's exact name and path. The vulnerability does not include the capability to enumerate or list directory contents.

CVE-2026-19572
CRITICAL 9.3

FlexNet Publisher lmadmin SOAP Authentication Bypass Vulnerability

CVE-2026-19386
CRITICAL 9.3

A stack-based buffer overflow in the ASUS router modules allows an authenticated nearby user to execute arbitrary code via a crafted configuration file upload that exceeds the expected buffer size.Refer to the ' Security Update for ASUS Router Firmware  ' section on the ASUS Security Advisory for more information.

CVE-2026-18872
CRITICAL 9.3

IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

CVE-2026-14911
CRITICAL 9.3

Improper Neutralization of Input During Web Page Generation (“Cross-site Scripting”) in ASUS router modules allows a remote attacker to read DOM information, modify router settings, and cause a denial-of-service condition when an authenticated user visits a crafted URL.Refer to the ' Security Update for ASUS Router Firmware  ' section on the ASUS Security Advisory for more information.

CVE-2025-71318
CRITICAL 9.3

NetMan 204 Missing Authentication for Administrative Functions

CVE-2025-71317
CRITICAL 9.3

NetMan 204 Hard-coded Backdoor Credentials

CVE-2025-71284
CRITICAL 9.3

Synway SMG Gateway Management Software OS Command Injection via radius_address

CVE-2025-68865
CRITICAL 9.3

WordPress Infility Global plugin <= 2.15.06 - SQL Injection vulnerability

CVE-2025-67928
CRITICAL 9.3

WordPress Automotive Listings plugin <= 18.6 - SQL Injection vulnerability

CVE-2025-64119
CRITICAL 9.3

Nuvation Energy BMS Client-side Authentication

CVE-2025-41029
CRITICAL 9.3

SQL injection in Zeon Academy Pro by Zeon Global Tech

CVE-2025-39484
CRITICAL 9.3

WordPress Entrada Theme <= 5.7.7 - SQL Injection vulnerability

CVE-2025-32303
CRITICAL 9.3

WordPress WPCHURCH plugin <= 2.7.0 - SQL Injection Vulnerability

CVE-2025-30633
CRITICAL 9.3

WordPress Amazon Native Shopping Recommendations Plugin <= 1.3 - SQL Injection Vulnerability

CVE-2025-23993
CRITICAL 9.3

WordPress Felan Framework plugin <= 1.1.3 - SQL Injection vulnerability

CVE-2025-15624
CRITICAL 9.3

Plaintext Storage of a Password in Sparx Pro Cloud Server.

CVE-2025-15623
CRITICAL 9.3

Sparx Pro Cloud Server reveals sensitive information to an unauthenticated user

CVE-2025-15610
CRITICAL 9.3

The .NET Remoting framework used by OpenText Fax (RightFax) includes known security vulnerabilities that could be exploited if the service is exposed in environments where the remoting ports are accessible.

CVE-2025-15346
CRITICAL 9.3

wolfSSL Python library `CERT_REQUIRED` mode fails to enforce client certificate requirement

CVE-2025-15228
CRITICAL 9.3

WELLTEND TECHNOLOGY| BPMFlowWebkit - Arbitrary File Upload

CVE-2025-15226
CRITICAL 9.3

Sunnet|WMPro - Arbitrary File Upload

CVE-2025-14813
CRITICAL 9.3

GOSTCTR implementation unable to process more than 255 blocks correctly

CVE-2025-13926
CRITICAL 9.3

Contemporary Controls BASC 20T Reliance on Untrusted Inputs in a Security Decision

CVE-2025-13605
CRITICAL 9.3

Shell command injection in 3onedata GW1101-1D(RS-485)-TB-P modbus gateway

CVE-2025-13158
CRITICAL 9.3

apidoc-core - prototype pollution in api_group.js, api_param_title.js, api_use.js, and api_permission.js worker

CVE-2025-8769
CRITICAL 9.3

MegaSys Computer Technologies Telenium Online Web Application Improper Input Validation

CVE-2019-25471
CRITICAL 9.3

FileThingie 2.5.7 Arbitrary File Upload via ft2.php

CVE-2018-25223
CRITICAL 9.3

Crashmail 1.6 Stack-based Buffer Overflow Remote Code Execution

CVE-2026-107194
CRITICAL 9.2

Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via "login_type":"5" in a login request, potentially leading to "local blackouts on the whole continent" in Europe. An email address for the user_account property is required; however, a user can view the email address associated with their parent organization.

CVE-2026-107183
CRITICAL 9.2

llama.cpp before b11393 Use-After-Free via common_chat_peg_mapper chat_parser

CVE-2026-106445
CRITICAL 9.2

Handlebars: JavaScript Injection via Own Property Check Bypass

CVE-2026-105324
CRITICAL 9.2

An HTTP header injection vulnerability was found in the ADM

CVE-2025-68428
CRITICAL 9.2

jsPDF has Local File Inclusion/Path Traversal vulnerability

CVE-2025-40801
CRITICAL 9.2

A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), JT Bi-Directional Translator for STEP (All versions), NX V2412 (All versions < V2412.8900 with Cloud Entitlement (bundled as NX X)), NX V2506 (All versions < V2506.6000 with Cloud Entitlement (bundled as NX X)), Simcenter 3D (All versions < V2506.6000 with Cloud Entitlement (bundled as Simcenter X Mechanical)), Simcenter Femap (All versions < V2506.0002 with Cloud Entitlement (bundled as Simcenter X Mechanical)), Simcenter Studio (All versions < V2506.0001), Simcenter System Architect (All versions < V2506.0001), Tecnomatix Plant Simulation (All versions < V2504.0007). The SALT SDK is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-middle attack.

CVE-2025-13036
CRITICAL 9.2

Rockwell Automation FactoryTalk Historian Site Edition - Authentication Bypass

CVE-2026-103059
CRITICAL 9.1

Gitea built-in SSH server authentication bypass through key case folding

CVE-2026-96659
CRITICAL 9.1

Foreman: excessive permissions for viewer role on preview

CVE-2026-79794
CRITICAL 9.1

Authenticated SQL Injection Vulnerability in ClearPass Policy Manager Web-based Management Interface

CVE-2026-76747
CRITICAL 9.1

Unauthenticated Buffer Overflow Vulnerabilities lead to Information Disclosure in AOS-S

CVE-2026-51882
CRITICAL 9.1

The OpenAI-compatible file upload endpoint `/v1/files` in Langchain-Chatchat 0.3.0 is vulnerable to path traversal. An attacker can write files to arbitrary locations outside the `openai_files` directory by crafting malicious filenames.

CVE-2025-69234
CRITICAL 9.1

Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment.

CVE-2025-69222
CRITICAL 9.1

LibreChat is vulnerable to Server-Side Request Forgery due to missing restrictions

CVE-2025-68916
CRITICAL 9.1

Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload with resultant code execution.

CVE-2025-68637
CRITICAL 9.1

Apache Uniffle: Insecure SSL Configuration in Uniffle HTTP Client

CVE-2025-68620
CRITICAL 9.1

Signal K Server vulnerable to JWT Token Theft via WebSocket Enumeration and Unauthenticated Polling

CVE-2025-57735
CRITICAL 9.1

Apache Airflow: Airflow Logout Not Invalidating JWT

CVE-2025-41118
CRITICAL 9.1

Sensitive COS `SecretKey` exposed in plaintext via configuration API due to missing type protection

CVE-2025-40800
CRITICAL 9.1

A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), NX V2412 (All versions < V2412.8700), NX V2506 (All versions < V2506.6000), Simcenter 3D (All versions < V2506.6000), Simcenter Femap (All versions < V2506.0002), Solid Edge SE2025 (All versions < V225.0 Update 10), Solid Edge SE2026 (All versions < V226.0 Update 1). The IAM client in affected products is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-middle attack.

CVE-2025-15484
CRITICAL 9.1

Order Notification for WooCommerce < 3.6.3 - Unauthenticated WooCommerce REST Permission Bypass

CVE-2025-15359
CRITICAL 9.1

DVP-12SE11T - Out-of-bound memory write Vulnerability

CVE-2025-15102
CRITICAL 9.1

DVP-12SE11T - Password Protection Bypass

CVE-2025-13888
CRITICAL 9.1

Openshift-gitops-operator: openshift gitops: namespace admin cluster takeover via privileged jobs

CVE-2025-11159
CRITICAL 9.1

Hitachi Vantara Pentaho Data Integration & Analytics - Dependency on Vulnerable Third-Party Component

CVE-2025-8095
CRITICAL 9.1

Recoverable obfuscation using the OECH1 prefix encoding in OpenEdge

CVE-2026-102167
CRITICAL 9

Security Advisory 0197

CVE-2026-16516
CRITICAL 9

wolfSSH ECDSA host key curve not validated against negotiated algorithm

CVE-2025-59470
CRITICAL 9

This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.

CVE-2025-59469
CRITICAL 9

This vulnerability allows a Backup or Tape Operator to write files as root.

CVE-2025-59468
CRITICAL 9

This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter.

CVE-2026-106448
HIGH 8.9

StableLib: Prototype poisoning via `__proto__` map keys in CBOR decoding

CVE-2025-68920
HIGH 8.9

C-Kermit (aka ckermit) through 10.0 Beta.12 (aka 416-beta12) before 244644d allows a remote Kermit system to overwrite files on the local system, or retrieve arbitrary files from the local system.

CVE-2025-15471
HIGH 8.9

TRENDnet TEW-713RE formFSrvX os command injection

CVE-2025-15194
HIGH 8.9

D-Link DIR-600 HTTP Header hedwig.cgi stack-based overflow

CVE-2026-106558
HIGH 8.8

Backstage: Improper validation of TechDocs MkDocs configuration

CVE-2026-106423
HIGH 8.8

Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106421
HIGH 8.8

Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106411
HIGH 8.8

Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106383
HIGH 8.8

Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106374
HIGH 8.8

Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-106373
HIGH 8.8

Use after free in Fonts in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106371
HIGH 8.8

Incorrect authorization in Transactions Platform in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-106357
HIGH 8.8

Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106349
HIGH 8.8

Use after free in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106347
HIGH 8.8

Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-106346
HIGH 8.8

Improper state validation in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106335
HIGH 8.8

Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106318
HIGH 8.8

Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106315
HIGH 8.8

Use after free in Modularization in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106314
HIGH 8.8

Incorrect authorization in Bluetooth in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106309
HIGH 8.8

Incorrect authorization in Selection in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-106308
HIGH 8.8

Incorrect reference resolution in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106291
HIGH 8.8

Use after free in GarbageCollection in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106283
HIGH 8.8

Use after free in Streaming in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106278
HIGH 8.8

Use after free in Select in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106269
HIGH 8.8

Use after free in CSS in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-106268
HIGH 8.8

Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106257
HIGH 8.8

Use after free in HTML in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106256
HIGH 8.8

Information leak in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-106255
HIGH 8.8

Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106252
HIGH 8.8

Incorrect comparison in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-106249
HIGH 8.8

Incorrect authorization in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-106248
HIGH 8.8

Use after free in Bindings in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106240
HIGH 8.8

Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106235
HIGH 8.8

Use after free in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106218
HIGH 8.8

In JetBrains TeamCity before 2026.1.3 2025.11.7 kotlin DSL sandbox escape leading to RCE on the server was possible

CVE-2026-106207
HIGH 8.8

Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106204
HIGH 8.8

Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)

CVE-2026-106201
HIGH 8.8

Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106200
HIGH 8.8

Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106193
HIGH 8.8

Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106190
HIGH 8.8

Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-105812
HIGH 8.8

Code injection via unencoded configuration values during Python code generation in Bedrock AgentCore Starter Toolkit agent import

CVE-2026-104335
HIGH 8.8

Langflow OSS is affected by multiple vulnerabilities

CVE-2026-103668
HIGH 8.8

An SQL Injection vulnerability exists in the Site Search function of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary SQL query on the affected product.

CVE-2026-102406
HIGH 8.8

Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Tenant Data Interception

CVE-2026-102120
HIGH 8.8

Kiteworks Core OS Command Injection

CVE-2026-101207
HIGH 8.8

Dell OpenManage Integration with Microsoft Windows Admin Center, versions prior to 3.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

CVE-2026-98339
HIGH 8.8

wifi: cfg80211: don't filter by BSS type when removing stale entries

CVE-2026-98283
HIGH 8.8

KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()

CVE-2026-98282
HIGH 8.8

powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba

CVE-2026-98171
HIGH 8.8

smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs

CVE-2026-97679
HIGH 8.8

Langflow OSS is affected by multiple vulnerabilities

CVE-2026-97678
HIGH 8.8

Langflow OSS is affected by multiple vulnerabilities

CVE-2026-97676
HIGH 8.8

Langflow OSS is affected by multiple vulnerabilities

CVE-2026-97673
HIGH 8.8

Langflow OSS is affected by multiple vulnerabilities

CVE-2026-97655
HIGH 8.8

Langflow OSS is affected by multiple vulnerabilities

CVE-2026-97188
HIGH 8.8

String Locator < 2.6.8 - Unauthenticated PHP Object Injection via Database Editor

CVE-2026-93675
HIGH 8.8

Langflow OSS is affected by multiple vulnerabilities

CVE-2026-88962
HIGH 8.8

Langflow OSS is affected by multiple vulnerabilities

CVE-2026-87782
HIGH 8.8

Koinonia Link 1.1.2 - 1.1.4 - Subscriber+ Privilege Escalation to Administrator

CVE-2026-79803
HIGH 8.8

Authenticated Command Injection Leading to Privilege Escalation in ClearPass Policy Manager API

CVE-2026-79802
HIGH 8.8

Command Injection Vulnerability in the ClearPass Policy Manager Client Software

CVE-2026-79800
HIGH 8.8

Authenticated Path Traversal Vulnerability Leads to Remote Code Execution in ClearPass Policy Manager

CVE-2026-79799
HIGH 8.8

Unauthenticated Stored Cross-Site Scripting (XSS) Vulnerability in ClearPass Policy Manager Web-Based Management Interface

CVE-2026-79797
HIGH 8.8

Improper Access Control in HPE Networking ClearPass Android Client Application

CVE-2026-76748
HIGH 8.8

Authenticated Privilege Escalation Vulnerability in the API of AOS-S

CVE-2026-65772
HIGH 8.8

Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability

CVE-2026-58835
HIGH 8.8

In cfg2prop of btif_storage.cc, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2026-55280
HIGH 8.8

In multiple locations, there is a possible out-of-bounds write due to uninitialized data. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2026-45524
HIGH 8.8

In isSystem of WifiPermissionsUtil.java, there is a possible sandbox escape due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2026-18490
HIGH 8.8

IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

CVE-2026-15894
HIGH 8.8

Bluetooth Mesh solicitation PDU stack buffer overflow via oversized advertisement

CVE-2026-12405
HIGH 8.8

Rubygem-foreman_remote_execution: command injection in job invocations via effective_user parameter

CVE-2025-67915
HIGH 8.8

WordPress Timetics plugin <= 1.0.46 - Broken Authentication vulnerability

CVE-2025-67729
HIGH 8.8

lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()

CVE-2025-66738
HIGH 8.8

An issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a crafted request the ping function of the diagnostic component.

CVE-2025-66518
HIGH 8.8

Apache Kyuubi: Unauthorized directory access due to missing path normalization

CVE-2025-66001
HIGH 8.8

NeuVector OpenID Connect is vulnerable to man-in-the-middle (MITM)

CVE-2025-62624
HIGH 8.8

A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

CVE-2025-62623
HIGH 8.8

A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

CVE-2025-62549
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-62456
HIGH 8.8

Windows Resilient File System (ReFS) Remote Code Execution Vulnerability

CVE-2025-58074
HIGH 8.8

Privilege escalation during the installation of Norton Secure VPN via the Microsoft Store

CVE-2025-55204
HIGH 8.8

muffon has One-click Remote Code Execution via XSS and Custom URL Handling

CVE-2025-55061
HIGH 8.8

Priority - CWE-434 Unrestricted Upload of File with Dangerous Type

CVE-2025-53844
HIGH 8.8

A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11 allows attacker to execute unauthorized code or commands via specially crafted packets.

CVE-2025-47553
HIGH 8.8

WordPress DZS Video Gallery plugin <= 12.25 - PHP Object Injection vulnerability

CVE-2025-47392
HIGH 8.8

Integer Overflow or Wraparound in GPS

CVE-2025-43539
HIGH 8.8

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing a file may lead to memory corruption.

CVE-2025-43529
HIGH 8.8

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.

CVE-2025-36940
HIGH 8.8

Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation from Userspace to Kernel (AP)

CVE-2025-31951
HIGH 8.8

HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability

CVE-2025-31643
HIGH 8.8

WordPress WPCHURCH plugin <= 2.7.0 - Privilege Escalation Vulnerability

CVE-2025-31047
HIGH 8.8

WordPress Themify Edmin theme <= 2.0.0 - PHP Object Injection Vulnerability

CVE-2025-24284
HIGH 8.8

This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Sequoia 15.4. An app may be able to break out of its sandbox.

CVE-2025-15158
HIGH 8.8

WP Enable WebP <= 1.0 - Authenticated (Author+) Arbitrary File Upload

CVE-2025-15025
HIGH 8.8

IDOR in Yordam Informatics' Library Automation System

CVE-2025-15024
HIGH 8.8

RCE in Yordam Informatics' Library Automation System

CVE-2025-15023
HIGH 8.8

Improper Access Control in Yordam Informatics' Library Automation System

CVE-2025-14997
HIGH 8.8

BuddyPress Xprofile Custom Field Types <= 1.2.8 - Authenticated (Subscriber+) Arbitrary File Deletion

CVE-2025-14868
HIGH 8.8

Career Section <= 1.6 - Cross-Site Request Forgery to Arbitrary File Deletion

CVE-2025-14543
HIGH 8.8

Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows Serialized Data External Linking.

CVE-2025-12008
HIGH 8.8

IDOR in APPYAP's Yaay Social Media App

CVE-2025-2155
HIGH 8.8

Arbitrary File Upload in EchoCCS's Specto CM

CVE-2019-25580
HIGH 8.8

ownDMS 4.7 SQL Injection via pdfstream.php imagestream.php

CVE-2019-25578
HIGH 8.8

phpTransformer 2016.9 SQL Injection via GeneratePDF.php

CVE-2018-25197
HIGH 8.8

PlayJoom 0.10.1 SQL Injection via catid Parameter

CVE-2018-25196
HIGH 8.8

ServerZilla 1.0 SQL Injection via email Parameter

CVE-2018-25171
HIGH 8.8

EdTv 2 SQL Injection via id Parameter

CVE-2018-25163
HIGH 8.8

BitZoom 1.0 SQL Injection via rollno Parameter

CVE-2026-106447
HIGH 8.7

StableLib: Stack exhaustion denial of service via deeply nested CBOR arrays, maps, or tags

CVE-2026-106059
HIGH 8.7

GitAhead through 2.7.1 on macOS Command Injection via Show in Finder AppleScript

CVE-2026-105985
HIGH 8.7

Authenticated RCE via render-components Entry Type overrides

CVE-2026-102478
HIGH 8.7

In affected versions of Octopus Server, an authenticated user with permission to modify roles could bypass the protections preventing access abuse resulting in privilege escalation. It was possible for the built-in role to be weakened and the attacker's account added to a privileged team. This was achievable due to improper validation of unsafe equivalence in inputs.

CVE-2026-102163
HIGH 8.7

Security Advisory 0195

CVE-2026-102161
HIGH 8.7

Security Advisory 0190

CVE-2026-102100
HIGH 8.7

Kiteworks Core stored XSS

CVE-2026-102092
HIGH 8.7

Kiteworks Core stored XSS

CVE-2026-33226
HIGH 8.7

Budibase Unrestricted Server-Side Request Forgery (SSRF) via REST Datasource Query Preview

CVE-2026-33143
HIGH 8.7

OneUptime: WhatsApp Webhook Missing Signature Verification

CVE-2026-24480
HIGH 8.7

QGIS had validated RCE and Repository Takeover via GitHub Actions

CVE-2025-68421
HIGH 8.7

Hardcoded credentials in Comarch ERP Optima

CVE-2025-64421
HIGH 8.7

Coolify has a privilege escalation - low privileged user can invite themselves as an admin user

CVE-2025-64124
HIGH 8.7

Nuvation Energy Multi-Stack Controller OS Command Injection

CVE-2025-61939
HIGH 8.7

Columbia Weather Systems MicroServer Improper Restriction of Communication Channel to Intended Endpoints

CVE-2025-43876
HIGH 8.7

iSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, iSTAR Edge G2 - Authenticated web application command injection - get8021xSettings

CVE-2025-43875
HIGH 8.7

iSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, iSTAR Edge G2 - Authenticated web application command injection - getOptionsInfo

CVE-2025-40820
HIGH 8.7

Affected products do not properly enforce TCP sequence number validation in specific scenarios but accept values within a broad range. This could allow an unauthenticated remote attacker e.g. to interfere with connection setup, potentially leading to a denial of service. The attack succeeds only if an attacker can inject IP packets with spoofed addresses at precisely timed moments, and it affects only TCP-based services.

CVE-2025-40639
HIGH 8.7

SQL injection in Eventobot

CVE-2025-15240
HIGH 8.7

Quanta Computer|QOCA aim AI Medical Cloud Platform - Arbitrary File Upload

CVE-2025-15227
HIGH 8.7

WELLTEND TECHNOLOGY| BPMFlowWebkit - Arbitrary File Read

CVE-2025-15225
HIGH 8.7

Sunnet|WMPro - Arbitrary File Read

CVE-2025-11694
HIGH 8.7

Rockwell Automation CompactLogix 5370 Controllers – Multiple Vulnerabilities

CVE-2025-5088
HIGH 8.7

Arista CloudVision Exchange (CVX) Cluster Privilege Escalation via MCS Redis Session

CVE-2025-3232
HIGH 8.7

Mitsubishi Electric Europe smartRTU Missing Authentication for Critical Function

CVE-2018-25169
HIGH 8.7

AMPPS 2.7 Denial of Service via Malformed Socket Connection

CVE-2026-107181
HIGH 8.6

Telegram Desktop before 7.2.9 IPC Record Injection File Exfiltration via interpret: Scheme

CVE-2026-106186
HIGH 8.6

Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 155.0.8059.39 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Low)

CVE-2026-102160
HIGH 8.6

Security Advisory 0190

CVE-2026-101155
HIGH 8.6

Security Advisory 0189

CVE-2026-101154
HIGH 8.6

Security Advisory 0189

CVE-2026-27905
HIGH 8.6

BentoML has an Arbitrary File Write via Symlink Path Traversal in Tar Extraction

CVE-2025-71261
HIGH 8.6

Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS

CVE-2025-68459
HIGH 8.6

RG - AP180, Indoor Wall Plate Wireless AP AP180 series provided by Ruijie Networks Co., Ltd. contain an OS command injection vulnerability. An arbitrary OS command may be executed on the product by an attacker who logs in to the CLI service.

CVE-2025-68455
HIGH 8.6

Craft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior

CVE-2025-68044
HIGH 8.6

WordPress Five Star Restaurant Reservations plugin <= 2.7.4 - Insecure Direct Object References (IDOR) vulnerability

CVE-2025-66620
HIGH 8.6

Columbia Weather Systems MicroServer Command Shell in Externally Accessible Directory

CVE-2025-59887
HIGH 8.6

Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to the software package. This security issue has been fixed in the latest version of EUC which is available on the Eaton download center.

CVE-2025-30028
HIGH 8.6

A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files.

CVE-2025-15065
HIGH 8.6

Data Exposure in Kings Information & Network KESS Enterprise

CVE-2025-13417
HIGH 8.6

Plugin Organizer < 10.2.4 - Subscriber+ SQLi

CVE-2020-37082
HIGH 8.6

webERP 4.15.1 - Unauthenticated Backup File Access

CVE-2018-25225
HIGH 8.6

SIPP 3.3 Stack-Based Buffer Overflow via Configuration File

CVE-2018-25224
HIGH 8.6

PMS 0.42 Stack-Based Buffer Overflow via Configuration File

CVE-2018-25222
HIGH 8.6

SC v7.16 Stack-Based Buffer Overflow Remote Code Execution

CVE-2016-20048
HIGH 8.6

iSelect 1.4.0-2+b1 Local Buffer Overflow via key parameter

CVE-2016-20045
HIGH 8.6

HNB Organizer 1.9.18-10 Local Buffer Overflow via -rc Parameter

CVE-2016-20044
HIGH 8.6

PInfo 0.6.9-5.1 Local Buffer Overflow via -m Parameter

CVE-2026-106547
HIGH 8.5

HDF5 heap buffer overflow in H5VM_array_fill via crafted fill-value metadata

CVE-2026-106500
HIGH 8.5

Backstage: Improper task state validation in Scaffolder backend

CVE-2026-106486
HIGH 8.5

Backstage: Improper filesystem validation in Bitbucket pull-request scaffolder actions

CVE-2026-106459
HIGH 8.5

Backstage: Improper input validation in Sentry scaffolder actions

CVE-2026-106057
HIGH 8.5

patool before 4.0.6 OS Command Injection on Windows via shell_quote_nt

CVE-2026-93449
HIGH 8.5

Langflow OSS is affected by multiple vulnerabilities

CVE-2025-69414
HIGH 8.5

Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient access token.

CVE-2025-69351
HIGH 8.5

WordPress Ninja Tables plugin <= 5.2.4 - SQL Injection vulnerability

CVE-2025-68990
HIGH 8.5

WordPress BWL Pro Voting Manager plugin <= 1.4.9 - SQL Injection vulnerability

CVE-2025-68519
HIGH 8.5

WordPress Brands for WooCommerce plugin <= 3.8.6.3 - SQL Injection vulnerability

CVE-2025-67921
HIGH 8.5

WordPress Lobo theme < 2.8.6 - SQL Injection vulnerability

CVE-2025-64425
HIGH 8.5

Coolify has host header injection in forgot password

CVE-2025-63080
HIGH 8.5

Authenticated RCE in KAON PG5298

CVE-2025-48977
HIGH 8.5

Apache Ignite: REST HTTP arbitrary file read vulnerability

CVE-2025-34290
HIGH 8.5

Versa SASE Client for Windows < 7.9.5 Arbitrary Folder Deletion Leading to Local Privilege Escalation

CVE-2025-31044
HIGH 8.5

WordPress Premium SEO Pack <= 3.3.2 - SQL Injection Vulnerability

CVE-2025-22728
HIGH 8.5

WordPress Workreap (theme's plugin) plugin <= 3.3.6 - SQL Injection vulnerability

CVE-2025-22713
HIGH 8.5

WordPress WooCommerce Orders & Customers Exporter plugin <= 5.4 - SQL Injection vulnerability

CVE-2025-15068
HIGH 8.5

Account Takeover in Gmission Web FAX

CVE-2025-15067
HIGH 8.5

Unrestricted File Upload and RCE in Innorix WP

CVE-2025-14979
HIGH 8.5

Eddie VPN 2.24.6 - Local Privilege Escalation

CVE-2020-37020
HIGH 8.5

SonarQube 8.3.1 - Unquoted Service Path

CVE-2019-25261
HIGH 8.5

AnyDesk 5.4.0 - Unquoted Service Path

CVE-2026-16528
HIGH 8.4

Insertion of Sensitive Information into Log File in certain ASUS router models allows a remote authenticated attacker to obtain DDNS credentials from the system log, potentially enabling modification of DNS settings.Refer to the ' Security Update for ASUS Router Firmware  ' section on the ASUS Security Advisory for more information.

CVE-2025-67732
HIGH 8.4

Dify Vulnerable to Plaintext API Key Exposure via Model Provider Configuration Endpoint

CVE-2025-62554
HIGH 8.4

Microsoft Office Remote Code Execution Vulnerability

CVE-2025-47345
HIGH 8.4

Reusing a Nonce, Key Pair in Encryption in Automotive Platform

CVE-2025-15069
HIGH 8.4

Privilege Escalation in Gmission Web FAX

CVE-2025-13478
HIGH 8.4

Cache Misconfiguration Leading to Cross-User Data Exposure

CVE-2025-10238
HIGH 8.4

During an internal security assessment, a potential out-of-bounds write vulnerability was discovered in the BIOS of some ThinkPad products could allow a privileged local user to execute code in System Management Mode (SMM).

CVE-2025-10237
HIGH 8.4

During an internal security assessment, a potential vulnerability was discovered in some ThinkPad embedded controller firmware that could allow a privileged local user to perform arbitrary reads or writes to privileged memory regions.

CVE-2026-106426
HIGH 8.3

Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106412
HIGH 8.3

Race condition in Core in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106409
HIGH 8.3

Incorrect reference resolution in WebAppInstalls in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)

CVE-2026-106393
HIGH 8.3

Use after free in Storage in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106378
HIGH 8.3

Privilege elevation in Sandbox in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106377
HIGH 8.3

Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106293
HIGH 8.3

Type confusion in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106292
HIGH 8.3

Buffer overflow in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106247
HIGH 8.3

Buffer overflow in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-106238
HIGH 8.3

Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106233
HIGH 8.3

Use after free in Metrics in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106228
HIGH 8.3

Confused deputy in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106194
HIGH 8.3

Missing authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106191
HIGH 8.3

Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-97680
HIGH 8.3

Langflow OSS is affected by multiple vulnerabilities

CVE-2026-77214
HIGH 8.3

libexpat Heap Buffer Over-read in xmlparse.c via XML_ParseBuffer

CVE-2026-58069
HIGH 8.3

This vulnerability in Veeam Backup & Replication allows an authenticated Cloud Connect tenant to read arbitrary files on the service provider host.

CVE-2025-15617
HIGH 8.3

Wazuh GitHub Actions Workflow Exposure of Sensitive Credentials

CVE-2025-14272
HIGH 8.3

Rockwell Automation FactoryTalk Analytics PavilionX

CVE-2026-94114
HIGH 8.2

Apache Commons BCEL: Nested Code/Record attributes drive unbounded parse-time recursion in ClassParser

CVE-2026-82211
HIGH 8.2

Nexi XPay Build <= 7.6.2 - Unauthenticated Payment Completion and Order Key Disclosure

CVE-2026-19179
HIGH 8.2

IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

CVE-2026-12541
HIGH 8.2

Foreman: command injection in foreman-rake database tasks

CVE-2026-12540
HIGH 8.2

Foreman: command injection in foreman-rake errors:fetch_log via request_id parameter

CVE-2025-59683
HIGH 8.2

Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange Tokens. This allows a remote attacker to read potentially sensitive data and excessively consume resources, leading to a denial of service.

CVE-2025-14523
HIGH 8.2

Libsoup: libsoup: duplicate host header handling causes host-parsing discrepancy (first- vs last-value wins)

CVE-2025-11774
HIGH 8.2

Malicious Code Execution Vulnerability in the Software Keyboard Function of GENESIS64, ICONICS Suite, Mobile HMI, and MC Works64

CVE-2025-7389
HIGH 8.2

Unauthorized Arbitrary File Read via RMI in AdminServer Interface

CVE-2026-106503
HIGH 8.1

Backstage: Scaffolder action input authorization bypass

CVE-2026-106488
HIGH 8.1

Backstage: Improper authentication in the OIDC provider

CVE-2026-106471
HIGH 8.1

Candlepin: candlepin: broken object-level authorization via verifyauthorizationfilter multi-@verify hasaccess latching

CVE-2026-103360
HIGH 8.1

Langflow OSS is affected by multiple vulnerabilities

CVE-2026-102126
HIGH 8.1

Kiteworks Core Stored Cross-site Scripting (XSS)

CVE-2026-102101
HIGH 8.1

Kiteworks Core deserialization of untrusted data

CVE-2026-98357
HIGH 8.1

IB/isert: wait for deferred control PDU completions before releasing the connection

CVE-2026-98261
HIGH 8.1

cifs: Fix server use-after-free in cifs_chan_skip_or_disable()

CVE-2026-98239
HIGH 8.1

net: lan743x: fix RX checksum use-after-free

CVE-2026-97674
HIGH 8.1

Langflow OSS is affected by multiple vulnerabilities

CVE-2026-96404
HIGH 8.1

Gitea installer authentication bypass for existing accounts

CVE-2026-93445
HIGH 8.1

Langflow OSS is affected by multiple vulnerabilities

CVE-2026-59347
HIGH 8.1

VMware Workstation and Fusion HGFS stack-based buffer-overflow vulnerability

CVE-2026-33142
HIGH 8.1

OneUptime: ClickHouse SQL Injection via unvalidated column identifiers in sort, select, and groupBy parameters

CVE-2026-19186
HIGH 8.1

Integer underflow in IEEE 802.15.4 frame decryption leads to out-of-bounds read and write

CVE-2026-18181
HIGH 8.1

IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

CVE-2026-18137
HIGH 8.1

IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

CVE-2025-69201
HIGH 8.1

Tugtainer has RCE in Agent Command Execution Api

CVE-2025-69087
HIGH 8.1

WordPress FreeAgent theme <= 2.1.2 - Local File Inclusion vulnerability

CVE-2025-69086
HIGH 8.1

WordPress Issabella theme <= 1.1.2 - Local File Inclusion vulnerability

CVE-2025-69083
HIGH 8.1

WordPress Frappé theme <= 1.8 - Local File Inclusion vulnerability

CVE-2025-69081
HIGH 8.1

WordPress Hope theme <= 3.0.0 - Local File Inclusion vulnerability

CVE-2025-69080
HIGH 8.1

WordPress Gecko theme <= 1.9.8 - Local File Inclusion vulnerability

CVE-2025-69034
HIGH 8.1

WordPress Lekker theme <= 1.8 - Local File Inclusion vulnerability

CVE-2025-68506
HIGH 8.1

WordPress Docket Cache plugin <= 24.07.03 - Local File Inclusion vulnerability

CVE-2025-67937
HIGH 8.1

WordPress Hendon theme < 1.7 - Local File Inclusion vulnerability

CVE-2025-67936
HIGH 8.1

WordPress Curly theme < 3.3 - Local File Inclusion vulnerability

CVE-2025-67935
HIGH 8.1

WordPress Optimize theme < 2.4 - Local File Inclusion vulnerability

CVE-2025-67934
HIGH 8.1

WordPress Wellspring theme < 2.8 - Local File Inclusion vulnerability

CVE-2025-67920
HIGH 8.1

WordPress Neo Ocular theme < 1.2 - Local File Inclusion vulnerability

CVE-2025-66172
HIGH 8.1

Apache CloudStack: Any user can attach a volume in their VMs from backups they should not have access to

CVE-2025-58913
HIGH 8.1

WordPress VideoPro theme <= 2.3.8.1 - Local File Inclusion vulnerability

CVE-2025-54550
HIGH 8.1

Apache Airflow: RCE by race condition in example_xcom dag

CVE-2025-48769
HIGH 8.1

Apache NuttX RTOS: fs/vfs/fs_rename: use after free

CVE-2025-47411
HIGH 8.1

Apache StreamPipes: Leverage of User ID for Privilege Escalation

CVE-2025-45871
HIGH 8.1

LogicalDOC Enterprise up to and for 9.1.1 is vulnerable to blind SQL injection in the WorkflowsDataServlet component, allowing authenticated user to manipulate SQL queries via crafted workflow template name.

CVE-2025-32304
HIGH 8.1

WordPress WPCHURCH plugin <= 2.7.0 - Local File Inclusion vulnerability

CVE-2025-22712
HIGH 8.1

WordPress Typify theme <= 3.0.2 - Local File Inclusion vulnerability

CVE-2025-22708
HIGH 8.1

WordPress Mitech theme <= 2.3.4 - Local File Inclusion vulnerability

CVE-2025-22707
HIGH 8.1

WordPress Moody theme <= 2.7.3 - Local File Inclusion vulnerability

CVE-2025-22509
HIGH 8.1

WordPress Atlas theme <= 2.1.0 - Local File Inclusion vulnerability

CVE-2025-15103
HIGH 8.1

DVP-12SE11T - Authentication Bypass via Partial Password Disclosure

CVE-2025-14432
HIGH 8.1

Poly Video - Sensitive Data Might Be Written to Log File

CVE-2025-13392
HIGH 8.1

Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected) allows remote attackers to bypass authentication with prior knowledge of the distinguished name (DN).

CVE-2025-66467
HIGH 8

Apache CloudStack: MinIO policy remains intact on bucket deletion

CVE-2025-48640
HIGH 8

In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2025-24818
HIGH 8

An OS Command Injection vulnerability in Nokia MantaRay NM

CVE-2025-24817
HIGH 8

An OS Command Injection vulnerability in Nokia MantaRay NM

CVE-2025-65104
HIGH 7.9

Firebird: Information leak vulnerability in firebird3 client when used with newer server

CVE-2025-64123
HIGH 7.9

Nuvation Energy Multi-Stack Controller Proxy service allows arbitrary BMS access

CVE-2026-106442
HIGH 7.8

Hydra instantiate target blacklist bypasses permit code execution

CVE-2026-106062
HIGH 7.8

Gimp: gimp: heap buffer overflow in dds loader on crafted directdraw surface file

CVE-2026-102256
HIGH 7.8

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 appliance which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

CVE-2026-102118
HIGH 7.8

Kiteworks Core before version 9.5.0 is vulnerable to Local Privilege Escalation

CVE-2026-102113
HIGH 7.8

Kiteworks Core Local Privilege Escalation

CVE-2026-102112
HIGH 7.8

Kiteworks Core Local Privilege Escalation

CVE-2026-101258
HIGH 7.8

Ghostscript: ghostscript: -dsafer sandbox bypass via type 5 shading oob write and procedure-stream use-after-free

CVE-2026-98369
HIGH 7.8

xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject()

CVE-2026-98368
HIGH 7.8

esp: downgrade zerocopy managed frags before mutating skb frags

CVE-2026-98367
HIGH 7.8

RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept

CVE-2026-98366
HIGH 7.8

RDMA/rxe: validate access flags before swapping the MR's PD

CVE-2026-98364
HIGH 7.8

xfrm: hold net_device reference under RCU in bundle creation

CVE-2026-98361
HIGH 7.8

RDMA/rxe: Restore HMM_PFN_WRITE check in ODP write paths

CVE-2026-98341
HIGH 7.8

wifi: cfg80211: don't free driver-owned scan requests

CVE-2026-98324
HIGH 7.8

dmaengine: pxa: fix double counting of the hw descriptors

CVE-2026-98320
HIGH 7.8

netfilter: flowtable: hold reference on ct until flow is released

CVE-2026-98318
HIGH 7.8

smb: client: validate absolute native symlink targets before NT fixups

CVE-2026-98315
HIGH 7.8

ntfs: protect runlist updates with the runlist lock

CVE-2026-98311
HIGH 7.8

wifi: virt_wifi: don't transfer operstate before register

CVE-2026-98305
HIGH 7.8

net: dsa: mxl862xx: disable the stats poll on teardown

CVE-2026-98281
HIGH 7.8

futex: Also allocate private hash on vfork()

CVE-2026-98276
HIGH 7.8

net: lock the socket in sock_gettstamp()

CVE-2026-98260
HIGH 7.8

exec: Cleanup POSIX timers right after de_thread()

CVE-2026-98258
HIGH 7.8

posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list

CVE-2026-98256
HIGH 7.8

signal: Prevent exec() race

CVE-2026-98254
HIGH 7.8

swiotlb: use the adjusted address for the highmem page lookup

CVE-2026-98253
HIGH 7.8

RDMA/ucma: Serialize join and leave on copy_to_user failure

CVE-2026-98251
HIGH 7.8

openvswitch: avoid reallocating confirmed conntrack labels

CVE-2026-98241
HIGH 7.8

ipv6: xfrm: use full sockets in local error paths

CVE-2026-98229
HIGH 7.8

xfrm: save input state data before secpath resets

CVE-2026-98228
HIGH 7.8

mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ

CVE-2026-98166
HIGH 7.8

drm/ttm: fix swapped-out resources never leaving their bulk_move range

CVE-2026-98163
HIGH 7.8

cgroup: Avoid iteration of dying tasks with zero refcount

CVE-2026-79808
HIGH 7.8

Local Authenticated Buffer Overflow Vulnerability in the ClearPass Policy Manager OnGuard Agent

CVE-2026-79807
HIGH 7.8

Authenticated Local Missing Integrity Verification Vulnerability leads to Local Privilege Escalation in the ClearPass Policy Manager Windows Client Software

CVE-2026-79806
HIGH 7.8

Authenticated Local Privilege Escalation in ClearPass Policy Manager OnGuard Linux Agent

CVE-2026-65142
HIGH 7.8

NVIDIA Model-Optimizer contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.

CVE-2026-58859
HIGH 7.8

In multiple places, there is a possible denial of service due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2026-58854
HIGH 7.8

In multiple locations, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2026-58841
HIGH 7.8

In multiple functions of VirtualAudioControllerTest.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2026-58815
HIGH 7.8

In multiple locations, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2026-55286
HIGH 7.8

In stpropnci_process of stpropnci.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2026-55270
HIGH 7.8

In dialInternal in multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2026-55269
HIGH 7.8

In FilterCapturedPacket of snoop_logger.cc, there is a possible memory safety issue due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2026-55266
HIGH 7.8

In qsort of libufdt_sysdeps_vendor.c, there is a possible out-of-bounds write due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2026-49937
HIGH 7.8

In multiple functions of MessageQueueBase.h, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2026-49933
HIGH 7.8

In handle_le_monitor_device_event of msft.cc, there is a possible control-flow hijack in the privileged bluetooth process due to an uninitialized pointer dereference. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2026-49885
HIGH 7.8

In rw_t4t_update_file of rw_t4t.cc, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2026-49880
HIGH 7.8

In multiple functions of nfa_nfcee_act.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2026-33744
HIGH 7.8

BentoML has Dockerfile Command Injection via system_packages in bentofile.yaml

CVE-2026-28648
HIGH 7.8

In Settings, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2026-28647
HIGH 7.8

In updateState of DeviceAdminAppsPreferenceController.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2026-28641
HIGH 7.8

In shouldDisableUninstallButton of ApplicationActionButtonsPreferenceController.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2026-28640
HIGH 7.8

In checkCallerIsCertInstallerOrSelfInProfile of CredentialStorageActivity.java, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2026-28625
HIGH 7.8

In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2026-25267
HIGH 7.8

Missing Authorization in Core

CVE-2025-67450
HIGH 7.8

Due to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the software package could perform arbitrary code execution . This security issue has been fixed in the latest version of EUC which is available on the Eaton download center.

CVE-2025-62552
HIGH 7.8

Microsoft Access Remote Code Execution Vulnerability

CVE-2025-62474
HIGH 7.8

Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

CVE-2025-62472
HIGH 7.8

Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

CVE-2025-62470
HIGH 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2025-62467
HIGH 7.8

Windows Projected File System Elevation of Privilege Vulnerability

CVE-2025-62466
HIGH 7.8

Windows Client-Side Caching Elevation of Privilege Vulnerability

CVE-2025-62464
HIGH 7.8

Windows Projected File System Elevation of Privilege Vulnerability

CVE-2025-62462
HIGH 7.8

Windows Projected File System Elevation of Privilege Vulnerability

CVE-2025-62461
HIGH 7.8

Windows Projected File System Elevation of Privilege Vulnerability

CVE-2025-62458
HIGH 7.8

Win32k Elevation of Privilege Vulnerability

CVE-2025-62457
HIGH 7.8

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2025-59517
HIGH 7.8

Windows Storage VSP Driver Elevation of Privilege Vulnerability

CVE-2025-59516
HIGH 7.8

Windows Storage VSP Driver Elevation of Privilege Vulnerability

CVE-2025-55233
HIGH 7.8

Windows Projected File System Elevation of Privilege Vulnerability

CVE-2025-55125
HIGH 7.8

This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file.

CVE-2025-54100
HIGH 7.8

PowerShell Remote Code Execution Vulnerability

CVE-2025-48643
HIGH 7.8

In multiple locations there is a possible provisioning bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2025-48617
HIGH 7.8

In overrideConfig of CarrierConfigLoader.java, there is a possible way to bypass UID check due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2025-47408
HIGH 7.8

Untrusted Pointer Dereference in Power Optimization Firmware

CVE-2025-47407
HIGH 7.8

Time-of-check Time-of-use (TOCTOU) Race Condition in DSP Service

CVE-2025-47405
HIGH 7.8

Untrusted Pointer Dereference in Camera

CVE-2025-47396
HIGH 7.8

Double Free in Graphics

CVE-2025-47394
HIGH 7.8

Buffer Copy Without Checking Size of Input in DSP Service

CVE-2025-47393
HIGH 7.8

Improper Validation of Array Index in Automotive Linux OS

CVE-2025-47391
HIGH 7.8

Stack-based Buffer Overflow in Camera Driver

CVE-2025-47390
HIGH 7.8

Buffer Over-read in Camera

CVE-2025-47389
HIGH 7.8

Buffer Copy Without Checking Size of Input in Automotive Platform

CVE-2025-47388
HIGH 7.8

Buffer Copy without Checking Size of Input in DSP Service

CVE-2025-47380
HIGH 7.8

Untrusted Pointer Dereference in Camera

CVE-2025-47356
HIGH 7.8

Double Free in Video

CVE-2025-47348
HIGH 7.8

Use of Uninitialized Variable in HLOS

CVE-2025-47346
HIGH 7.8

Out-of-bounds Write in HLOS

CVE-2025-47343
HIGH 7.8

Untrusted Pointer Dereference in Video

CVE-2025-47339
HIGH 7.8

Use After Free in HLOS

CVE-2025-46285
HIGH 7.8

An integer overflow was addressed by adopting 64-bit timestamps. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. An app may be able to gain root privileges.

CVE-2025-43510
HIGH 7.8

A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may cause unexpected changes in memory shared between processes.

CVE-2025-36568
HIGH 7.8

Dell PowerProtect Data Domain BoostFS for client of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain an insufficiently protected credentials vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to credential exposure. The attacker may be able to use the exposed credentials to access the system with privileges of the compromised account.

CVE-2025-31272
HIGH 7.8

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to bypass launch constraint protections and execute malicious code with elevated privileges.

CVE-2025-20800
HIGH 7.8

In mminfra, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10267349; Issue ID: MSV-5033.

CVE-2025-20799
HIGH 7.8

In c2ps, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10274607; Issue ID: MSV-5049.

CVE-2025-20798
HIGH 7.8

In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10315812; Issue ID: MSV-5533.

CVE-2025-20797
HIGH 7.8

In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10315812; Issue ID: MSV-5534.

CVE-2025-20796
HIGH 7.8

In imgsys, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS10314745; Issue ID: MSV-5553.

CVE-2025-20795
HIGH 7.8

In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10276761; Issue ID: MSV-5141.

CVE-2025-20781
HIGH 7.8

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10182914; Issue ID: MSV-4699.

CVE-2025-20780
HIGH 7.8

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10184061; Issue ID: MSV-4712.

CVE-2025-20778
HIGH 7.8

In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10184870; Issue ID: MSV-4729.

CVE-2025-12771
HIGH 7.8

IBM Concert Software Improper Restriction of Operations within the Bounds of a Memory Buffer.

CVE-2025-7017
HIGH 7.8

Avira antivirus engine heap buffer OOB read when scanning a malformed Windows MSI file

CVE-2025-7011
HIGH 7.8

Avast antivirus heap OOB when scanning a malformed zip file

CVE-2025-7009
HIGH 7.8

Avast antivirus heap buffer OOB read when scanning a malformed PE file

CVE-2025-7008
HIGH 7.8

Avast antivirus heap buffer OOB read when scanning a malformed PE file

CVE-2025-7004
HIGH 7.8

Avast antivirus heap buffer OOB write when scanning a malformed PE file

CVE-2025-7003
HIGH 7.8

Avira antivirus engine heap buffer OOB read when scanning a malformed PDF file (variant 1)

CVE-2025-7002
HIGH 7.8

Avira antivirus engine heap buffer OOB read when scanning a malformed PDF file (variant 2)

CVE-2025-6020
HIGH 7.8

Linux-pam: linux-pam directory traversal

CVE-2025-5914
HIGH 7.8

Libarchive: double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c

CVE-2024-26507
HIGH 7.8

An issue in FinalWire AIRDA Extreme, AIDA64 Engineer, AIDA64 Business, AIDA64 Network Audit through 7.00.6742 allows a local attacker to escalate privileges via the DeviceIoControl call associated with MmMapIoSpace, IoAllocateMdl, MmBuildMdlForNonPagedPool, or MmMapLockedPages components.

CVE-2026-106556
HIGH 7.7

Backstage: Configuration bypass in TechDocs mkdocs.yml sanitization

CVE-2026-106510
HIGH 7.7

Backstage: Remote code execution via crafted markdown_extensions in TechDocs mkdocs.yml

CVE-2026-106509
HIGH 7.7

Backstage: Improper validation of MkDocs theme configuration in TechDocs

CVE-2026-106505
HIGH 7.7

Backstage: Bypass of MkDocs configuration sanitizer in TechDocs backend

CVE-2026-106498
HIGH 7.7

Backstage: Improper URL validation in catalog entity placeholder resolution

CVE-2026-106455
HIGH 7.7

Backstage: Improper validation of MkDocs plugin configuration in TechDocs

CVE-2026-106058
HIGH 7.7

GitAhead through 2.7.1 OS Command Injection via Git Filter Filenames

CVE-2026-106056
HIGH 7.7

Rundeck before 6.2.0 OS Command Injection via Windows Job Option Quoting

CVE-2026-103435
HIGH 7.7

Arbitrary File Write via Write-Time Symlink Following (TOCTOU) in Claude Code

CVE-2026-102165
HIGH 7.7

Security Advisory 0198

CVE-2026-101331
HIGH 7.7

Langflow OSS is affected by multiple vulnerabilities

CVE-2026-101027
HIGH 7.7

Gitea migration SSRF through ALLOWED_DOMAINS address check bypass

CVE-2026-93677
HIGH 7.7

Langflow OSS is affected by multiple vulnerabilities

CVE-2026-83540
HIGH 7.7

wolfSSHd on Windows race condition leading to logon token reused across connections

CVE-2026-43598
HIGH 7.7

Improper input validation in the AMD ROCm Communication Collectives Library (RCCL) could allow a compromised peer rank or network-adjacent attacker to dereference an attacker-controlled pointer, potentially resulting in remote code execution.

CVE-2026-33530
HIGH 7.7

InvenTree Vulnerable to ORM Filter Injection

CVE-2026-19396
HIGH 7.7

A predictable seed in the pseudo-random number generator (PRNG) in the IFTTT pairing token generation of the ASUS RT-BE57 router allows an unauthenticated nearby user to derive the pairing token and read or modify router settings via observed values from an administrator-initiated IFTTT pairing session.Refer to the ' Security Update for ASUS Router Firmware  ' section on the ASUS Security Advisory for more information.

CVE-2026-12544
HIGH 7.7

Foreman: ssti and insecure deserialization in foreman-rake configuration

CVE-2025-67914
HIGH 7.7

WordPress VidMov theme <= 2.3.8 - Path Traversal vulnerability

CVE-2025-64645
HIGH 7.7

Multiple Vulnerabilities in IBM Concert Software.

CVE-2025-64423
HIGH 7.7

Coolify has a Privilege Escalation - low privileged users can see and use admin invitation links

CVE-2025-14804
HIGH 7.7

Frontend File Manager < 23.5 - Subscriber+ Arbitrary File Deletion

CVE-2025-5591
HIGH 7.7

Stored Cross-site Scripting (XSS) in Kentico Xperience 13

CVE-2026-107162
HIGH 7.6

Express Gateway through 1.16.11 OAuth 2.0 Refresh Token Validation Bypass

CVE-2026-106492
HIGH 7.6

Backstage: Improper preservation of access restrictions during service credential delegation

CVE-2026-101152
HIGH 7.6

Security Advisory 0187

CVE-2026-93678
HIGH 7.6

Langflow OSS is affected by multiple vulnerabilities

CVE-2026-42721
HIGH 7.6

WordPress affiliate-toolkit plugin <= 3.9.1 - SQL Injection vulnerability

CVE-2026-42720
HIGH 7.6

WordPress Dynamic User Directory plugin <= 2.4 - SQL Injection vulnerability

CVE-2026-42714
HIGH 7.6

WordPress Pix por Piggly (para Woocommerce) plugin <= 2.1.2 - SQL Injection vulnerability

CVE-2026-42713
HIGH 7.6

WordPress Post title marquee scroll plugin <= 9.9 - SQL Injection vulnerability

CVE-2026-42710
HIGH 7.6

WordPress Slider by 10Web plugin <= 1.2.63 - SQL Injection vulnerability

CVE-2026-42708
HIGH 7.6

WordPress WP Post Author plugin <= 4.0.0 - SQL Injection vulnerability

CVE-2026-32308
HIGH 7.6

OneUptime: Stored XSS via Mermaid Diagram Rendering (securityLevel: "loose")

CVE-2025-68590
HIGH 7.6

WordPress Integration for Contact Form 7 HubSpot plugin <= 1.4.2 - SQL Injection vulnerability

CVE-2025-68496
HIGH 7.6

WordPress User Feedback plugin <= 1.10.0 - SQL Injection vulnerability

CVE-2025-68060
HIGH 7.6

WordPress Team Member plugin <= 8.5 - SQL Injection vulnerability

CVE-2025-63029
HIGH 7.6

WordPress WCFM Marketplace plugin <= 3.7.1 - SQL Injection vulnerability

CVE-2025-36589
HIGH 7.6

Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to data and resources outside of the intended sphere of control.

CVE-2025-2406
HIGH 7.6

XSS in Verisay Communication's Trizbi

CVE-2025-2405
HIGH 7.6

XSS in Verisay Communication's Titarus

CVE-2025-2307
HIGH 7.6

XSS in Verisay Communication's Aidango

CVE-2026-98290
HIGH 7.5

Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup

CVE-2026-98257
HIGH 7.5

rds: ib: use rds_conn_drop() on protocol version mismatch

CVE-2026-98175
HIGH 7.5

smb: client: cancel reconnect work in clean_demultiplex_info()

CVE-2026-98174
HIGH 7.5

smb: client: fix rlist race and missing initialization

CVE-2026-98173
HIGH 7.5

smb: client: fix use-after-free of iface in cifs_try_adding_channels()

CVE-2026-93447
HIGH 7.5

Langflow OSS is affected by multiple vulnerabilities

CVE-2026-93443
HIGH 7.5

Langflow OSS is affected by multiple vulnerabilities

CVE-2026-92532
HIGH 7.5

Unrestricted Upload of File with Dangerous Type in BugTracker.NET

CVE-2026-92531
HIGH 7.5

Improper Neutralization of Special Elements used in an OS Command in BugTracker.NET

CVE-2026-82212
HIGH 7.5

Nexi XPay Build <= 7.6.2 - Unauthenticated Payment Bypass via NPG Notification Handler

CVE-2026-58865
HIGH 7.5

In multiple functions of PduParser.java, there is a possible persistent denial of service due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2026-49329
HIGH 7.5

Openshift/oauth-server: openshift/oauth-server: quadratic-time dos via accept-language header underscore bypass on unauthenticated login endpoints

CVE-2026-42638
HIGH 7.5

WordPress Easy Digital Downloads plugin <= 3.7.1 - Broken Access Control vulnerability

CVE-2026-12423
HIGH 7.5

Foreman: unauthenticated information disclosure via provisioning token validation flaw

CVE-2025-69356
HIGH 7.5

WordPress TheGem Theme Elements (for Elementor) plugin <= 5.11.0 - Local File Inclusion vulnerability

CVE-2025-69342
HIGH 7.5

WordPress Calafate theme <= 1.7.7 - Local File Inclusion vulnerability

CVE-2025-69260
HIGH 7.5

A message out-of-bounds read vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-of-service condition on affected installations. Please note: authentication is not required in order to exploit this vulnerability.

CVE-2025-69259
HIGH 7.5

A message unchecked NULL return value vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-of-service condition on affected installations. Please note: authentication is not required in order to exploit this vulnerability..

CVE-2025-69235
HIGH 7.5

Whale browser before 4.35.351.12 allows an attacker to bypass the Same-Origin Policy in a sidebar environment.

CVE-2025-69200
HIGH 7.5

phpMyFAQ has unauthenticated config backup download via /api/setup/backup

CVE-2025-68996
HIGH 7.5

WordPress Responsive Posts Carousel Pro plugin <= 15.1 - Local File Inclusion vulnerability

CVE-2025-68987
HIGH 7.5

WordPress Cinerama theme <= 2.9 - Local File Inclusion vulnerability

CVE-2025-68985
HIGH 7.5

WordPress Aora theme <= 1.3.15 - Local File Inclusion vulnerability

CVE-2025-68984
HIGH 7.5

WordPress Puca theme <= 2.6.39 - Local File Inclusion vulnerability

CVE-2025-68983
HIGH 7.5

WordPress Greenmart theme <= 4.2.11 - Local File Inclusion vulnerability

CVE-2025-68954
HIGH 7.5

Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced

CVE-2025-68877
HIGH 7.5

WordPress CedCommerce Integration for Good Market plugin <= 1.0.6 - Local File Inclusion vulnerability

CVE-2025-68870
HIGH 7.5

WordPress CookieHint WP plugin <= 1.0.0 - Local File Inclusion vulnerability

CVE-2025-68850
HIGH 7.5

WordPress Sell Downloads plugin <= 1.1.12 - Broken Access Control vulnerability

CVE-2025-68825
HIGH 7.5

HCL Hive is affected by incorrect default permissions

CVE-2025-68608
HIGH 7.5

WordPress Userpro plugin <= 5.1.9 - Broken Access Control vulnerability

CVE-2025-68563
HIGH 7.5

WordPress Subscribe to Unlock Lite plugin <= 1.3.0 - Local File Inclusion vulnerability

CVE-2025-68547
HIGH 7.5

WordPress Follow My Blog Post plugin <= 2.4.0 - Arbitrary Content Deletion vulnerability

CVE-2025-68540
HIGH 7.5

WordPress Fana theme <= 1.1.35 - Local File Inclusion vulnerability

CVE-2025-68537
HIGH 7.5

WordPress Zota theme <= 1.3.14 - Local File Inclusion vulnerability

CVE-2025-68530
HIGH 7.5

WordPress Bookory theme <= 2.2.7 - Local File Inclusion vulnerability

CVE-2025-68420
HIGH 7.5

Privilege Escalation in Comarch ERP Optima

CVE-2025-68272
HIGH 7.5

Signal K Server Vulnerable to Denial of Service via Unrestricted Access Request Flooding

CVE-2025-68045
HIGH 7.5

WordPress WP Event SOlution plugin <= 4.1.12 - Broken Access Control vulnerability

CVE-2025-68036
HIGH 7.5

WordPress CubeWP plugin <= 1.1.27 - Broken Access Control vulnerability

CVE-2025-68033
HIGH 7.5

WordPress Custom Related Posts plugin <= 1.8.0 - Sensitive Data Exposure vulnerability

CVE-2025-67931
HIGH 7.5

WordPress BulletProof Security plugin <= 6.9 - Sensitive Data Exposure vulnerability

CVE-2025-67925
HIGH 7.5

WordPress Corpkit theme <= 2.0 - Local File Inclusion vulnerability

CVE-2025-67909
HIGH 7.5

WordPress Membership For WooCommerce plugin <= 3.0.3 - Insecure Direct Object References (IDOR) vulnerability

CVE-2025-66877
HIGH 7.5

Buffer overflow vulnerability in function dcputchar in decompile.c in libming 0.4.8.

CVE-2025-66862
HIGH 7.5

A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.

CVE-2025-66443
HIGH 7.5

Pexip Infinity 35.0 through 38.1 before 39.0, in non-default configurations that use Direct Media for WebRTC, has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a temporary denial of service.

CVE-2025-66379
HIGH 7.5

Pexip Infinity before 39.0 has Improper Input Validation in the media implementation, allowing a remote attacker to trigger a software abort via a crafted media stream, resulting in a denial of service.

CVE-2025-66377
HIGH 7.5

Pexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an attacker (who already has access to execute code on one node within a Pexip Infinity installation) to impact the operation of other nodes within the installation.

CVE-2025-66236
HIGH 7.5

Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI

CVE-2025-62188
HIGH 7.5

Apache DolphinScheduler: Users can access sensitive information through the actuator endpoint.

CVE-2025-59467
HIGH 7.5

A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow privilege escalation if an Administrator is tricked into visiting a crafted malicious page. This plugin is disabled by default. Affected Products: UCRM Argentina AFIP invoices Plugin (Version 1.2.0 and earlier) Mitigation: Update UCRM Argentina AFIP invoices Plugin to Version 1.3.0 or later.

CVE-2025-59032
HIGH 7.5

ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.

CVE-2025-49403
HIGH 7.5

WordPress Premium Age Verification / Restriction for WordPress Plugin <= 3.0.2 - Arbitrary File Download Vulnerability

CVE-2025-48704
HIGH 7.5

Pexip Infinity 35.0 through 37.2 before 38.0 has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a denial of service.

CVE-2025-48431
HIGH 7.5

Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid pointer error.

CVE-2025-46315
HIGH 7.5

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to access protected user data.

CVE-2025-46311
HIGH 7.5

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2. An app may be able to access sensitive user data.

CVE-2025-46255
HIGH 7.5

WordPress LoginWP - Pro Plugin <= 4.0.8.5 - Settings Change vulnerability

CVE-2025-43494
HIGH 7.5

A mail header parsing issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. An attacker may be able to cause a persistent denial-of-service.

CVE-2025-32151
HIGH 7.5

WordPress BuddyForms plugin <= 2.10.2 - Local File Inclusion vulnerability

CVE-2025-32096
HIGH 7.5

Pexip Infinity 33.0 through 37.0 before 37.1 has improper input validation in signaling that allows an attacker to trigger a software abort, resulting in a denial of service.

CVE-2025-32095
HIGH 7.5

Pexip Infinity before 37.0 has improper input validation in signalling that allows a remote attacker to trigger a software abort via a crafted signalling message, resulting in a denial of service.

CVE-2025-22715
HIGH 7.5

WordPress WP Attractive Donations System - Easy Stripe & Paypal donations plugin <= 1.25 - Arbitrary Content Deletion vulnerability

CVE-2025-15464
HIGH 7.5

KL-001-2026-01: yintibao Fun Print Mobile Unauthorized Access via Context Hijacking

CVE-2025-15358
HIGH 7.5

DVP-12SE11T - Denial of Service Vulnerability

CVE-2025-14874
HIGH 7.5

Nodemailer: nodemailer: denial of service via crafted email address header

CVE-2025-14713
HIGH 7.5

An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote attackers to obtain user credentials from the edge server.

CVE-2025-5804
HIGH 7.5

WordPress Case Theme User < 1.0.4 - Local File Inclusion Vulnerability

CVE-2026-107177
HIGH 7.4

Express Gateway through 1.16.11 Hardcoded Default cipherKey Exposes OAuth Tokens

CVE-2026-106279
HIGH 7.4

Incorrect reference resolution in Passwords in Google Chrome on on iOS prior to 155.0.8059.39 allowed a local attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)

CVE-2026-102123
HIGH 7.4

Kiteworks Core Path Traversal

CVE-2026-95676
HIGH 7.4

AuthPoint Gateway Improper Authentication in LDAP Sync Allows First-Factor Authentication Bypass

CVE-2026-78501
HIGH 7.4

Microsoft 365 Copilot Business Chat Information Disclosure Vulnerability

CVE-2026-18184
HIGH 7.4

IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

CVE-2026-18176
HIGH 7.4

IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

CVE-2026-18172
HIGH 7.4

IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

CVE-2025-15462
HIGH 7.4

UTT 进取 520W ConfigAdvideo strcpy buffer overflow

CVE-2025-15461
HIGH 7.4

UTT 进取 520W formTaskEdit strcpy buffer overflow

CVE-2025-15460
HIGH 7.4

UTT 进取 520W formPptpClientConfig strcpy buffer overflow

CVE-2025-15459
HIGH 7.4

UTT 进取 520W formUser strcpy buffer overflow

CVE-2025-15431
HIGH 7.4

UTT 进取 512W formFtpServerDirConfig strcpy buffer overflow

CVE-2025-15430
HIGH 7.4

UTT 进取 512W formFtpServerShareDirSelcet strcpy buffer overflow

CVE-2025-15429
HIGH 7.4

UTT 进取 512W formConfigCliForEngineerOnly strcpy buffer overflow

CVE-2025-15428
HIGH 7.4

UTT 进取 512W formRemoteControl strcpy buffer overflow

CVE-2025-15234
HIGH 7.4

Tenda M3 setInternetLanInfo formSetRemoteInternetLanInfo heap-based overflow

CVE-2025-15233
HIGH 7.4

Tenda M3 setAdInfoDetail formSetAdInfoDetails heap-based overflow

CVE-2025-15232
HIGH 7.4

Tenda M3 setAdPushInfo formSetAdPushInfo stack-based overflow

CVE-2025-15231
HIGH 7.4

Tenda M3 setVlanInfo formSetRemoteVlanInfo stack-based overflow

CVE-2025-15230
HIGH 7.4

Tenda M3 setVlanPolicyData formSetVlanPolicy heap-based overflow

CVE-2025-15218
HIGH 7.4

Tenda AC10U POST Request Parameter AdvSetLanip fromadvsetlanip buffer overflow

CVE-2025-15217
HIGH 7.4

Tenda AC23 HTTP POST Request formSetPPTPUserList buffer overflow

CVE-2025-15216
HIGH 7.4

Tenda AC23 SetIpMacBind fromSetIpMacBind stack-based overflow

CVE-2025-15215
HIGH 7.4

Tenda AC10U HTTP POST Request setPptpUserList formSetPPTPUserList buffer overflow

CVE-2025-15193
HIGH 7.4

D-Link DWR-M920 formParentControl sub_423848 buffer overflow

CVE-2025-15190
HIGH 7.4

D-Link DWR-M920 formFilter sub_42261C stack-based overflow

CVE-2025-15189
HIGH 7.4

D-Link DWR-M920 formDefRoute sub_464794 buffer overflow

CVE-2025-15137
HIGH 7.4

TRENDnet TEW-800MB NTPSyncWithHost.cgi sub_F934  command injection

CVE-2025-15136
HIGH 7.4

TRENDnet TEW-800MB Management wizardset do_setWizard_asp command injection

CVE-2025-15092
HIGH 7.4

UTT 进取 512W ConfigExceptMSN strcpy buffer overflow

CVE-2025-15091
HIGH 7.4

UTT 进取 512W formPictureUrl strcpy buffer overflow

CVE-2025-15090
HIGH 7.4

UTT 进取 512W formConfigNoticeConfig strcpy buffer overflow

CVE-2025-15089
HIGH 7.4

UTT 进取 512W APSecurity strcpy buffer overflow

CVE-2025-14576
HIGH 7.4

Possible QML code injection in VectorImage component

CVE-2026-106451
HIGH 7.3

yawkat LZ4 Java: Native library extraction to a shared temporary directory is vulnerable to file replacement by another local user

CVE-2026-79809
HIGH 7.3

Unauthenticated Path Traversal in ClearPass Policy Manager API Endpoint Leads to Authorization Bypass

CVE-2026-18875
HIGH 7.3

IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

CVE-2026-18185
HIGH 7.3

IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

CVE-2025-68927
HIGH 7.3

Improper Neutralization of HTML Tags in a Web Page in libredesk

CVE-2025-68619
HIGH 7.3

Signal K Server Vulnerable to Remote Code Execution via Malicious npm Package

CVE-2025-15472
HIGH 7.3

TRENDnet TEW-811DRU httpd  uapply.cgi setDeviceURL  os command injection

CVE-2025-15364
HIGH 7.3

Download Manager <= 3.3.40 - Unauthenticated Limited Privilege Escalation via updatePassword

CVE-2025-15180
HIGH 7.3

Tenda WH450 HTTP Request webExcptypemanFilte stack-based overflow

CVE-2025-15179
HIGH 7.3

Tenda WH450 qossetting stack-based overflow

CVE-2025-15178
HIGH 7.3

Tenda WH450 HTTP Request VirtualSer stack-based overflow

CVE-2025-15177
HIGH 7.3

Tenda WH450 HTTP Request SetIpBind stack-based overflow

CVE-2025-15164
HIGH 7.3

Tenda WH450 SafeMacFilter stack-based overflow

CVE-2025-15163
HIGH 7.3

Tenda WH450 SafeEmailFilter stack-based overflow

CVE-2025-15162
HIGH 7.3

Tenda WH450 RouteStatic stack-based overflow

CVE-2025-15161
HIGH 7.3

Tenda WH450 PPTPUserSetting stack-based overflow

CVE-2025-15160
HIGH 7.3

Tenda WH450 PPTPServer stack-based overflow

CVE-2025-14362
HIGH 7.3

GoAnywhere MFT SFTP Service Login Vulnerable to Brute Force Attack Under Certain Circumstances

CVE-2025-12659
HIGH 7.3

Heap-based buffer overflow in Siemens Simcenter Femap

CVE-2021-1432
HIGH 7.3

Cisco IOS XE SD-WAN Software Arbitrary Command Execution Vulnerability

CVE-2026-104677
HIGH 7.2

WP Coder 4.0 - 4.5.1 - Editor+ RCE via Global PHP

CVE-2026-103007
HIGH 7.2

Incorrect Authorization in Elasticsearch Leading to Privilege Escalation

CVE-2026-102257
HIGH 7.2

A Zip Slip vulnerability in the in the SMA1000 Appliance Management Console (AMC) interface allows an attacker to extract files outside the intended destination directory using a specially crafted archive, resulting in remote code execution.

CVE-2026-102173
HIGH 7.2

Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.3.1 - Unauthenticated Stored Cross-Site Scripting via Registration Metadata

CVE-2026-102150
HIGH 7.2

Kiteworks Secure Data Forms Missing Authentication for Critical Function

CVE-2026-102142
HIGH 7.2

Kiteworks Core Remote Code Execution through Server-Side Template Injection

CVE-2026-102132
HIGH 7.2

Kiteworks Core Privilege Escalation through Improper Access Control

CVE-2026-102114
HIGH 7.2

Kiteworks Core OS Command Injection

CVE-2026-102099
HIGH 7.2

Kiteworks Core arbitrary file write

CVE-2026-102098
HIGH 7.2

Kiteworks Core SQL Injection

CVE-2026-102096
HIGH 7.2

Kiteworks Core OS command injection

CVE-2026-102093
HIGH 7.2

Kiteworks Core improper privilege management

CVE-2026-101153
HIGH 7.2

Security Advisory 0188

CVE-2026-89417
HIGH 7.2

OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. <= 6.3.10 - Unauthenticated Stored Cross-Site Scripting via 's' Search Parameter in comments-atom Feed

CVE-2026-79811
HIGH 7.2

Authenticated SQL Injection allows Remote Code Execution in ClearPass Policy Manager API

CVE-2026-79810
HIGH 7.2

Authenticated Remote Code Execution Vulnerabilities in HPE Networking ClearPass Policy Manager

CVE-2026-49878
HIGH 7.2

In wpas_handle_robust_av_scs_recv_action of robust_av.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitation.

CVE-2026-30958
HIGH 7.2

OneUptime: Path Traversal — Arbitrary File Read (No Auth)

CVE-2025-68038
HIGH 7.2

WordPress Icegram Express Pro plugin < 5.9.14 - PHP Object Injection vulnerability

CVE-2025-66376
HIGH 7.2

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

CVE-2025-64122
HIGH 7.2

Nuvation Energy Multi-Stack Controller Private Key Stored on Device

CVE-2025-62627
HIGH 7.2

An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could allow an attacker with an unprivileged VM to read kernel memory or co-located guest VM memory, potentially resulting in loss of confidentiality or availability.

CVE-2025-62578
HIGH 7.2

DVP-12SE - Modbus/TCP Cleartext Transmission of Sensitive Information

CVE-2025-53681
HIGH 7.2

An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2.0 through 7.2.8 allows an authenticated privileged attacker to execute unauthorized code or commands via specifically crafted HTTP or HTTPS requests.

CVE-2025-14509
HIGH 7.2

Lucky Wheel for WooCommerce – Spin a Sale <= 1.1.13 - Authenticated (Administrator+) PHP Code Injection via Conditional Tags

CVE-2025-13592
HIGH 7.2

Advanced Ads <= 2.0.14 - Authenticated (Editor+) Remote Code Execution via Shortcode

CVE-2025-9611
HIGH 7.2

Microsoft Playwright MCP Server < 0.0.40 DNS Rebinding via Missing Origin Header Validation

CVE-2025-5965
HIGH 7.2

RCE via the backup feature available only to user with high privilege

CVE-2025-2515
HIGH 7.2

Bluechi: privilege escalation in bluechi via unrestricted cross-node systemd dependencies

CVE-2026-107180
HIGH 7.1

MISP: Forced TOTP Enrolment Bypassed via Non-Browser Request Types on otp_required Instances

CVE-2026-107159
HIGH 7.1

MiniUPnPd through 2.3.11 Divide-by-Zero DoS via SSDP M-SEARCH MX Header

CVE-2026-106560
HIGH 7.1

Backstage: Improper repository path validation in a Scaffolder backend module

CVE-2026-105811
HIGH 7.1

Authorization bypass through a user-controlled key in the Amazon Q Business Lambda hook sample in QnABot on AWS

CVE-2026-105316
HIGH 7.1

Magee Shortcodes <= 2.1.1 - Reflected XSS via live_preview and magee_create_shortcode Actions

CVE-2026-105138
HIGH 7.1

Obot 0.12.0 before 0.26.2 Credential Exposure via MCP Catalog Entry API

CVE-2026-104944
HIGH 7.1

Unauthenticated TDP Function Pointer Dispatch Denial of Service in TP-Link Tapo C500

CVE-2026-103009
HIGH 7.1

Authorization Bypass Through User-Controlled Key in Elasticsearch Leading to Information Disclosure

CVE-2026-102169
HIGH 7.1

Security Advisory 0194

CVE-2026-102168
HIGH 7.1

Security Advisory 0194

CVE-2026-102158
HIGH 7.1

Security Advisory 0190

CVE-2026-102155
HIGH 7.1

Security Advisory 0190

CVE-2026-100507
HIGH 7.1

WordPress If-So Dynamic Content Personalization plugin <= 1.10.1 - Cross Site Scripting (XSS) vulnerability

CVE-2026-98349
HIGH 7.1

wifi: libipw: reject too-short beacon and probe responses

CVE-2026-98348
HIGH 7.1

wifi: libipw: reject too-short association responses

CVE-2026-98243
HIGH 7.1

dma-buf/dma-fence: fix checking signaling bit for timeline and driver name v3

CVE-2026-98216
HIGH 7.1

IB/hfi1: Fix the PIO_CRED credit-return mmap

CVE-2026-98180
HIGH 7.1

drm/msm: RCU-free the scheduler-containing ring and VM objects

CVE-2026-98169
HIGH 7.1

smb: client: fix potential OOB read in smb3_enum_snapshots()

CVE-2026-98164
HIGH 7.1

KVM: x86/mmu: Check write tracking in all address spaces

CVE-2026-96577
HIGH 7.1

Oc-mirror__release-4.21: embedded local cache registry listens on all interfaces without authentication, with delete enabled

CVE-2026-92533
HIGH 7.1

Path Traversal in BugTracker.NET

CVE-2026-87971
HIGH 7.1

If-So Dynamic Content 1.4.4 - 1.10.1 - Reflected XSS via 'message' Parameter

CVE-2026-87114
HIGH 7.1

Kube-compare: container:// reference extraction runs the image entrypoint and silently escalates to sudo

CVE-2026-79960
HIGH 7.1

Gitea deploy key pushes acting as the repository owner

CVE-2026-46434
HIGH 7.1

wger: Trainer Privilege Escalation - Improper Privilege Management

CVE-2026-43976
HIGH 7.1

wger: cross-tenant admin notes/contracts leak via gym=None bypass (5 views)

CVE-2026-42618
HIGH 7.1

In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_decompress() in compress.c that allows an attacker to corrupt one byte of heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by reading the special crafted file.

CVE-2026-42418
HIGH 7.1

WordPress Social Rocket plugin <= 1.3.5 - Cross Site Scripting (XSS) vulnerability

CVE-2026-18177
HIGH 7.1

IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

CVE-2026-5703
HIGH 7.1

Path Traversal in Satel Iberia SenNet Datalogger Serie 200

CVE-2025-69415
HIGH 7.1

In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly aligned with whether the device is currently associated with an account.

CVE-2025-69220
HIGH 7.1

LibreChat has Insufficient Access Control for Agent Files

CVE-2025-69085
HIGH 7.1

WordPress JobBank plugin <= 1.2.2 - Reflected Cross Site Scripting (XSS) vulnerability

CVE-2025-69084
HIGH 7.1

WordPress Photo Gallery plugin <= 2.7.7.26 - Reflected Cross Site Scripting (XSS) vulnerability

CVE-2025-69082
HIGH 7.1

WordPress Arlo theme <= 6.0.3 - Cross Site Scripting (XSS) vulnerability

CVE-2025-68892
HIGH 7.1

WordPress Scroll rss excerpt plugin <= 5.0 - Reflected Cross Site Scripting (XSS) vulnerability

CVE-2025-68891
HIGH 7.1

WordPress WP App Bar plugin <= 1.5 - Reflected Cross Site Scripting (XSS) vulnerability

CVE-2025-68890
HIGH 7.1

WordPress e-shops plugin <= 1.0.4 - Reflected Cross Site Scripting (XSS) vulnerability

CVE-2025-68887
HIGH 7.1

WordPress WP-BusinessDirectory plugin <= 4.0.1 - Cross Site Scripting (XSS) vulnerability

CVE-2025-68879
HIGH 7.1

WordPress Content Grid Slider plugin <= 1.5 - Reflected Cross Site Scripting (XSS) vulnerability

CVE-2025-68878
HIGH 7.1

WordPress Advanced Custom CSS plugin <= 1.1.0 - Reflected Cross Site Scripting (XSS) vulnerability

CVE-2025-68876
HIGH 7.1

WordPress Invelity SPS connect plugin <= 1.0.8 - Reflected Cross Site Scripting (XSS) vulnerability

CVE-2025-68874
HIGH 7.1

WordPress Visitor Stats Widget plugin <= 1.5.0 - Reflected Cross Site Scripting (XSS) vulnerability

CVE-2025-68873
HIGH 7.1

WordPress PRIMER by chloédigital plugin <= 1.0.25 - Reflected Cross Site Scripting (XSS) vulnerability

CVE-2025-68872
HIGH 7.1

WordPress Eli's WordCents adSense Widget with Analytics plugin <= 1.3.03.27 - Reflected Cross Site Scripting (XSS) vulnerability

CVE-2025-68861
HIGH 7.1

WordPress Plugin Optimizer plugin <= 1.3.7 - Broken Access Control vulnerability

CVE-2025-68851
HIGH 7.1

WordPress Okay Toolkit plugin <= 2.3 - Reflected Cross Site Scripting (XSS) vulnerability

CVE-2025-68840
HIGH 7.1

WordPress iRobots.txt SEO plugin <= 1.1.2 - Reflected Cross Site Scripting (XSS) vulnerability

CVE-2025-67932
HIGH 7.1

WordPress Listeo Core plugin < 2.0.19 - Cross Site Scripting (XSS) vulnerability

CVE-2025-67930
HIGH 7.1

WordPress eHive Search plugin <= 2.5.0 - Cross Site Scripting (XSS) vulnerability

CVE-2025-67927
HIGH 7.1

WordPress Link Whisper Free plugin <= 0.8.8 - Cross Site Scripting (XSS) vulnerability

CVE-2025-67922
HIGH 7.1

WordPress Grand Restaurant theme < 7.0.9 - Cross Site Scripting (XSS) vulnerability

CVE-2025-67918
HIGH 7.1

WordPress Woffice theme <= 5.4.30 - Cross Site Scripting (XSS) vulnerability

CVE-2025-67916
HIGH 7.1

WordPress Jobify theme <= 4.3.0 - Cross Site Scripting (XSS) vulnerability

CVE-2025-67622
HIGH 7.1

WordPress Evergreen Post Tweeter plugin <= 1.8.9 - Cross Site Request Forgery (CSRF) to Stored XSS vulnerability

CVE-2025-64305
HIGH 7.1

Columbia Weather Systems MicroServer Cleartext Storage in a File or on Disk

CVE-2025-59969
HIGH 7.1

Junos OS Evolved: QFX5000 Series and PTX Series: An attacker sending crafted multicast packets will cause evo-aftmand / evo-pfemand to crash and restart

CVE-2025-59174
HIGH 7.1

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially crafted messages may cause service degradation.

CVE-2025-58920
HIGH 7.1

WordPress Cerato theme <= 2.2.18 - Reflected Cross Site Scripting (XSS) vulnerability

CVE-2025-52747
HIGH 7.1

WordPress Themebox - Digital Products Ecommerce theme <= 1.4.2 - Cross Site Scripting (XSS) vulnerability

CVE-2025-47400
HIGH 7.1

Buffer Over-read in Computer Vision

CVE-2025-46494
HIGH 7.1

WordPress WidgetKit Pro plugin <= 1.13.1 - Reflected Cross Site Scripting (XSS) vulnerability

CVE-2025-41752
HIGH 7.1

Reflected XSS vulnerability in pxc_portSfp.php

CVE-2025-41751
HIGH 7.1

Reflected XSS vulnerability in pxc_portCntr.php

CVE-2025-41750
HIGH 7.1

Reflected XSS vulnerability in pxc_PortCfg.php

CVE-2025-41749
HIGH 7.1

Reflected XSS vulnerability in port_util.php

CVE-2025-41748
HIGH 7.1

Reflected XSS vulnerability in pxc_Dot1xCfg.php

CVE-2025-41747
HIGH 7.1

Reflected XSS vulnerability in pxc_vlanIntfCfg.php

CVE-2025-41746
HIGH 7.1

Reflected XSS vulnerability in pxc_portSecCfg.php

CVE-2025-41745
HIGH 7.1

Reflected XSS vulnerability in pxc_portCntr2.php

CVE-2025-41695
HIGH 7.1

Reflected XSS vulnerability in dyn_conn.php

CVE-2025-32300
HIGH 7.1

WordPress DZS Video Gallery plugin <= 12.25 - Reflected Cross Site Scripting (XSS) vulnerability

CVE-2025-31642
HIGH 7.1

WordPress WPCHURCH plugin <= 2.7.0 - Reflected Cross Site Scripting (XSS) vulnerability

CVE-2025-31013
HIGH 7.1

WordPress Themify Folo theme <= 1.9.6 - Reflected Cross Site Scripting (XSS) vulnerability

CVE-2025-27004
HIGH 7.1

WordPress Famous - Responsive Image And Video Grid Gallery WordPress Plugin plugin <= 1.4 - Reflected Cross Site Scripting (XSS) vulnerability

CVE-2025-27002
HIGH 7.1

WordPress CountDown With Image or Video Background plugin <= 1.5 - Reflected Cross Site Scripting (XSS) vulnerability

CVE-2025-23554
HIGH 7.1

WordPress Off Page SEO plugin <= 3.0.3 - Reflected Cross Site Scripting (XSS) vulnerability

CVE-2025-23550
HIGH 7.1

WordPress Product Puller plugin <= 1.5.1 - Reflected Cross Site Scripting (XSS) vulnerability

CVE-2025-23458
HIGH 7.1

WordPress Ads24 Lite plugin <= 1.0 - Reflected Cross Site Scripting (XSS) vulnerability

CVE-2025-22741
HIGH 7.1

WordPress Felan Framework plugin <= 1.1.3 - Reflected Cross Site Scripting (XSS) vulnerability

CVE-2025-22725
HIGH 7.1

WordPress WP Virtual Assistant plugin <= 3.1 - Cross Site Scripting (XSS) vulnerability

CVE-2025-15239
HIGH 7.1

Quanta Computer|QOCA aim AI Medical Cloud Platform - SQL Injection

CVE-2025-15238
HIGH 7.1

Quanta Computer|QOCA aim AI Medical Cloud Platform - SQL Injection

CVE-2025-15235
HIGH 7.1

Quanta Computer|QOCA aim AI Medical Cloud Platform - Missing Authorization

CVE-2025-14835
HIGH 7.1

WP Photo Album Plus <= 9.1.05.008 - Reflected Cross-Site Scripting

CVE-2025-5090
HIGH 7.1

Arista CloudVision Exchange Cluster Instability via Unexpected Switch Messages

CVE-2025-5089
HIGH 7.1

Arista EOS SysDB Agent Denial of Service via Malformed CVX Client/Server Messages

CVE-2026-98360
HIGH 7

RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds

CVE-2026-98359
HIGH 7

RDMA/core: Reject unregistering netdevs in ib_get_eth_speed

CVE-2026-98331
HIGH 7

wifi: mac80211: unlist vifs when their netdev is unregistered

CVE-2026-98330
HIGH 7

wifi: cfg80211: get the wiphy out of a dying network namespace

CVE-2026-98252
HIGH 7

RDMA/core: fix refcount bug in iwpm_get_nlmsg_request()

CVE-2026-98230
HIGH 7

xfrm: use hlist_del_init_rcu for state_cache and state_cache_input

CVE-2026-98197
HIGH 7

hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove

CVE-2026-84854
HIGH 7

Out of Bound Write on WibuKey for Windows

CVE-2026-58880
HIGH 7

In handle_app_val_response of btif_rc.cc, there is a possible way to achieve code execution due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2026-56906
HIGH 7

In ep_free of eventpoll.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2025-68456
HIGH 7

Unauthenticated Craft CMS users can trigger a database backup

CVE-2025-62555
HIGH 7

Microsoft Word Remote Code Execution Vulnerability

CVE-2025-20801
HIGH 7

In seninf, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10251210; Issue ID: MSV-4926.

CVE-2025-20779
HIGH 7

In display, there is a possible use after free due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10184084; Issue ID: MSV-4720.

CVE-2025-14304
HIGH 7

ASRock, ASRockRack, ASRockInd|Motherboard - Protection Mechanism Failure

CVE-2025-14302
HIGH 7

GIGABYTE|Motherboard - Protection Mechanism Failure

CVE-2025-13914
HIGH 7

Apstra: SSH host key validation vulnerability for managed devices

CVE-2025-11901
HIGH 7

An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760, H410, H510, H610, H470, Z590, Z690, Z790, W480, W680 series chipsets. Exploitation requires physical access to internal expansion slots to install a specially crafted device and supporting software utility, and may lead to uncontrolled resource consumption that increases the risk of unauthorized direct memory access (DMA). Refer to the 'Security Update for UEFI firmware' section on the ASUS Security Advisory for more information.

CVE-2026-104074
MEDIUM 6.9

Coturn 4.10.0 Uninitialized Stack Memory Disclosure via ERROR-CODE

CVE-2026-104073
MEDIUM 6.9

NetBox 2.9.5 < 4.7.0 Session Hijacking via Custom Links

CVE-2026-102781
MEDIUM 6.9

Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6

CVE-2026-102156
MEDIUM 6.9

Security Advisory 0191

CVE-2026-84897
MEDIUM 6.9

wolfSSH server accepts server-to-client DH group exchange messages from an unauthenticated client, causing pre-authentication primality-test CPU exhaustion and key exchange role confusion

CVE-2026-32598
MEDIUM 6.9

OneUptime: Password Reset Token Logged at INFO Level

CVE-2025-69211
MEDIUM 6.9

Nest has a Fastify URL Encoding Middleware Bypass (TOCTOU)

CVE-2025-34171
MEDIUM 6.9

CasaOS <= 0.4.15 Unauthenticated File and Debug Data Exposure

CVE-2025-15615
MEDIUM 6.9

Wazuh Manager authd service Improper SSL/TLS Renegotiation Handling leading to Denial of Service

CVE-2025-15115
MEDIUM 6.9

Petlibro Smart Pet Feeder Platform through 1.7.31 Authentication Bypass via API endpoint

CVE-2025-15066
MEDIUM 6.9

Arbitrary File Download through Path Traversal in Innorix WP

CVE-2025-6225
MEDIUM 6.9

Command injection in Kieback&Peter Neutrino-GLT

CVE-2025-3660
MEDIUM 6.9

Petlibro Smart Pet Feeder Platform through 1.7.31 Broken Access Control via API endpoint

CVE-2025-3654
MEDIUM 6.9

Petlibro Smart Pet Feeder Platform through 1.7.31 Information Disclosure via API endpoint

CVE-2025-3653
MEDIUM 6.9

Petlibro Smart Pet Feeder through 1.7.31 Platform Improper Access Control via API endpoint

CVE-2025-3652
MEDIUM 6.9

Petlibro Smart Pet Feeder Platform through 1.7.31 Audio Information Disclosure via API endpoint

CVE-2025-3646
MEDIUM 6.9

Petlibro Smart Pet Feeder Platform through 1.7.31 Authorization Bypass via Device Share API

CVE-2019-25597
MEDIUM 6.9

NSauditor 3.1.2.0 Denial of Service via Community Field

CVE-2019-25595
MEDIUM 6.9

jetAudio 8.1.7.20702 Basic Denial of Service via URL Handler

CVE-2019-25572
MEDIUM 6.9

NordVPN 6.19.6 Denial of Service via Email Field Buffer Overflow

CVE-2019-25571
MEDIUM 6.9

MediaMonkey 4.1.23 Denial of Service via Malformed URL

CVE-2019-25548
MEDIUM 6.9

BlueStacks 4.80.0.1060 Denial of Service via Search Field

CVE-2018-25233
MEDIUM 6.9

WebDrive 18.00.5057 Denial of Service via Secure WebDAV

CVE-2018-25231
MEDIUM 6.9

HeidiSQL 9.5.0.5196 Denial of Service via Preferences

CVE-2018-25228
MEDIUM 6.9

NetSetMan 4.7.1 Workgroup Buffer Overflow Denial of Service

CVE-2026-106460
MEDIUM 6.8

Backstage: Explicit negative email verification can be ignored during shared OAuth profile normalization

CVE-2026-106457
MEDIUM 6.8

Backstage: Insufficient audience validation in the Cloudflare Access auth provider

CVE-2026-104953
MEDIUM 6.8

MPG < 4.2.3 - Editor+ SQLi via Project Import

CVE-2026-104945
MEDIUM 6.8

Authenticated ONVIF PTZ Out-of-Bounds Stack Write Denial of Service in TP-Link Tapo C500

CVE-2026-104667
MEDIUM 6.8

Animated Number Counters < 3.1 - Editor+ Second-Order SQLi via Counter Order

CVE-2026-104653
MEDIUM 6.8

Envira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Crop Dimensions

CVE-2026-104652
MEDIUM 6.8

Envira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Image ID

CVE-2026-104048
MEDIUM 6.8

Sssd: sssd: authorization bypass via cross-domain username collision in hbac evaluation

CVE-2026-58068
MEDIUM 6.8

This vulnerability in Veeam Agent for Microsoft Windows allows any local user to terminate arbitrary processes on the system.

CVE-2026-19029
MEDIUM 6.8

HDF5 scale-offset filter heap buffer over-read via crafted chunk

CVE-2025-41697
MEDIUM 6.8

Shell access to UART Console

CVE-2025-41692
MEDIUM 6.8

Weak/Predictable root Password

CVE-2025-31991
MEDIUM 6.8

HCL DevOps Velocity is susceptible to brute-force attacks

CVE-2025-15642
MEDIUM 6.8

Netskope Client Service Insufficient Access Controls

CVE-2025-15641
MEDIUM 6.8

Netskope Client Exposed IOCTL with Insufficient Access Controls

CVE-2025-15441
MEDIUM 6.8

Form Maker < 1.15.38 - SQL Injection

CVE-2025-15070
MEDIUM 6.8

Data Exposure in Gmission Web FAX

CVE-2025-14728
MEDIUM 6.8

Rapid7 Velociraptor Directory Traversal Vulnerability

CVE-2025-14095
MEDIUM 6.8

Privilege boundary violation in Radiometer Products

CVE-2026-102141
MEDIUM 6.7

Kiteworks Core Privilege Escalation through External Control of File Name or Path

CVE-2026-79814
MEDIUM 6.7

Local Arbitrary File Write Leading to Local Privilege Escalation in ClearPass Policy Manager OnGuard Agent

CVE-2026-79813
MEDIUM 6.7

Local Privilege Escalation in ClearPass Client Software

CVE-2026-56952
MEDIUM 6.7

In platform_msg_handler_init of default_msg_handlers.c, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVE-2026-25269
MEDIUM 6.7

Out-of-bounds Write in Camera Driver

CVE-2026-12545
MEDIUM 6.7

Rubygem-hammer_cli: command injection via insecure editor invocation

CVE-2025-71384
MEDIUM 6.7

Dbit WIFI4 N300 1.0.0 devices allows administrators (from the local Wi-Fi network) to execute OS commands by leveraging a stack-based buffer overflow via the /api/addStaticDHCP comment field,

CVE-2025-59888
MEDIUM 6.7

Improper quotation in search paths in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to the file system. This security issue has been fixed in the latest version of EUC which is available on the Eaton download center.

CVE-2025-47344
MEDIUM 6.7

Time-of-check Time-of-use (TOCTOU) Race Condition in Camera Driver

CVE-2025-47337
MEDIUM 6.7

Use After Free in Camera Driver

CVE-2025-47336
MEDIUM 6.7

Use After Free in Camera Driver

CVE-2025-47335
MEDIUM 6.7

Buffer Copy Without Checking Size of Input in Camera Driver

CVE-2025-47334
MEDIUM 6.7

Buffer Copy Without Checking Size of Input in Camera Driver

CVE-2025-47332
MEDIUM 6.7

Time-of-check Time-of-use (TOCTOU) Race Condition in Camera Driver

CVE-2025-36192
MEDIUM 6.7

Missing Authorization with the DS8900F and DS8A00 Hardware Management Console

CVE-2025-20807
MEDIUM 6.7

In dpe, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10114841; Issue ID: MSV-4451.

CVE-2025-20806
MEDIUM 6.7

In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10114835; Issue ID: MSV-4479.

CVE-2025-20805
MEDIUM 6.7

In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10114696; Issue ID: MSV-4480.

CVE-2025-20804
MEDIUM 6.7

In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS10198951; Issue ID: MSV-4503.

CVE-2025-20803
MEDIUM 6.7

In dpe, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS10199779; Issue ID: MSV-4504.

CVE-2025-20802
MEDIUM 6.7

In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10238968; Issue ID: MSV-4914.

CVE-2025-20787
MEDIUM 6.7

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10149879; Issue ID: MSV-4658.

CVE-2025-20786
MEDIUM 6.7

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10149882; Issue ID: MSV-4673.

CVE-2025-20785
MEDIUM 6.7

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10149882; Issue ID: MSV-4677.

CVE-2025-20784
MEDIUM 6.7

In display, there is a possible memory corruption due to uninitialized data. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10182882; Issue ID: MSV-4683.

CVE-2025-20783
MEDIUM 6.7

In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10182882; Issue ID: MSV-4684.

CVE-2025-20782
MEDIUM 6.7

In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10182882; Issue ID: MSV-4685.

CVE-2025-68974
MEDIUM 6.6

WordPress WordPress Social Login and Register plugin <= 7.7.0 - Local File Inclusion vulnerability

CVE-2025-47333
MEDIUM 6.6

Use After Free in HLOS

CVE-2025-46641
MEDIUM 6.6

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authentication vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.

CVE-2025-46607
MEDIUM 6.6

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authentication vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.

CVE-2025-43937
MEDIUM 6.6

Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an insertion of sensitive information into log file vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.

CVE-2026-107121
MEDIUM 6.5

Keycloak-services: keycloak-services: smtp starttls plaintext credential and message downgrade

CVE-2026-106585
MEDIUM 6.5

In sshd and ssh in OpenSSH before 10.6, there is no check for whether the maximum packet length is exceeded during decompression of highly compressed data.

CVE-2026-106504
MEDIUM 6.5

Backstage: Sensitive information exposure in scaffolder task logs

CVE-2026-106490
MEDIUM 6.5

Backstage: Improper input validation in TechDocs static content requests

CVE-2026-106489
MEDIUM 6.5

Backstage: Improper authorization enforcement for TechDocs static content

CVE-2026-106458
MEDIUM 6.5

Backstage: Inconsistent repository filtering in Bitbucket Server catalog event updates

CVE-2026-106386
MEDIUM 6.5

Uninitialized resource in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106312
MEDIUM 6.5

Missing authorization in SignIn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Low)

CVE-2026-106310
MEDIUM 6.5

Use of released resource in FontAccess in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-106244
MEDIUM 6.5

Incorrect authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)

CVE-2026-106242
MEDIUM 6.5

Information leak in Omnibox in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak sensitive information via crafted network traffic. (Chromium security severity: Medium)

CVE-2026-105884
MEDIUM 6.5

WordPress Rocket Lazy Load plugin <= 2.4.0 - Cross Site Scripting (XSS) vulnerability

CVE-2026-105875
MEDIUM 6.5

WordPress Prime Slider – Addons For Elementor plugin <= 4.6.2 - Cross Site Scripting (XSS) vulnerability

CVE-2026-105873
MEDIUM 6.5

WordPress Element Pack Elementor Addons plugin <= 8.8.6 - Cross Site Scripting (XSS) vulnerability

CVE-2026-105871
MEDIUM 6.5

WordPress Element Pack Elementor Addons plugin <= 8.8.6 - Cross Site Scripting (XSS) vulnerability

CVE-2026-104393
MEDIUM 6.5

WordPress Happy Addons for Elementor plugin <= 3.50.0 - Cross Site Scripting (XSS) vulnerability

CVE-2026-104391
MEDIUM 6.5

WordPress Quiz And Survey Master plugin <= 11.2.7 - Cross Site Scripting (XSS) vulnerability

CVE-2026-103869
MEDIUM 6.5

Pulp-ansible: bearer tokens are reused across remotes in a worker

CVE-2026-103868
MEDIUM 6.5

Pulp-container: registry credentials are reused across remotes in a worker

CVE-2026-103378
MEDIUM 6.5

Geliver Akıllı Kargo Pazaryeri 3.0.0 - 3.1.0 - Unauthenticated API Key Disclosure via Public Log File

CVE-2026-103008
MEDIUM 6.5

Uncontrolled Recursion in Elasticsearch Leading to Denial of Service

CVE-2026-103006
MEDIUM 6.5

Uncontrolled Recursion in Elasticsearch Leading to Denial of Service

CVE-2026-103005
MEDIUM 6.5

Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service

CVE-2026-102412
MEDIUM 6.5

Incorrect Authorization in Kibana Leading to Sensitive Information Disclosure

CVE-2026-102411
MEDIUM 6.5

Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service

CVE-2026-102409
MEDIUM 6.5

Uncontrolled Recursion in Elasticsearch Leading to Denial of Service

CVE-2026-102404
MEDIUM 6.5

Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service

CVE-2026-102375
MEDIUM 6.5

WordPress Optimole plugin <= 4.2.14 - Broken Access Control vulnerability

CVE-2026-102139
MEDIUM 6.5

Kiteworks Email Protection Gateway Incorrect Authorization

CVE-2026-101329
MEDIUM 6.5

Langflow OSS is affected by multiple vulnerabilities

CVE-2026-97671
MEDIUM 6.5

Langflow OSS is affected by multiple vulnerabilities

CVE-2026-97294
MEDIUM 6.5

WordPress Media LIbrary Assistant plugin <= 3.41 - Cross Site Scripting (XSS) vulnerability

CVE-2026-96530
MEDIUM 6.5

Optimole 4.0.0 - 4.2.14 - Subscriber+ Sensitive Data Disclosure via Dashboard Widget

CVE-2026-93448
MEDIUM 6.5

Langflow OSS is affected by multiple vulnerabilities

CVE-2026-81792
MEDIUM 6.5

WordPress Product Catalog Enquiry for WooCommerce by MultiVendorX plugin <= 6.1.5 - Privilege Escalation vulnerability

CVE-2026-81658
MEDIUM 6.5

Foreman: cross-tenant disclosure of template revisions via unauthorized audit lookup

CVE-2026-79815
MEDIUM 6.5

Authenticated Command Injection Vulnerability in the ClearPass Policy Manager OnGuard Agent

CVE-2026-76749
MEDIUM 6.5

Unauthenticated Sensitive Information Disclosure in AOS-S

CVE-2026-76741
MEDIUM 6.5

Authenticated Buffer Overflow Vulnerabilities lead to Denial-of-Service in AOS-S

CVE-2026-69147
MEDIUM 6.5

vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation

CVE-2026-62179
MEDIUM 6.5

PraisonAI: Platform members can delete owner issue dependencies through member-owned related issues

CVE-2026-58649
MEDIUM 6.5

.NET Information Disclosure Vulnerability

CVE-2026-57737
MEDIUM 6.5

WordPress Shortcodes and extra features for Phlox theme plugin <= 2.17.22 - Cross Site Scripting (XSS) vulnerability

CVE-2026-57173
MEDIUM 6.5

vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions

CVE-2026-56097
MEDIUM 6.5

Rubygem-katello: sql injection in registry proxy via labels

CVE-2026-55265
MEDIUM 6.5

In multiple functions of PduParser.java, there is a possible out of bounds read due to a missing bounds check. This could lead to a remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2026-46438
MEDIUM 6.5

wger: Cross-User Data Corruption via Missing Ownership Check on WorkoutLog.slot_entry

CVE-2026-41958
MEDIUM 6.5

A path traversal vulnerability exists in the unzip_http RemoteZipFile extract functionality of VisiData (version(s): dev (commit 38b21f78)). A specially crafted .zip file can lead to arbitrary file write. An attacker can provide a crafted URL to trigger this vulnerability.

CVE-2026-34036
MEDIUM 6.5

Dolibarr Core Discloses Sensitive Data via Authenticated Local File Inclusion in selectobject.php

CVE-2026-18180
MEDIUM 6.5

IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

CVE-2026-18179
MEDIUM 6.5

IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

CVE-2025-69363
MEDIUM 6.5

WordPress Responsive Addons for Elementor plugin <= 2.0.8 - Broken Access Control vulnerability

CVE-2025-69360
MEDIUM 6.5

WordPress TheGem Theme Elements (for WPBakery) plugin <= 5.11.0 - Cross Site Scripting (XSS) vulnerability

CVE-2025-69357
MEDIUM 6.5

WordPress TheGem Theme Elements (for Elementor) plugin <= 5.11.0 - Cross Site Scripting (XSS) vulnerability

CVE-2025-69335
MEDIUM 6.5

WordPress Team Showcase plugin <= 2.9 - Cross Site Scripting (XSS) vulnerability

CVE-2025-69334
MEDIUM 6.5

WordPress Wishlist for WooCommerce plugin <= 3.3.0 - Cross Site Scripting (XSS) vulnerability

CVE-2025-69332
MEDIUM 6.5

WordPress Bookify plugin <= 1.1.1 - Broken Access Control vulnerability

CVE-2025-69233
MEDIUM 6.5

Apache CloudStack: Domain/account resources limits not honored

CVE-2025-69197
MEDIUM 6.5

Pterodactyl TOTPs can be reused during validity window

CVE-2025-69092
MEDIUM 6.5

WordPress Essential Addons for Elementor plugin <= 6.5.3 - Cross Site Scripting (XSS) vulnerability

CVE-2025-69089
MEDIUM 6.5

WordPress Auto Listings plugin <= 2.7.1 - Cross Site Scripting (XSS) vulnerability

CVE-2025-69088
MEDIUM 6.5

WordPress Combo Offers WooCommerce plugin <= 4.2 - Cross Site Scripting (XSS) vulnerability

CVE-2025-69033
MEDIUM 6.5

WordPress Blog Filter plugin <= 1.7.3 - Cross Site Scripting (XSS) vulnerability

CVE-2025-69024
MEDIUM 6.5

WordPress BizPrint plugin <= 4.6.7 - Broken Access Control vulnerability

CVE-2025-69020
MEDIUM 6.5

WordPress Newsletters plugin <= 4.12 - Cross Site Scripting (XSS) vulnerability

CVE-2025-69018
MEDIUM 6.5

WordPress Web Directory Free plugin <= 1.7.12 - Cross Site Scripting (XSS) vulnerability

CVE-2025-69017
MEDIUM 6.5

WordPress RestroPress plugin <= 3.2.8.6 - Cross Site Scripting (XSS) vulnerability

CVE-2025-68992
MEDIUM 6.5

WordPress BWL Knowledge Base Manager plugin <= 1.6.3 - Cross Site Scripting (XSS) vulnerability

CVE-2025-68991
MEDIUM 6.5

WordPress BWL Pro Voting Manager plugin <= 1.4.9 - Cross Site Scripting (XSS) vulnerability

CVE-2025-68978
MEDIUM 6.5

WordPress DesignThemes Core plugin <= 1.6 - Cross Site Scripting (XSS) vulnerability

CVE-2025-68977
MEDIUM 6.5

WordPress DesignThemes Portfolio Addon plugin <= 1.5 - Cross Site Scripting (XSS) vulnerability

CVE-2025-68914
MEDIUM 6.5

Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/login.cgi username SQL Injection. For example, an attacker can delete the LOGINFAILEDTABLE table.

CVE-2025-68875
MEDIUM 6.5

WordPress Flaming Password Reset plugin <= 1.0.3 - Cross Site Scripting (XSS) vulnerability

CVE-2025-68868
MEDIUM 6.5

WordPress Wp Text Slider Widget plugin <= 1.0 - Cross Site Scripting (XSS) vulnerability

CVE-2025-68867
MEDIUM 6.5

WordPress Effect Maker plugin <= 1.2.1 - Cross Site Scripting (XSS) vulnerability

CVE-2025-68607
MEDIUM 6.5

WordPress Custom Field Template plugin <= 2.7.7 - Cross Site Scripting (XSS) vulnerability

CVE-2025-68605
MEDIUM 6.5

WordPress Post Grid and Gutenberg Blocks plugin <= 2.3.23 - Cross Site Scripting (XSS) vulnerability

CVE-2025-68599
MEDIUM 6.5

WordPress YouTube Embed plugin <= 5.4 - Cross Site Scripting (XSS) vulnerability

CVE-2025-68597
MEDIUM 6.5

WordPress Jobs for WordPress plugin <= 2.8.1 - Cross Site Scripting (XSS) vulnerability

CVE-2025-68533
MEDIUM 6.5

WordPress WC Builder plugin <= 1.2.0 - Cross Site Scripting (XSS) vulnerability

CVE-2025-68532
MEDIUM 6.5

WordPress ModelTheme Addons for WPBakery and Elementor plugin < 1.5.6 - Cross Site Scripting (XSS) vulnerability

CVE-2025-68528
MEDIUM 6.5

WordPress Free Shipping Bar: Amount Left for Free Shipping for WooCommerce plugin <= 2.4.9 - Cross Site Scripting (XSS) vulnerability

CVE-2025-68527
MEDIUM 6.5

WordPress Academy LMS plugin <= 3.4.0 - Cross Site Scripting (XSS) vulnerability

CVE-2025-68513
MEDIUM 6.5

WordPress Bold Timeline Lite plugin <= 1.2.7 - Cross Site Scripting (XSS) vulnerability

CVE-2025-68512
MEDIUM 6.5

WordPress Real 3D FlipBook plugin <= 4.11.4 - Cross Site Scripting (XSS) vulnerability

CVE-2025-68511
MEDIUM 6.5

WordPress Gutenverse Form plugin <= 2.3.1 - Broken Access Control vulnerability

CVE-2025-68504
MEDIUM 6.5

WordPress JetSearch plugin <= 3.5.16 - Cross Site Scripting (XSS) vulnerability

CVE-2025-68503
MEDIUM 6.5

WordPress JetBlog plugin <= 2.4.7 - Broken Access Control vulnerability

CVE-2025-68499
MEDIUM 6.5

WordPress JetTabs plugin <= 2.2.12 - Cross Site Scripting (XSS) vulnerability

CVE-2025-68498
MEDIUM 6.5

WordPress JetTabs plugin <= 2.2.12 - Broken Access Control vulnerability

CVE-2025-68431
MEDIUM 6.5

libheif has Potential Heap Buffer Over-Read

CVE-2025-68280
MEDIUM 6.5

Apache SIS: XML External Entity (XXE) vulnerability

CVE-2025-68040
MEDIUM 6.5

WordPress WP Project Manager plugin <= 3.0.1 - Sensitive Data Exposure vulnerability

CVE-2025-68014
MEDIUM 6.5

WordPress AweBooking plugin <= 3.2.26 - Sensitive Data Exposure vulnerability

CVE-2025-67926
MEDIUM 6.5

WordPress Fluent Support plugin <= 1.10.4 - Broken Access Control vulnerability

CVE-2025-67919
MEDIUM 6.5

WordPress Woffice Core plugin <= 5.4.30 - Insecure Direct Object References (IDOR) vulnerability

CVE-2025-67917
MEDIUM 6.5

WordPress Traveler theme <= 3.2.6 - Broken Access Control vulnerability

CVE-2025-67913
MEDIUM 6.5

WordPress Aruba HiSpeed Cache plugin < 3.0.3 - Broken Access Control vulnerability

CVE-2025-66171
MEDIUM 6.5

Apache CloudStack: Any user can create a new VM from backups they should not have access to

CVE-2025-66170
MEDIUM 6.5

Apache CloudStack: Any user can list backups that they should not have access to

CVE-2025-64215
MEDIUM 6.5

WordPress MasterStudy LMS Pro plugin < 4.7.16 - Broken Access Control vulnerability

CVE-2025-62473
MEDIUM 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-62463
MEDIUM 6.5

DirectX Graphics Kernel Denial of Service Vulnerability

CVE-2025-62110
MEDIUM 6.5

WordPress Rescue Shortcodes plugin <= 3.3 - Cross Site Scripting (XSS) vulnerability

CVE-2025-53847
MEDIUM 6.5

A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiOS 6.2.9 through 6.2.17 allows attacker to execute unauthorized code or commands via specially crafted packets.

CVE-2025-48768
MEDIUM 6.5

Apache NuttX RTOS: fs/inode: fs_inoderemove root inode removal

CVE-2025-47404
MEDIUM 6.5

Buffer Copy Without Checking Size of Input in Automotive Audio

CVE-2025-47403
MEDIUM 6.5

Buffer Over-read in WLAN Firmware

CVE-2025-47401
MEDIUM 6.5

Buffer Over-read in WLAN HAL

CVE-2025-47395
MEDIUM 6.5

Buffer Over-read in WLAN Firmware

CVE-2025-47374
MEDIUM 6.5

Use After Free in Camera Driver

CVE-2025-46434
MEDIUM 6.5

WordPress The Plus Addons for Elementor Pro plugin < 6.3.7 - Broken Access Control vulnerability

CVE-2025-46287
MEDIUM 6.5

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, visionOS 26.2, watchOS 26.2. An attacker may be able to spoof their FaceTime caller ID.

CVE-2025-43511
MEDIUM 6.5

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2025-42611
MEDIUM 6.5

Improper certificate validation in multiple RouterOS services

CVE-2025-41694
MEDIUM 6.5

Authenticated Denial-of-Service via Webshell

CVE-2025-39561
MEDIUM 6.5

WordPress LoginWP - Pro Plugin <= 4.0.8.5 - Broken Access Control vulnerability

CVE-2025-39497
MEDIUM 6.5

WordPress Dokan Pro plugin <= 3.14.5 - Cross Site Scripting (XSS) vulnerability

CVE-2025-36122
MEDIUM 6.5

IBM® Db2® is vulnerable to a denial of service with a specially crafted query when stmtheap is set to automatic

CVE-2025-20794
MEDIUM 6.5

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689259 / MOLY01586470; Issue ID: MSV-4847.

CVE-2025-20793
MEDIUM 6.5

In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01430930; Issue ID: MSV-4836.

CVE-2025-20762
MEDIUM 6.5

In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01685181; Issue ID: MSV-4760.

CVE-2025-20761
MEDIUM 6.5

In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01311265; Issue ID: MSV-4655.

CVE-2025-20760
MEDIUM 6.5

In Modem, there is a possible read of uninitialized heap data due to an uncaught exception. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01676750; Issue ID: MSV-4653.

CVE-2025-15659
MEDIUM 6.5

WordPress Elizaibots plugin <= 1.0.2 - Cross Site Scripting (XSS) vulnerability

CVE-2025-15636
MEDIUM 6.5

WordPress YouTube Showcase plugin <= 3.5.1 - Cross Site Scripting (XSS) vulnerability

CVE-2025-15470
MEDIUM 6.5

Eleganzo <= 1.2 - Authenticated (Subscriber+) Arbitrary Directory Deletion

CVE-2025-15463
MEDIUM 6.5

Advanced Custom Fields: Extended <= 0.9.2.3 - Unauthenticated Arbitrary Shortcode Execution

CVE-2025-14901
MEDIUM 6.5

Bit Form – Contact Form Plugin <= 2.21.6 - Missing Authorization to Unauthenticated Workflow Replay

CVE-2025-14867
MEDIUM 6.5

Flashcard Plugin for WordPress <= 0.9 - Authenticated (Contributor+) Arbitrary File Read via Path Traversal

CVE-2025-14726
MEDIUM 6.5

Widgets for Social Photo Feed <= 1.8 - Missing Authentication to Unauthenticated Plugin Settings Access/Update via trustindex_feed_hook_instagram REST API endpoints

CVE-2025-14545
MEDIUM 6.5

YML for Yandex Market < 5.0.26 - Shop Manager+ RCE via Feed Generation

CVE-2025-14512
MEDIUM 6.5

Glib: integer overflow in glib gio attribute escaping causes heap buffer overflow

CVE-2025-9637
MEDIUM 6.5

Quiz and Survey Master (QSM) <= 10.3.1 - Missing Authorization to Unpublished, Private And Password-Protected Quiz Information Disclosure And Image Response Uploads

CVE-2025-9318
MEDIUM 6.5

Quiz and Survey Master (QSM) <= 10.3.1 - Authenticated (Subscriber+) SQL Injection via `is_linking` Query Parameter

CVE-2025-5919
MEDIUM 6.5

Appointment Booking and Scheduling Calendar Plugin – WP Timetics <= 1.0.36 - Missing Authorization to Unauthenticated Booking Details View And Modification

CVE-2025-0898
MEDIUM 6.5

Xpro Elementor Addons - Pro <= 1.4.7 - Authenticated (Contributor+) Arbitrary File Read via Draw SVG

CVE-2026-107174
MEDIUM 6.4

Source-to-image: source-to-image: security boundary bypass via absolute symbolic link extraction

CVE-2026-106491
MEDIUM 6.4

Backstage: Improper input validation in proxy-backend

CVE-2026-106462
MEDIUM 6.4

Backstage: Scaffolder credential handling may allow unintended GitHub authentication fallback

CVE-2025-68936
MEDIUM 6.4

ONLYOFFICE Docs before 9.2.1 allows XSS via the Color theme name. This is related to DocumentServer.

CVE-2025-68935
MEDIUM 6.4

ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to DocumentServer.

CVE-2025-68917
MEDIUM 6.4

ONLYOFFICE Docs before 9.2.1 allows XSS in the textarea of the comment editing form. This is related to DocumentServer.

CVE-2025-46256
MEDIUM 6.4

WordPress Advanced Database Cleaner PRO Plugin <= 3.2.10 - Limited .txt Path Traversal vulnerability

CVE-2025-22726
MEDIUM 6.4

WordPress nK Themes Helper plugin <= 1.7.9 - Server Side Request Forgery (SSRF) vulnerability

CVE-2025-15058
MEDIUM 6.4

Responsive Pricing Table <= 5.1.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'table_currency'

CVE-2025-14984
MEDIUM 6.4

Gutenverse Form <= 2.3.2 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

CVE-2025-14891
MEDIUM 6.4

Customer Reviews for WooCommerce <= 5.93.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via displayName Parameter

CVE-2025-14796
MEDIUM 6.4

My Album Gallery <= 1.0.4 - Authenticated (Author+) Stored Cross-Site Scripting via Image Title

CVE-2025-13535
MEDIUM 6.4

King Addons for Elementor <= 51.1.38 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Multiple Widgets

CVE-2025-13364
MEDIUM 6.4

WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.8.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'put_wpgm' Shortcode

CVE-2025-9878
MEDIUM 6.4

Password Protect WordPress Lite <= 1.9.21 - Authenticated (Contributor+) Stored Cross-Site Scripting

CVE-2025-9016
MEDIUM 6.4

Mechrevo Control Center GX V2 Powershell Script Command uncontrolled search path

CVE-2025-9000
MEDIUM 6.4

Mechrevo Control Center GX V2 reg File uncontrolled search path

CVE-2025-4776
MEDIUM 6.4

Phlox <= 2.17.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via `data-caption` HTML Attribute

CVE-2026-106559
MEDIUM 6.3

Backstage: Improper input validation in Confluence to Markdown scaffolder module

CVE-2026-106064
MEDIUM 6.3

Gimp: gimp: heap buffer overflow in gif export on oversized image dimensions

CVE-2026-106063
MEDIUM 6.3

Gimp: gimp: heap buffer overflow in dicom export on oversized image dimensions

CVE-2026-81535
MEDIUM 6.3

wolfSSH SSH client accepts unsolicited forwarded-tcpip channel opens without an authorization check

CVE-2026-79816
MEDIUM 6.3

Unauthenticated DOM-Based Cross-Site Scripting (XSS) Vulnerability in the ClearPass Policy Manager Client Interface

CVE-2025-69205
MEDIUM 6.3

In µURU, a Specially Crafted Federation Name Allows Dialplan Injection

CVE-2025-69203
MEDIUM 6.3

Signal K Server Vulnerable to Access Request Spoofing

CVE-2025-68029
MEDIUM 6.3

WordPress Wallet System for WooCommerce plugin <= 2.7.3 - Sensitive Data Exposure vulnerability

CVE-2025-66483
MEDIUM 6.3

Multiple vulnerabilities have been addressed in IBM Aspera Shares

CVE-2025-62233
MEDIUM 6.3

Apache DolphinScheduler: Deserialization of untrusted data in RPC

CVE-2025-61669
MEDIUM 6.3

jupyter_server next parameter open redirect can redirect users to external domains

CVE-2025-58441
MEDIUM 6.3

Knowage is vulnerable to blind server-side request forgery (SSRF)

CVE-2025-52601
MEDIUM 6.3

Hardcoding sensitive information

CVE-2025-52599
MEDIUM 6.3

Inadequate account permissions management

CVE-2025-52598
MEDIUM 6.3

Insufficient certificate validation

CVE-2025-15612
MEDIUM 6.3

Wazuh Provisioning Scripts / Build Infrastructure Improper Certificate Validation leading to MITM and RCE

CVE-2025-10262
MEDIUM 6.3

An unsanitized format validation vulnerability in Nokia SR Linux

CVE-2025-9912
MEDIUM 6.3

A local privilege escalation vulnerability in Nokia SR Linux

CVE-2026-107169
MEDIUM 6.2

M17n-lib: null-pointer write in read_mtext_element() on malformed utf-8

CVE-2026-107168
MEDIUM 6.2

M17n-lib: parser infinite loop on malformed utf-8 in count_utf_8_chars()

CVE-2026-107167
MEDIUM 6.2

M17n-lib: heap use-after-free write in re_init_ic()

CVE-2026-104046
MEDIUM 6.2

Sssd: sssd: denial of service via incomplete identity provider authentication requests

CVE-2026-102413
MEDIUM 6.2

Uncaught Exception in Elastic Endpoint Leading to Denial of Service

CVE-2026-101156
MEDIUM 6.2

Security Advisory 0192

CVE-2026-19267
MEDIUM 6.2

IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

CVE-2025-46606
MEDIUM 6.2

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper restriction of excessive authentication attempts vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.

CVE-2025-46605
MEDIUM 6.2

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain a session fixation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.

CVE-2025-36335
MEDIUM 6.2

Vulnerabilities found

CVE-2025-36154
MEDIUM 6.2

IBM Concert Software Cleartext Storage in a File or on Disk.

CVE-2025-15622
MEDIUM 6.2

Sparx Enterprise Architect Client reveals plaintext OAuth2 client secret

CVE-2026-106324
MEDIUM 6.1

Incorrect authorization in WebAppInstalls in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-102258
MEDIUM 6.1

Post-authentication Stored Cross-Site Scripting (XSS) vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to store and potentially execute arbitrary JavaScript code in the Appliance Management Console (AMC).

CVE-2026-93026
MEDIUM 6.1

This vulnerability in Veeam Backup & Replication allows a Backup Viewer to modify the Enterprise Manager master key and stored antivirus update credentials.

CVE-2026-83589
MEDIUM 6.1

Oauth-proxy: open redirect via /\ and /\t bypass in post-login redirect

CVE-2026-79812
MEDIUM 6.1

Authenticated Local Denial-of-Service Vulnerability in the OnGuard Agent of ClearPass Policy Manager

CVE-2025-68474
MEDIUM 6.1

ESF-IDF Has Out-of-Bounds Write in ESP32 Bluetooth AVRCP Vendor Command Handling

CVE-2025-66593
MEDIUM 6.1

An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.

CVE-2025-66592
MEDIUM 6.1

An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.

CVE-2025-65954
MEDIUM 6.1

SimpleSAMLphp-casserver has an Open Redirect vulnerability via logout

CVE-2025-65442
MEDIUM 6.1

DOM-based Cross-Site Scripting (XSS) vulnerability in 201206030 novel V3.5.0 allows remote attackers to execute arbitrary JavaScript code or disclose sensitive information (e.g., user session cookies) via a crafted "wvstest" parameter in the URL or malicious script injection into window.localStorage. The vulnerability arises from insufficient validation and encoding of user-controllable data in the book comment module: unfiltered user input is stored in the backend database (book_comment table, commentContent field) and returned via API, then rendered directly into the page DOM via Vue 3's v-html directive without sanitization. Even if modern browsers' built-in XSS filters block pop-up alerts, attackers can use concealed payloads to bypass interception and achieve actual harm.

CVE-2025-60935
MEDIUM 6.1

An open redirect vulnerability in the login endpoint of Blitz Panel v1.17.0 allows attackers to redirect users to malicious domains via a crafted URL. This issue affects the next_url parameter in the login endpoint and could lead to phishing or token theft after successful authentication.

CVE-2025-55060
MEDIUM 6.1

Priority - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

CVE-2025-47406
MEDIUM 6.1

Buffer Over-read in DSP Service

CVE-2025-47331
MEDIUM 6.1

Buffer Over-read in Video

CVE-2025-15345
MEDIUM 6.1

MapGeo - Interactive Geo Maps <= 1.6.27 - Reflected Cross-Site Scripting via 'map' Parameter

CVE-2025-14875
MEDIUM 6.1

HBLPAY Payment Gateway for WooCommerce <= 5.0.0 - Reflected Cross-Site Scripting via 'cusdata' Parameter

CVE-2025-14842
MEDIUM 6.1

Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.9.2 - Unauthenticated Limited Arbitrary File Upload

CVE-2025-14313
MEDIUM 6.1

Advance WP Query Search Filter <= 1.0.10 - Reflected XSS via taxo_ajax

CVE-2025-14312
MEDIUM 6.1

Advance WP Query Search Filter <= 1.0.10 - Reflected XSS via counter

CVE-2025-13593
MEDIUM 6.1

Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.

CVE-2025-10503
MEDIUM 6.1

Reflected Cross-Site Scripting via Authentication Endpoint in WSO2 Identity Server

CVE-2026-102157
MEDIUM 6

Security Advisory 0190

CVE-2025-69202
MEDIUM 6

axios-cache-interceptor Vulnerable to Cache Poisoning via Ignored HTTP Vary Header

CVE-2025-14175
MEDIUM 6

Weak Algorithm Support in SSH Server on TL-WR820N

CVE-2025-12624
MEDIUM 6

Improper Token Invalidation in WSO2 Identity Server Allows Access After Account Lock

CVE-2025-9290
MEDIUM 6

Authentication Weakness on Omada Controllers, Gateways and Access Points

CVE-2026-107151
MEDIUM 5.9

Rubygem-smart_proxy_dynflow: task update and done callbacks accept unauthenticated requests

CVE-2026-106328
MEDIUM 5.9

Incorrect authorization in PDF in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker leveraging social engineering to obtain sensitive information via a co-installed app. (Chromium security severity: Medium)

CVE-2026-106222
MEDIUM 5.9

Incorrect authorization in Sync in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium)

CVE-2026-103323
MEDIUM 5.9

Integration for Epos Now and WooCommerce 4.6.0 - 4.11.1 - Unauthenticated Action Scheduler Queue Disclosure

CVE-2025-69362
MEDIUM 5.9

WordPress UiChemy plugin <= 4.4.2 - Cross Site Scripting (XSS) vulnerability

CVE-2025-69350
MEDIUM 5.9

WordPress Accordion plugin <= 3.0.3 - Cross Site Scripting (XSS) vulnerability

CVE-2025-69008
MEDIUM 5.9

WordPress Inboxify Sign Up Form plugin <= 1.0.4 - Cross Site Scripting (XSS) vulnerability

CVE-2025-69007
MEDIUM 5.9

WordPress Popping Sidebars and Widgets Light plugin <= 1.27 - Cross Site Scripting (XSS) vulnerability

CVE-2025-69006
MEDIUM 5.9

WordPress AM Events plugin <= 1.13.1 - Cross Site Scripting (XSS) vulnerability

CVE-2025-68574
MEDIUM 5.9

WordPress WPBakery Visual Composer WHMCS Elements plugin <= 1.0.4.3 - Cross Site Scripting (XSS) vulnerability

CVE-2025-68566
MEDIUM 5.9

WordPress My auctions allegro plugin <= 3.6.35 - Cross Site Scripting (XSS) vulnerability

CVE-2025-68525
MEDIUM 5.9

WordPress Category Icon plugin <= 1.0.2 - Cross Site Scripting (XSS) vulnerability

CVE-2025-68497
MEDIUM 5.9

WordPress Astra Widgets plugin <= 1.2.16 - Cross Site Scripting (XSS) vulnerability

CVE-2025-67633
MEDIUM 5.9

WordPress Greenhouse Job Board plugin <= 2.7.3 - Cross Site Scripting (XSS) vulnerability

CVE-2025-67632
MEDIUM 5.9

WordPress Google AdSense for Responsive Design – GARD plugin <= 2.23 - Cross Site Scripting (XSS) vulnerability

CVE-2025-67631
MEDIUM 5.9

WordPress Gift Hunt plugin <= 2.0.2 - Cross Site Scripting (XSS) vulnerability

CVE-2025-67630
MEDIUM 5.9

WordPress WH Tweaks plugin <= 1.0.2 - Cross Site Scripting (XSS) vulnerability

CVE-2025-67629
MEDIUM 5.9

WordPress Basticom Framework plugin <= 1.5.2 - Cross Site Scripting (XSS) vulnerability

CVE-2025-67628
MEDIUM 5.9

WordPress Review Disclaimer plugin <= 2.0.3 - Cross Site Scripting (XSS) vulnerability

CVE-2025-67627
MEDIUM 5.9

WordPress Draft Notify plugin <= 1.5 - Cross Site Scripting (XSS) vulnerability

CVE-2025-66560
MEDIUM 5.9

Quarkus REST has potential worker thread starvation when HTTP connection is closed while waiting to write

CVE-2025-66378
MEDIUM 5.9

Pexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacker to disconnect RTMP streams traversing a Proxy Node.

CVE-2025-63083
MEDIUM 5.9

Joomla! Core - [20260102] - XSS vector in the pagebreak plugin

CVE-2025-63082
MEDIUM 5.9

Joomla! Core - [20260101] - Inadequate content filtering for data URLs

CVE-2025-62127
MEDIUM 5.9

WordPress WEN Logo Slider plugin <= 3.4.0 - Cross Site Scripting (XSS) vulnerability

CVE-2025-49088
MEDIUM 5.9

Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join, has Improper Input Validation in the OTJ service, allowing a remote attacker to trigger a software abort via a crafted calendar invite, leading to a denial of service.

CVE-2025-15658
MEDIUM 5.9

WordPress WP Emmet plugin <= 0.3.4 - Cross Site Scripting (XSS) vulnerability

CVE-2025-13958
MEDIUM 5.9

YaMaps < 0.6.40 - Contributor+ Stored XSS

CVE-2025-13916
MEDIUM 5.9

Multiple vulnerabilities have been addressed in IBM Aspera Shares

CVE-2025-10466
MEDIUM 5.9

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Safe Access in Synology Safe Access before 1.3.1-0329 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information or conduct limited denial-of-service in SRM.

CVE-2025-8307
MEDIUM 5.9

Recoverable passwords in Asseco Infomedica Plus

CVE-2025-1721
MEDIUM 5.9

BM Concert Software Improper Clearing of Heap Memory Before Release.

CVE-2025-8075
MEDIUM 5.8

Improper Input Validation

CVE-2025-1241
MEDIUM 5.8

Encryption vulnerable to brute-force decryption in GoAnywhere MFT

CVE-2026-106032
MEDIUM 5.7

Server-side request forgery and local file read via unrestricted external OpenAPI reference resolution in Bedrock AgentCore Starter Toolkit agent import

CVE-2025-59955
MEDIUM 5.7

Coolify leaksensitive information `email_change_code` in `/api/v1/teams/{team_id | current}/members` API endpoint

CVE-2025-43533
MEDIUM 5.7

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. A malicious HID device may cause an unexpected process crash.

CVE-2025-24819
MEDIUM 5.7

A Relative Path Traversal vulnerability in Nokia MantaRay NM

CVE-2025-15621
MEDIUM 5.7

Sparx Enterprise Architect Client does not verify the receiver of OAuth2 credentials during OpenID authentication

CVE-2025-68919
MEDIUM 5.6

Fujitsu / Fsas Technologies ETERNUS SF ACM/SC/Express (DX / AF Management Software) before 16.8-16.9.1 PA 2025-12, when collected maintenance data is accessible by a principal/authority other than ETERNUS SF Admin, allows an attacker to potentially affect system confidentiality, integrity, and availability.

CVE-2025-7064
MEDIUM 5.6

Freelance Security Lock – Access to Windows OS

CVE-2026-106061
MEDIUM 5.5

Gimp: gimp: heap buffer over-read in x cursor (xmc) thumbnail loader on crafted file

CVE-2026-79817
MEDIUM 5.5

Local Disclosure of Sensitive Information in HPE Networking ClearPass Policy Manager Client Software

CVE-2026-76061
MEDIUM 5.5

Cri-o: cri-o: bind_mount_prefix intermediate-symlink prefix bypass

CVE-2026-70414
MEDIUM 5.5

Dell Command | Configure (DCC), versions prior to 5.2.3.35, contain a Plaintext Storage of Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.

CVE-2026-65122
MEDIUM 5.5

NVIDIA TensorRT contains a vulnerability where an attacker can cause an out of bounds read. A successful exploit of this vulnerability may lead to denial of service.

CVE-2026-58834
MEDIUM 5.5

In setPermissionGrantState of DevicePolicyManagerService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2026-46571
MEDIUM 5.5

In NTFS-3G before 2026.7.7, a out-of-bounds read exists in ntfs_fix_file_name() in libntfs-3g/reparse.c that allows an attacker to read possibly confidential information in ntfs-3g process memory by crafting a malicious NTFS image. The out-of-bounds read is triggered by a readlink on a corrupted file.

CVE-2026-42532
MEDIUM 5.5

A path traversal vulnerability exists in the EmailSheet extract_parts functionality of VisiData (version(s): dev (commit 38b21f78)). A specially crafted .eml file can lead to arbitrary file write. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2026-28667
MEDIUM 5.5

In multiple functions of rw_t5t.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2025-68915
MEDIUM 5.5

Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/loginbanner_w.cgi XSS via a crafted banner.

CVE-2025-66484
MEDIUM 5.5

Multiple vulnerabilities have been addressed in IBM Aspera Shares

CVE-2025-64422
MEDIUM 5.5

Rate-limit bypass on login via X-Forwarded-Host header

CVE-2025-62468
MEDIUM 5.5

Windows Defender Firewall Service Information Disclosure Vulnerability

CVE-2025-62224
MEDIUM 5.5

Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability

CVE-2025-47369
MEDIUM 5.5

Information Exposure in Computer Vision

CVE-2025-47330
MEDIUM 5.5

Buffer Over-read in Video

CVE-2025-46313
MEDIUM 5.5

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.

CVE-2025-46293
MEDIUM 5.5

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.

CVE-2025-46288
MEDIUM 5.5

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, watchOS 26.2. An app may be able to access sensitive payment tokens.

CVE-2025-46276
MEDIUM 5.5

An information disclosure issue was addressed with improved privacy controls. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, visionOS 26.2, watchOS 26.2. An app may be able to access sensitive user data.

CVE-2025-43538
MEDIUM 5.5

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sonoma 14.8.3, macOS Tahoe 26.2, visionOS 26.2, watchOS 26.2. An app may be able to access sensitive user data.

CVE-2025-43520
MEDIUM 5.5

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may be able to cause unexpected system termination or write kernel memory.

CVE-2025-43339
MEDIUM 5.5

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. A malicious app may be able to access sensitive user data.

CVE-2025-43278
MEDIUM 5.5

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.

CVE-2025-36074
MEDIUM 5.5

Security vulnerability has been detected in IBM Security Verify Directory

CVE-2025-30459
MEDIUM 5.5

A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.

CVE-2025-30431
MEDIUM 5.5

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to access private information.

CVE-2025-24268
MEDIUM 5.5

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.

CVE-2025-24165
MEDIUM 5.5

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause unexpected system termination.

CVE-2025-15458
MEDIUM 5.5

bg5sbk MiniCMS Article post-edit.php improper authentication

CVE-2025-15457
MEDIUM 5.5

bg5sbk MiniCMS Trash File Restore post.php improper authentication

CVE-2025-15456
MEDIUM 5.5

bg5sbk MiniCMS Publish page-edit.php improper authentication

CVE-2025-15455
MEDIUM 5.5

bg5sbk MiniCMS File Recovery Request page.php delete_page improper authentication

CVE-2025-15436
MEDIUM 5.5

Yonyou KSOA work_edit.jsp sql injection

CVE-2025-15435
MEDIUM 5.5

Yonyou KSOA work_update.jsp sql injection

CVE-2025-15434
MEDIUM 5.5

Yonyou KSOA PrintZPYG.jsp sql injection

CVE-2025-15432
MEDIUM 5.5

yeqifu carRental com.yeqifu.sys.controller.FileController downloadShowFile.action downloadShowFile path traversal

CVE-2025-15425
MEDIUM 5.5

Yonyou KSOA HTTP GET Parameter del_user.jsp sql injection

CVE-2025-15424
MEDIUM 5.5

Yonyou KSOA HTTP GET Parameter agent_worksdel.jsp sql injection

CVE-2025-15422
MEDIUM 5.5

EmpireSoft EmpireCMS IP Address connect.php egetip protection mechanism

CVE-2025-15421
MEDIUM 5.5

Yonyou KSOA HTTP GET Parameter agent_worksadd.jsp sql injection

CVE-2025-15420
MEDIUM 5.5

Yonyou KSOA agent_work_report.jsp sql injection

CVE-2025-15410
MEDIUM 5.5

code-projects Online Guitar Store login.php sql injection

CVE-2025-15409
MEDIUM 5.5

code-projects Online Guitar Store Delete_product.php sql injection

CVE-2025-15408
MEDIUM 5.5

code-projects Online Guitar Store Create_product.php sql injection

CVE-2025-15407
MEDIUM 5.5

code-projects Online Guitar Store Create_category.php sql injection

CVE-2025-15247
MEDIUM 5.5

gmg137 snap7-rs client.rs download heap-based overflow

CVE-2025-15243
MEDIUM 5.5

code-projects Simple Stock System login.php sql injection

CVE-2025-15229
MEDIUM 5.5

Tenda CH22 DhcpListClient fromDhcpListClient denial of service

CVE-2025-15208
MEDIUM 5.5

code-projects Refugee Food Management System editrefugee.php sql injection

CVE-2025-15207
MEDIUM 5.5

Campcodes Supplier Management System view_products.php sql injection

CVE-2025-15206
MEDIUM 5.5

Campcodes Supplier Management System add_area.php sql injection

CVE-2025-15198
MEDIUM 5.5

code-projects College Notes Uploading System login.php sql injection

CVE-2025-15196
MEDIUM 5.5

code-projects Assessment Management login.php sql injection

CVE-2025-15195
MEDIUM 5.5

code-projects Assessment Management add-module.php sql injection

CVE-2025-15186
MEDIUM 5.5

code-projects Refugee Food Management System addusers.php sql injection

CVE-2025-15185
MEDIUM 5.5

code-projects Refugee Food Management System refugeesreport.php sql injection

CVE-2025-15184
MEDIUM 5.5

code-projects Refugee Food Management System refugeesreport2.php sql injection

CVE-2025-15183
MEDIUM 5.5

code-projects Refugee Food Management System viewtakenfd.php sql injection

CVE-2025-15182
MEDIUM 5.5

code-projects Refugee Food Management System served.php sql injection

CVE-2025-15181
MEDIUM 5.5

code-projects Refugee Food Management System pagenateRefugeesList.php sql injection

CVE-2025-15168
MEDIUM 5.5

itsourcecode Student Management System statistical.php sql injection

CVE-2025-15167
MEDIUM 5.5

itsourcecode Online Cake Ordering System detailtransac.php sql injection

CVE-2025-15166
MEDIUM 5.5

itsourcecode Online Cake Ordering System updatesupplier.php sql injection

CVE-2025-15165
MEDIUM 5.5

itsourcecode Online Cake Ordering System updatecustomer.php sql injection

CVE-2025-15142
MEDIUM 5.5

9786 phpok3w show.php sql injection

CVE-2025-15140
MEDIUM 5.5

saiftheboss7 onlinemcqexam quesadd.php sql injection

CVE-2025-15128
MEDIUM 5.5

ZKTeco BioTime Endpoint safe_setting credentials storage

CVE-2025-15127
MEDIUM 5.5

FantasticLBP Hotels_Server Room.php sql injection

CVE-2025-15109
MEDIUM 5.5

jackq XCMS upload.php unrestricted upload

CVE-2025-15099
MEDIUM 5.5

simstudioai sim CRON Secret internal.ts improper authentication

CVE-2025-15082
MEDIUM 5.5

TOZED ZLT M30s Web Management proc_post information disclosure

CVE-2025-15078
MEDIUM 5.5

itsourcecode Student Management System list_report.php sql injection

CVE-2025-15077
MEDIUM 5.5

itsourcecode Student Management System form137.php sql injection

CVE-2025-15076
MEDIUM 5.5

Tenda CH22 public path traversal

CVE-2025-15075
MEDIUM 5.5

itsourcecode Student Management System student_p.php sql injection

CVE-2025-15074
MEDIUM 5.5

itsourcecode Online Frozen Foods Ordering System customer_details.php sql injection

CVE-2025-15073
MEDIUM 5.5

itsourcecode Online Frozen Foods Ordering System contact_us.php sql injection

CVE-2025-14767
MEDIUM 5.5

WPC Badge Management for WooCommerce <= 3.1.6 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'text' Attribute

CVE-2025-7019
MEDIUM 5.5

Avast antivirus stack overflow when scanning a malformed Office Open XML file

CVE-2025-7018
MEDIUM 5.5

Avira antivirus engine null pointer dereference when scanning a malformed PE file

CVE-2025-7010
MEDIUM 5.5

Avast antivirus stack overflow when scanning a malformed PDF file

CVE-2025-7006
MEDIUM 5.5

Avast antivirus use of stack memory after free when scanning a malformed PE file

CVE-2025-7005
MEDIUM 5.5

Avast antivirus infinite recursion when scanning a malformed PE file

CVE-2026-106463
MEDIUM 5.4

Backstage: Improper authorization in GitLab organizational user ingestion

CVE-2026-106420
MEDIUM 5.4

Incorrect calculation in API in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted Chrome extension. (Chromium security severity: Medium)

CVE-2026-106416
MEDIUM 5.4

Code injection in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted Chrome extension. (Chromium security severity: Medium)

CVE-2026-106406
MEDIUM 5.4

Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106400
MEDIUM 5.4

Clickjacking in Messages in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106380
MEDIUM 5.4

UI misrepresentation in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-106356
MEDIUM 5.4

Clickjacking in EVP in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106343
MEDIUM 5.4

Improper state validation in Autofill AI in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-106338
MEDIUM 5.4

UI misrepresentation in PictureInPicture in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-106337
MEDIUM 5.4

UI misrepresentation in UI in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106333
MEDIUM 5.4

Incorrect authorization in Input in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106317
MEDIUM 5.4

UI misrepresentation in FullScreen in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-106316
MEDIUM 5.4

UI misrepresentation in Chromoting in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic. (Chromium security severity: Low)

CVE-2026-106311
MEDIUM 5.4

Clickjacking in PermissionElement in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106305
MEDIUM 5.4

UI misrepresentation in Mobile in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-106302
MEDIUM 5.4

UI misrepresentation in PermissionElement in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106285
MEDIUM 5.4

UI misrepresentation in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-106282
MEDIUM 5.4

UI misrepresentation in WebOTP in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106276
MEDIUM 5.4

UI misrepresentation in Payments in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-106270
MEDIUM 5.4

Incorrect authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-106265
MEDIUM 5.4

UI misrepresentation in File in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106264
MEDIUM 5.4

Missing authorization in Web Authentication (Passkeys & Security Keys) in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-106251
MEDIUM 5.4

UI misrepresentation in Chromoting in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic. (Chromium security severity: Low)

CVE-2026-106250
MEDIUM 5.4

Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-106246
MEDIUM 5.4

Incorrect authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106236
MEDIUM 5.4

UI misrepresentation in Chromoting in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic. (Chromium security severity: Low)

CVE-2026-106232
MEDIUM 5.4

UI misrepresentation in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106033
MEDIUM 5.4

Ansible: ansible-ui: ansible ui dom xss in /redirect next parameter

CVE-2026-102407
MEDIUM 5.4

Incorrect Authorization in Elasticsearch Leading to Unauthorized Data Stream Modification

CVE-2026-102134
MEDIUM 5.4

Kiteworks Core Unprotected Alternate Channel

CVE-2026-90462
MEDIUM 5.4

Sssd: sssd: fail-open in ldap ppolicy access check allows continued authorization

CVE-2026-89182
MEDIUM 5.4

Gitea push-to-create bypass of FORCE_PRIVATE policy

CVE-2026-86833
MEDIUM 5.4

MetForm < 4.3.1 - Unauthenticated HTML Injection in Notification Emails via Field Shortcodes

CVE-2026-81164
MEDIUM 5.4

Entity PDF - Moderately critical - Access bypass - SA-CONTRIB-2026-114

CVE-2026-45161
MEDIUM 5.4

wger: trainer_login accepts GET - CSRF bypass enables forced session rebinding

CVE-2026-18505
MEDIUM 5.4

IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

CVE-2025-69352
MEDIUM 5.4

WordPress The Events Calendar plugin <= 6.15.12.2 - Broken Access Control vulnerability

CVE-2025-69349
MEDIUM 5.4

WordPress RSS Feed Widget plugin <= 3.0.2 - Broken Access Control vulnerability

CVE-2025-69341
MEDIUM 5.4

WordPress WeDesignTech Ultimate Booking Addon plugin <= 1.0.3 - Broken Access Control vulnerability

CVE-2025-69169
MEDIUM 5.4

WordPress Easy Media Download plugin <= 1.1.11 - CSS Injection vulnerability

CVE-2025-69032
MEDIUM 5.4

WordPress FiveStar theme <= 1.7 - Insecure Direct Object References (IDOR) vulnerability

CVE-2025-69030
MEDIUM 5.4

WordPress Backpack Traveler theme <= 2.10.3 - Insecure Direct Object References (IDOR) vulnerability

CVE-2025-69029
MEDIUM 5.4

WordPress Struktur theme <= 2.5.1 - Insecure Direct Object References (IDOR) vulnerability

CVE-2025-69022
MEDIUM 5.4

WordPress HR Management Lite plugin <= 3.6 - Broken Access Control vulnerability

CVE-2025-69021
MEDIUM 5.4

WordPress Popup box plugin <= 6.0.7 - Cross Site Request Forgery (CSRF) vulnerability

CVE-2025-68998
MEDIUM 5.4

WordPress Heateor Social Login plugin <= 1.1.39 - Cross Site Request Forgery (CSRF) vulnerability

CVE-2025-68976
MEDIUM 5.4

WordPress Eagle Booking plugin <= 1.3.4.3 - Settings Change vulnerability

CVE-2025-68951
MEDIUM 5.4

phpMyFAQ has stored XSS in admin "List of users" via display_name HTML entity decoding (html_entity_decode) + Twig |raw

CVE-2025-68928
MEDIUM 5.4

Frappe CRM vulnerable to authenticated XSS via website field

CVE-2025-68603
MEDIUM 5.4

WordPress Editorial Calendar plugin <= 3.8.8 - Broken Access Control vulnerability

CVE-2025-68601
MEDIUM 5.4

WordPress Five Star Restaurant Reservations plugin <= 2.7.8 - Cross Site Request Forgery (CSRF) vulnerability

CVE-2025-68593
MEDIUM 5.4

WordPress WP Adminify plugin <= 4.0.6.1 - Broken Access Control vulnerability

CVE-2025-68591
MEDIUM 5.4

WordPress Simple File List plugin <= 6.1.18 - Broken Access Control vulnerability

CVE-2025-68581
MEDIUM 5.4

WordPress YITH Slider for page builders plugin <= 1.0.11 - Broken Access Control vulnerability

CVE-2025-68573
MEDIUM 5.4

WordPress Simple Keyword to Link plugin <= 1.5 - Cross Site Request Forgery (CSRF) vulnerability

CVE-2025-68567
MEDIUM 5.4

WordPress My auctions allegro plugin <= 3.6.33 - Cross Site Request Forgery (CSRF) vulnerability

CVE-2025-68517
MEDIUM 5.4

WordPress Tablesome plugin <= 1.1.35.1 - Broken Access Control vulnerability

CVE-2025-67623
MEDIUM 5.4

WordPress 6Storage Rentals plugin <= 2.22.0 - Server Side Request Forgery (SSRF) vulnerability

CVE-2025-66485
MEDIUM 5.4

Multiple vulnerabilities have been addressed in IBM Aspera Shares

CVE-2025-62313
MEDIUM 5.4

HCL AION is affected by a vulnerability where adequate protections against brute-force attempts are not enforced.

CVE-2025-62310
MEDIUM 5.4

HCL AION is affected by a vulnerability where encryption is not enforced for certain data transmissions or operations

CVE-2025-36230
MEDIUM 5.4

XSS in IBM Aspera Faspex

CVE-2025-15611
MEDIUM 5.4

Popup Box AYS Pro < 5.5.0 - Admin+ Stored Cross-Site Scripting (XSS) via CSRF

CVE-2025-14802
MEDIUM 5.4

LearnPress – WordPress LMS Plugin <= 4.3.2.2 - Insecure Direct Object Reference to Authenticated (Instructor+) Teacher Material Deletion

CVE-2025-13167
MEDIUM 5.4

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functionality in Synology Contacts before 1.0.10-20659 allows remote authenticated users to read or write specific files containing non-sensitive information via unspecified vectors.

CVE-2025-2154
MEDIUM 5.4

Stored XSS in EchoCCS's Specto CM

CVE-2026-107175
MEDIUM 5.3

MISP Correlation Engine Fails to Refresh When Event Distribution or Sharing Group Changes

CVE-2026-106563
MEDIUM 5.3

Backstage: Improper entity validation in deprecated Kubernetes services endpoint

CVE-2026-106508
MEDIUM 5.3

Backstage: Potential file exposure through local TechDocs publisher

CVE-2026-106507
MEDIUM 5.3

Backstage: TechDocs arbitrary file read via mkdocs snippets

CVE-2026-106506
MEDIUM 5.3

Backstage: Improper input validation in scaffolder task list ordering

CVE-2026-106502
MEDIUM 5.3

Backstage: Sensitive information may be exposed in Scaffolder task failure events

CVE-2026-106453
MEDIUM 5.3

yawkat LZ4 Java: LZ4DecompressorWithLength allocates the unvalidated size from the 4-byte length header, so a 5-byte input triggers a 1 GiB allocation and OutOfMemoryError

CVE-2026-106452
MEDIUM 5.3

yawkat LZ4 Java: LZ4BlockInputStream allocates an unvalidated compressed length from the stream header

CVE-2026-106450
MEDIUM 5.3

yawkat LZ4 Java: LZ4FrameInputStream reallocates block buffers for every frame, allowing CPU and GC amplification from small inputs

CVE-2026-106388
MEDIUM 5.3

Missing authorization in DataTransfer in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106303
MEDIUM 5.3

Observable discrepancy in Autofill AI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106243
MEDIUM 5.3

Incomplete cleanup in Proxy Auth in Google Chrome prior to 155.0.8059.39 allowed an adjacent attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: High)

CVE-2026-105876
MEDIUM 5.3

WordPress Modula Image Gallery plugin <= 3.0.11 - Sensitive Data Exposure vulnerability

CVE-2026-105322
MEDIUM 5.3

Magee Shortcodes <= 2.1.1 - Unauthenticated Mail Relay via Contact Form

CVE-2026-105244
MEDIUM 5.3

Apache log4net: RemoteSyslogAppender silently deletes non-ASCII content

CVE-2026-105243
MEDIUM 5.3

Apache log4net: Oversize EventLogAppender record silently discarded

CVE-2026-105242
MEDIUM 5.3

Apache log4net: Request validation failure drops the event in the aspnet-request converter

CVE-2026-105241
MEDIUM 5.3

Apache log4net: Unencodable content discards a whole SmtpPickupDirAppender batch

CVE-2026-105240
MEDIUM 5.3

Apache log4net: NUL character truncates OutputDebugStringAppender records

CVE-2026-105239
MEDIUM 5.3

Apache log4net: NUL character truncates EventLogAppender records

CVE-2026-105139
MEDIUM 5.3

Obot 0.26.0 before 0.26.2 Authorization Bypass via vMCP Profile Prompts and Resources

CVE-2026-104047
MEDIUM 5.3

Sssd: sssd: information disclosure via query injection in entra id lookups

CVE-2026-102144
MEDIUM 5.3

Kiteworks Email Protection Gateway Uncontrolled Resource Consumption

CVE-2026-101151
MEDIUM 5.3

Security Advisory 0187

CVE-2026-86816
MEDIUM 5.3

WPCafe < 3.0.21 - Unauthenticated Product Data Disclosure via REST API

CVE-2026-83742
MEDIUM 5.3

wstrncat() unsigned integer underflow leads to an off-by-one null write in wolfSSH on non-Windows platforms

CVE-2026-79818
MEDIUM 5.3

Authentication Bypass in the API Interface Allows Unauthorized Information Disclosure in ClearPass Policy Manager

CVE-2026-77121
MEDIUM 5.3

Nexus Repository 3 - Denial of Service via Unbounded Maven POM Metadata Fields

CVE-2026-75036
MEDIUM 5.3

Fleet: DNS exfiltration via Sprig getHostByName in fleet.yaml Helm template preprocessing

CVE-2026-30959
MEDIUM 5.3

OneUptime has WhatsApp Resend Verification Authorization Bypass

CVE-2026-27434
MEDIUM 5.3

WordPress WP Rentals theme <= 3.14.2 - Broken Access Control vulnerability

CVE-2026-12542
MEDIUM 5.3

Foreman: command injection in foreman-tail

CVE-2025-69364
MEDIUM 5.3

WordPress Breeze plugin <= 2.2.21 - Broken Access Control vulnerability

CVE-2025-69359
MEDIUM 5.3

WordPress Creator LMS plugin <= 1.1.12 - Broken Access Control vulnerability

CVE-2025-69093
MEDIUM 5.3

WordPress ShopMagic plugin <= 4.7.2 - Broken Access Control vulnerability

CVE-2025-69031
MEDIUM 5.3

WordPress Arcane theme <= 3.6.6 - Broken Access Control vulnerability

CVE-2025-69028
MEDIUM 5.3

WordPress weForms plugin <= 1.6.25 - Broken Access Control vulnerability

CVE-2025-69027
MEDIUM 5.3

WordPress Product Delivery Date for WooCommerce – Lite plugin <= 3.2.0 - Broken Access Control vulnerability

CVE-2025-69010
MEDIUM 5.3

WordPress Themebeez Toolkit plugin <= 1.3.5 - Broken Access Control vulnerability

CVE-2025-69009
MEDIUM 5.3

WordPress Medicalequipment theme <= 1.0.9 - Broken Access Control vulnerability

CVE-2025-68997
MEDIUM 5.3

WordPress wpDiscuz plugin <= 7.6.43 - Insecure Direct Object References (IDOR) vulnerability

CVE-2025-68994
MEDIUM 5.3

WordPress Product Loops for WooCommerce plugin <= 2.1.2 - Broken Access Control vulnerability

CVE-2025-68993
MEDIUM 5.3

WordPress Share, Print and PDF Products for WooCommerce plugin <= 3.1.2 - Broken Access Control vulnerability

CVE-2025-68988
MEDIUM 5.3

WordPress E-Invoice App Malaysia plugin <= 1.3.0 - Sensitive Data Exposure vulnerability

CVE-2025-68982
MEDIUM 5.3

WordPress DesignThemes LMS Addon plugin <= 2.6 - Broken Access Control vulnerability

CVE-2025-68981
MEDIUM 5.3

WordPress HomeFix Elementor Portfolio plugin <= 1.0.1 - Broken Access Control vulnerability

CVE-2025-68980
MEDIUM 5.3

WordPress WeDesignTech Portfolio plugin <= 1.0.2 - Broken Access Control vulnerability

CVE-2025-68979
MEDIUM 5.3

WordPress Google Calendar Events plugin <= 3.5.9 - Insecure Direct Object References (IDOR) vulnerability

CVE-2025-68833
MEDIUM 5.3

HCL Hive is affected by use of a cryptographic primitive with a risky implementation

CVE-2025-68606
MEDIUM 5.3

WordPress PostX plugin <= 5.0.3 - Sensitive Data Exposure vulnerability

CVE-2025-68596
MEDIUM 5.3

WordPress Bit Assist plugin <= 1.5.11 - Broken Access Control vulnerability

CVE-2025-68595
MEDIUM 5.3

WordPress Widgets for Social Photo Feed plugin <= 1.8 - Broken Access Control vulnerability

CVE-2025-68589
MEDIUM 5.3

WordPress WP Telegram Widget and Join Link plugin <= 2.2.12 - Broken Access Control vulnerability

CVE-2025-68586
MEDIUM 5.3

WordPress Cooked plugin <= 1.11.3 - Broken Access Control vulnerability

CVE-2025-68582
MEDIUM 5.3

WordPress Funnelforms Free plugin <= 3.8 - Broken Access Control vulnerability

CVE-2025-68579
MEDIUM 5.3

WordPress FV Simpler SEO plugin <= 1.9.6 - Broken Access Control vulnerability

CVE-2025-68572
MEDIUM 5.3

WordPress BBP Core plugin <= 1.4.1 - Broken Access Control vulnerability

CVE-2025-68571
MEDIUM 5.3

WordPress SALESmanago plugin <= 3.9.0 - Broken Access Control vulnerability

CVE-2025-68568
MEDIUM 5.3

WordPress Claspo – Popups, Spin the Wheel & Email Capture plugin <= 1.0.7 - Broken Access Control vulnerability

CVE-2025-68565
MEDIUM 5.3

WordPress Twitch Player plugin <= 2.1.3 - Broken Access Control vulnerability

CVE-2025-68505
MEDIUM 5.3

WordPress H5P plugin <= 1.16.1 - Broken Access Control vulnerability

CVE-2025-68494
MEDIUM 5.3

WordPress Premium Addons for Elementor plugin <= 4.11.53 - Sensitive Data Exposure vulnerability

CVE-2025-68273
MEDIUM 5.3

Signal K Server Vulnerable to Unauthenticated Information Disclosure via Exposed Endpoints

CVE-2025-66335
MEDIUM 5.3

Apache Doris MCP Server: MCP SQL inject

CVE-2025-66105
MEDIUM 5.3

WordPress Bus Ticket Booking with Seat Reservation plugin < 5.6.8 - Broken Access Control vulnerability

CVE-2025-62973
MEDIUM 5.3

WordPress BuddyForms plugin <= 2.10.2 - Broken Access Control vulnerability

CVE-2025-59028
MEDIUM 5.3

When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invalid BASE64 data can be used to DoS a vulnerable server to break concurrent logins. Install fixed version or disable concurrency in login processes (heavy perfomance penalty on large deployments). No publicly available exploits are known.

CVE-2025-53627
MEDIUM 5.3

Meshtastic firmware allows forged DMs with no PKC to show up as encrypted

CVE-2025-46308
MEDIUM 5.3

An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to leak sensitive user information.

CVE-2025-40935
MEDIUM 5.3

A vulnerability has been identified in RUGGEDCOM RMC8388 V5.X (All versions < V5.10.1), RUGGEDCOM RS416Pv2 V5.X (All versions < V5.10.1), RUGGEDCOM RS416v2 V5.X (All versions < V5.10.1), RUGGEDCOM RS900 (32M) V5.X (All versions < V5.10.1), RUGGEDCOM RS900G (32M) V5.X (All versions < V5.10.1), RUGGEDCOM RSG2100 (32M) V5.X (All versions < V5.10.1), RUGGEDCOM RSG2100P (32M) V5.X (All versions < V5.10.1), RUGGEDCOM RSG2288 V5.X (All versions < V5.10.1), RUGGEDCOM RSG2300 V5.X (All versions < V5.10.1), RUGGEDCOM RSG2300P V5.X (All versions < V5.10.1), RUGGEDCOM RSG2488 V5.X (All versions < V5.10.1), RUGGEDCOM RSG907R (All versions < V5.10.1), RUGGEDCOM RSG908C (All versions < V5.10.1), RUGGEDCOM RSG909R (All versions < V5.10.1), RUGGEDCOM RSG910C (All versions < V5.10.1), RUGGEDCOM RSG920P V5.X (All versions < V5.10.1), RUGGEDCOM RSL910 (All versions < V5.10.1), RUGGEDCOM RST2228 (All versions < V5.10.1), RUGGEDCOM RST2228P (All versions < V5.10.1), RUGGEDCOM RST916C (All versions < V5.10.1), RUGGEDCOM RST916P (All versions < V5.10.1). Affected devices do not properly validate input during the TLS certificate upload process of the web service. This could allow an authenticated remote attacker to trigger a device crash and reboot, leading to a temporary Denial of Service on the device.

CVE-2025-36180
MEDIUM 5.3

Inadequate Pod Communication Restrictions, affects watsonx.data

CVE-2025-31981
MEDIUM 5.3

HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption

CVE-2025-31970
MEDIUM 5.3

HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability

CVE-2025-31960
MEDIUM 5.3

HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module

CVE-2025-31051
MEDIUM 5.3

WordPress Plant - Gardening & Houseplants WordPress Theme <= 1.0.0 - Sensitive Data Exposure Vulnerability

CVE-2025-15626
MEDIUM 5.3

Authenticated user can bypass authorization in Ribblr - Crochet & Knitting iOS application

CVE-2025-15474
MEDIUM 5.3

AuntyFey Smart Combination Lock BLE Connection Flood DoS

CVE-2025-15449
MEDIUM 5.3

cld378632668 JavaMall MinioController.java delete path traversal

CVE-2025-15448
MEDIUM 5.3

cld378632668 JavaMall MinioController.java upload unrestricted upload

CVE-2025-15237
MEDIUM 5.3

Quanta Computer|QOCA aim AI Medical Cloud Platform - Path Traversal

CVE-2025-15236
MEDIUM 5.3

Quanta Computer|QOCA aim AI Medical Cloud Platform - Path Traversal

CVE-2025-15152
MEDIUM 5.3

h-moses moga-mall PmsProductController.java addProduct unrestricted upload

CVE-2025-14944
MEDIUM 5.3

Backup Migration <= 2.0.0 - Missing Authorization to Unauthenticated Backup Upload to Offline Storage

CVE-2025-14913
MEDIUM 5.3

Frontend Post Submission Manager Lite <= 1.2.6 - Incorrect Authorization to Unauthenticated Arbitrary Attachment Deletion

CVE-2025-14755
MEDIUM 5.3

Cost Calculator Builder <= 4.0.1 - Unauthenticated Price Manipulation and Insecure Direct Object Reference

CVE-2025-14688
MEDIUM 5.3

IBM® Db2® is vulnerable to a denial of service when fetching from certain tables under specific configurations

CVE-2025-14280
MEDIUM 5.3

PixelYourSite <= 11.1.5 - Sensitive Information Exposure via Log File

CVE-2025-14033
MEDIUM 5.3

ilGhera Support System for WooCommerce <= 1.3.0 - Missing Authorization to Unauthenticated Sensitive Information Exposure

CVE-2025-9987
MEDIUM 5.3

Broadstreet <= 1.53.1 - Authenticated (Subscriber+) Information Disclosure

CVE-2025-7048
MEDIUM 5.3

On affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can cause the MACsec process to terminate unexpectedly. Continuous receipt of these packets with certain MACsec configurations can cause longer term disruption o

CVE-2025-4596
MEDIUM 5.3

Information disclosure via IDOR in Asseco AMDX

CVE-2025-68454
MEDIUM 5.2

Craft CMS vulnerable to potential authenticated Remote Code Execution via Twig SSTI

CVE-2025-52600
MEDIUM 5.2

Improper Input Validation

CVE-2026-106313
MEDIUM 5.1

Incorrect authorization in Browser in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker leveraging social engineering to obtain sensitive information via a co-installed app. (Chromium security severity: Medium)

CVE-2026-106254
MEDIUM 5.1

Information leak in Mobile in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: Medium)

CVE-2026-101150
MEDIUM 5.1

Security Advisory 0186

CVE-2026-101149
MEDIUM 5.1

Security Advisory 0186

CVE-2025-62308
MEDIUM 5.1

HCL AION is affected by a vulnerability where sensitive backend infrastructure details may be exposed

CVE-2025-62305
MEDIUM 5.1

HCL AION is affected by a vulnerability where certain operations may trigger out-of-band interactions

CVE-2025-40638
MEDIUM 5.1

Reflected Cross-Site Scripting (XSS) in Eventobot

CVE-2025-32425
MEDIUM 5.1

AutoGPT has missing Docker log rotation on platform containers that allows host disk-exhaustion DoS

CVE-2025-15479
MEDIUM 5.1

NGSurvey Enterprise 3.6.4 incorrect authorization exposes other users’ API keys and personal data

CVE-2025-15355
MEDIUM 5.1

NetVision Information|ISOinsight - Reflected Cross-site Scripting

CVE-2025-13480
MEDIUM 5.1

Incorrect authorization in Fudo Enterprise

CVE-2025-10549
MEDIUM 5.1

DLL Hijacking in EfficientLab Controlio Leads to Local Privilege Escalation

CVE-2025-8306
MEDIUM 5.1

Improper Access Control in Asseco Infomedica Plus

CVE-2020-37018
MEDIUM 5.1

GOautodial 4.0 - Persistent Cross-Site Scripting

CVE-2026-106561
MEDIUM 5

Backstage: Sensitive information disclosure in Kubernetes resource queries

CVE-2026-103870
MEDIUM 5

Pulp-rpm: distribution tree publish creates directories from .treeinfo ids

CVE-2026-55655
MEDIUM 5

Openssh: local mitm of x11 forwarding via abstract unix socket pre-binding in red hat enterprise linux openssh client versions

CVE-2026-32442
MEDIUM 5

WordPress e2pdf plugin <= 1.28.15 - Broken Access Control vulnerability

CVE-2025-69417
MEDIUM 5

In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve share tokens (intended for unrelated access) via a shared_servers endpoint.

CVE-2025-69416
MEDIUM 5

In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve other tokens (intended for unrelated access) via clients.plex.tv/devices.xml.

CVE-2025-68516
MEDIUM 5

WordPress Tablesome plugin <= 1.1.35.1 - Sensitive Data Exposure vulnerability

CVE-2025-68437
MEDIUM 5

Craft CMS vulnerable to Server-Side Request Forgery (SSRF) via GraphQL Asset Upload Mutation

CVE-2026-106499
MEDIUM 4.9

Backstage: Secret-derived values may be exposed in scaffolder task logs

CVE-2026-102111
MEDIUM 4.9

Kiteworks Core Improper Validation of Specified Quantity in Input

CVE-2026-33531
MEDIUM 4.9

InvenTree has Path Traversal In Report Templates

CVE-2025-68893
MEDIUM 4.9

WordPress WordPress Image shrinker plugin <= 1.1.0 - Server Side Request Forgery (SSRF) vulnerability

CVE-2025-68600
MEDIUM 4.9

WordPress Link Library plugin <= 7.8.7 - Server Side Request Forgery (SSRF) vulnerability

CVE-2025-68500
MEDIUM 4.9

WordPress Prime Slider – Addons For Elementor plugin <= 4.0.10 - Server Side Request Forgery (SSRF) vulnerability

CVE-2025-68436
MEDIUM 4.9

Craft CMS vulnerable to potential information disclosure via unchecked asset relocation

CVE-2025-62327
MEDIUM 4.9

HCL DevOps Deploy is susceptible to insufficiently protected credentials

CVE-2025-49335
MEDIUM 4.9

WordPress External Media plugin <= 1.0.36 - Server Side Request Forgery (SSRF) vulnerability

CVE-2025-14830
MEDIUM 4.9

JFrog Artifactory Cross-Site Scripting

CVE-2023-22894
MEDIUM 4.9

Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting the query filter. The attacker can filter users by columns that contain sensitive information and infer a value from API responses. If the attacker has super admin access, then this can be exploited to discover the password hash and password reset token of all users. If the attacker has admin panel access to an account with permission to access the username and email of API users with a lower privileged role (e.g., Editor or Author), then this can be exploited to discover sensitive information for all API users but not other admin accounts.

CVE-2026-106456
MEDIUM 4.8

Backstage: Inconsistent credential enforcement for overlapping proxy routes

CVE-2026-106402
MEDIUM 4.8

Incorrect authorization in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted Chrome extension. (Chromium security severity: Medium)

CVE-2026-97146
MEDIUM 4.8

Apache YuniKorn: Admission control bypass via system label forgery

CVE-2026-46437
MEDIUM 4.8

wger: API credentials remain valid after logout/password change

CVE-2025-66486
MEDIUM 4.8

Multiple vulnerabilities have been addressed in IBM Aspera Shares

CVE-2025-64392
MEDIUM 4.8

This vulnerability in Veeam Backup Enterprise Manager allows an attacker to execute script in the browser of a portal user who opens a crafted link.

CVE-2025-55064
MEDIUM 4.8

Priority - CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

CVE-2025-55063
MEDIUM 4.8

Priority - CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

CVE-2025-55062
MEDIUM 4.8

Priority - CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

CVE-2025-31976
MEDIUM 4.8

HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials

CVE-2025-15150
MEDIUM 4.8

PX4 PX4-Autopilot mavlink_log_handler.cpp log_entry_from_id stack-based overflow

CVE-2025-14946
MEDIUM 4.8

Libnbd: libnbd: arbitrary code execution via ssh argument injection through a malicious uri

CVE-2025-10539
MEDIUM 4.8

Improper TLS Certificate Validation RCE via Malicious Update in DeskTime Time Tracking App

CVE-2026-106444
MEDIUM 4.7

Handlebars: JavaScript Injection via Unsafe Inline Embedding of Precompiled Templates

CVE-2026-104045
MEDIUM 4.7

Sssd: sssd: denial of service via race condition in autofs responder

CVE-2025-68602
MEDIUM 4.7

WordPress Accept Donations with PayPal plugin <= 1.5.2 - Open Redirection vulnerability

CVE-2025-68509
MEDIUM 4.7

WordPress User Submitted Posts plugin <= 20251121 - Open Redirection vulnerability

CVE-2026-102107
MEDIUM 4.6

Kiteworks Core user impersonation in a file-request feature

CVE-2025-52613
MEDIUM 4.6

HCL BigFix Service Management (SM) is affected by use of a vulnerable component

CVE-2025-41696
MEDIUM 4.6

Hardcoded User Password

CVE-2025-31978
MEDIUM 4.6

HCL BigFix Service Management (SM) does not adequately sanitize or safely render

CVE-2026-106494
MEDIUM 4.4

Backstage: Improper input validation in cloud storage URL readers

CVE-2026-106326
MEDIUM 4.4

Confused deputy in UI in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker to bypass system access restrictions into a privileged page via a co-installed app. (Chromium security severity: Medium)

CVE-2026-19087
MEDIUM 4.4

IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

CVE-2025-60175
MEDIUM 4.4

WordPress PopAd Plugin <= 1.0.4 - Server Side Request Forgery (SSRF) Vulnerability

CVE-2025-43935
MEDIUM 4.4

Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper resource shutdown or release vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service.

CVE-2025-15000
MEDIUM 4.4

Page Keys <= 1.3.3 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'page_key' Parameter

CVE-2025-14888
MEDIUM 4.4

Simple User Meta Editor <= 1.0.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via User Meta Value Field

CVE-2025-14887
MEDIUM 4.4

twinklesmtp – Email Service Provider For WordPress <= 1.03 - Authenticated (Administrator+) Stored Cross-Site Scripting via Sender Settings

CVE-2025-14792
MEDIUM 4.4

Key Figures <= 1.1 - Authenticated (Admin+) Stored Cross-Site Scripting via kf_field_figure_default_color_render

CVE-2025-12946
MEDIUM 4.4

Improper input validation in NETGEAR Nighthawk routers

CVE-2025-9989
MEDIUM 4.4

Broadstreet <= 1.53.1 - Authenticated (Admin+) Stored Cross-Site Scripting

CVE-2026-106562
MEDIUM 4.3

Backstage: Incorrect authorization in search engine permission filtering

CVE-2026-106497
MEDIUM 4.3

Backstage: Inconsistent catalog property permission evaluation

CVE-2026-106461
MEDIUM 4.3

Backstage: Incorrect authorization in scaffolder task listing

CVE-2026-106454
MEDIUM 4.3

Twisted: IMAP wildcardToRegexp() ReDoS

CVE-2026-106415
MEDIUM 4.3

Information leak in Enterprise in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106398
MEDIUM 4.3

Incorrect authorization in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106394
MEDIUM 4.3

Incomplete cleanup in Glic in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-106392
MEDIUM 4.3

Information leak in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106390
MEDIUM 4.3

Incorrect provision of specified functionality in SanitizerAPI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-106379
MEDIUM 4.3

Uninitialized resource in Skia in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106354
MEDIUM 4.3

Improper resource exposure in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106336
MEDIUM 4.3

Observable discrepancy in Paint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106332
MEDIUM 4.3

Integer overflow in Compositing in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106330
MEDIUM 4.3

Information leak in Paint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106325
MEDIUM 4.3

Incorrect reference resolution in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-106321
MEDIUM 4.3

Information leak in Editing in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106277
MEDIUM 4.3

Information leak in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106260
MEDIUM 4.3

Incorrect authorization in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-106253
MEDIUM 4.3

Incorrect authorization in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)

CVE-2026-106245
MEDIUM 4.3

Uninitialized resource in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106184
MEDIUM 4.3

Uninitialized resource in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVE-2026-104651
MEDIUM 4.3

Yaad Sarig Payment Gateway For WC < 2.2.13 - Subscriber+ Arbitrary Order Payment Manipulation via IDOR

CVE-2026-104390
MEDIUM 4.3

WordPress Booktics plugin <= 1.0.27 - Broken Access Control vulnerability

CVE-2026-104050
MEDIUM 4.3

Academy LMS < 4.0.0 - Subscriber+ Cross-Course Quiz Answer Disclosure via render_quiz_answers

CVE-2026-104049
MEDIUM 4.3

Academy LMS < 4.0.0 - Subscriber+ Arbitrary Lesson Content Disclosure via Topic REST Endpoint

CVE-2026-103681
MEDIUM 4.3

Frontend Dashboard < 3.0.0 - Subscriber+ Profile and Post Field Deletion via fed_user_profile_delete

CVE-2026-103075
MEDIUM 4.3

WordPress Hustle plugin <= 7.8.14.2 - Broken Access Control vulnerability

CVE-2026-102410
MEDIUM 4.3

Missing Authorization in Kibana Leading to Information Disclosure

CVE-2026-102408
MEDIUM 4.3

Inefficient Regular Expression Complexity in Elasticsearch Leading to Denial of Service

CVE-2026-102122
MEDIUM 4.3

Kiteworks Core Incorrect Authorization

CVE-2026-102090
MEDIUM 4.3

Kiteworks Core content injection

CVE-2026-97331
MEDIUM 4.3

User Private Files < 2.1.9 - Subscriber+ User Email Address Disclosure via dpk_upvf_rmv_access

CVE-2026-96589
MEDIUM 4.3

Gitea private repository access retained after rejected transfer

CVE-2026-96400
MEDIUM 4.3

Gitea migration SSRF to reserved addresses through ALLOWED_DOMAINS

CVE-2026-93679
MEDIUM 4.3

Langflow OSS is affected by multiple vulnerabilities

CVE-2026-56098
MEDIUM 4.3

Rubygem-katello: improper authorization logic allows resource enumeration

CVE-2026-55653
MEDIUM 4.3

Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validation leads to client-side denial of service

CVE-2025-69361
MEDIUM 4.3

WordPress Post Expirator plugin <= 4.9.3 - Broken Access Control vulnerability

CVE-2025-69354
MEDIUM 4.3

WordPress Better Business Reviews plugin <= 0.1.1 - Broken Access Control vulnerability

CVE-2025-69348
MEDIUM 4.3

WordPress The Events Calendar Countdown Addon plugin <= 1.4.15 - Broken Access Control vulnerability

CVE-2025-69346
MEDIUM 4.3

WordPress AffiliateX plugin <= 1.3.9.3 - Broken Access Control vulnerability

CVE-2025-69344
MEDIUM 4.3

WordPress Oneline Lite theme <= 6.6 - Broken Access Control vulnerability

CVE-2025-69336
MEDIUM 4.3

WordPress Ultimate Store Kit Elementor Addons plugin <= 2.9.4 - Broken Access Control vulnerability

CVE-2025-69333
MEDIUM 4.3

WordPress JetEngine plugin <= 3.8.1.1 - Broken Access Control vulnerability

CVE-2025-69331
MEDIUM 4.3

WordPress Theater for WordPress plugin <= 0.19 - Broken Access Control vulnerability

CVE-2025-69327
MEDIUM 4.3

WordPress Car Rental Manager plugin <= 1.0.9 - Broken Access Control vulnerability

CVE-2025-69284
MEDIUM 4.3

In plane.io, a Guest User to a Workspace can still be able to see list of members

CVE-2025-69221
MEDIUM 4.3

LibreChat has Insufficient Access Control for Agent Permission Queries

CVE-2025-69206
MEDIUM 4.3

Hemmelig has SSRF Filter bypass in Secret Request functionality

CVE-2025-69091
MEDIUM 4.3

WordPress Demo Importer Plus plugin <= 2.0.8 - Broken Access Control vulnerability

CVE-2025-69026
MEDIUM 4.3

WordPress PopupKit plugin <= 2.1.5 - Sensitive Data Exposure vulnerability

CVE-2025-69025
MEDIUM 4.3

WordPress Poptics plugin <= 1.0.20 - Sensitive Data Exposure vulnerability

CVE-2025-69023
MEDIUM 4.3

WordPress Discussion Board plugin <= 2.5.7 - Broken Access Control vulnerability

CVE-2025-69016
MEDIUM 4.3

WordPress Shortcodes and extra features for Phlox theme plugin <= 2.17.22 - Broken Access Control vulnerability

CVE-2025-69013
MEDIUM 4.3

WordPress Stratum plugin <= 1.6.1 - Broken Access Control vulnerability

CVE-2025-69012
MEDIUM 4.3

WordPress Event Organiser plugin <= 3.12.8 - Broken Access Control vulnerability

CVE-2025-68995
MEDIUM 4.3

WordPress My Sticky Elements plugin <= 2.3.3 - Broken Access Control vulnerability

CVE-2025-68989
MEDIUM 4.3

WordPress Contact Form 7 Extension For Mailchimp plugin <= 0.9.68 - Sensitive Data Exposure vulnerability

CVE-2025-68975
MEDIUM 4.3

WordPress Eagle Booking plugin <= 1.3.4.3 - Insecure Direct Object References (IDOR) vulnerability

CVE-2025-68592
MEDIUM 4.3

WordPress WP Adminify plugin <= 4.0.6.1 - Broken Access Control vulnerability

CVE-2025-68588
MEDIUM 4.3

WordPress TS Poll plugin <= 2.5.5 - Broken Access Control vulnerability

CVE-2025-68587
MEDIUM 4.3

WordPress Watu Quiz plugin <= 3.4.5 - Broken Access Control vulnerability

CVE-2025-68584
MEDIUM 4.3

WordPress Vimeotheque plugin <= 2.3.5.2 - Cross Site Request Forgery (CSRF) vulnerability

CVE-2025-68583
MEDIUM 4.3

WordPress Fast User Switching plugin <= 1.4.10 - Cross Site Request Forgery (CSRF) vulnerability

CVE-2025-68580
MEDIUM 4.3

WordPress Advanced Classifieds & Directory Pro plugin <= 3.2.9 - Cross Site Request Forgery (CSRF) vulnerability

CVE-2025-68535
MEDIUM 4.3

WordPress Sunshine Photo Cart plugin <= 3.5.7.1 - Broken Access Control vulnerability

CVE-2025-68529
MEDIUM 4.3

WordPress WP Email Capture plugin <= 3.12.5 - Cross Site Request Forgery (CSRF) vulnerability

CVE-2025-68523
MEDIUM 4.3

WordPress Spiffy Calendar plugin <= 5.0.7 - Broken Access Control vulnerability

CVE-2025-68502
MEDIUM 4.3

WordPress JetPopup plugin <= 2.0.20.1 - Insecure Direct Object References (IDOR) vulnerability

CVE-2025-67625
MEDIUM 4.3

WordPress Trade Runner plugin <= 3.14 - Cross Site Request Forgery (CSRF) vulnerability

CVE-2025-67621
MEDIUM 4.3

WordPress Eight Day Week Print Workflow plugin <= 1.2.5 - Sensitive Data Exposure vulnerability

CVE-2025-62311
MEDIUM 4.3

HCL AION is affected by a vulnerability where backend service details may be transmitted over insecure HTTP channels.

CVE-2025-62104
MEDIUM 4.3

WordPress ACF Galerie 4 plugin <= 1.4.2 - Broken Access Control vulnerability

CVE-2025-59031
MEDIUM 4.3

Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachments. Attacker can use specially crafted OOXML documents to cause unintended files on the system to be indexed and subsequently ending up in FTS indexes. Do not use the provided script, instead, use something else like FTS tika. No publicly available exploits are known.

CVE-2025-58922
MEDIUM 4.3

WordPress Avada theme < 7.13.2 - Cross Site Request Forgery (CSRF) vulnerability

CVE-2025-53444
MEDIUM 4.3

WordPress Userpro plugin < 5.1.11 - Cross Site Request Forgery (CSRF) vulnerability

CVE-2025-53344
MEDIUM 4.3

WordPress Thim Core Plugin <= 2.3.3 - Cross Site Request Forgery (CSRF) Vulnerability

CVE-2025-48571
MEDIUM 4.3

In multiple functions of btm_sec.cc, there is a possible way for an attacker to intercept SMS messages due to a logic error in the code. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

CVE-2025-43541
MEDIUM 4.3

A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.

CVE-2025-43535
MEDIUM 4.3

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2025-43501
MEDIUM 4.3

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2025-41693
MEDIUM 4.3

Authenticated Denial-of-Service via SSH

CVE-2025-31046
MEDIUM 4.3

WordPress AnyWhere Elementor Pro plugin <= 2.29 - Broken Access Control Vulnerability

CVE-2025-15635
MEDIUM 4.3

WordPress Smart Online Order for Clover plugin <= 1.6.0 - Cross Site Request Forgery (CSRF) vulnerability

CVE-2025-14999
MEDIUM 4.3

Latest Tabs <= 1.5 - Cross-Site Request Forgery to Plugin's Settings Update

CVE-2025-14904
MEDIUM 4.3

Newsletter Email Subscribe <= 2.4 - Cross-Site Request Forgery to Plugin Settings Update

CVE-2025-14845
MEDIUM 4.3

NS IE Compatibility Fixer <= 2.1.5 - Cross-Site Request Forgery to Plugin Settings Update

CVE-2025-14687
MEDIUM 4.3

Client-Side Enforcement of Server-Side Security in IBM Db2 Intelligence Center

CVE-2025-11762
MEDIUM 4.3

HubSpot All-In-One Marketing - Forms, Popups, Live Chat <= 11.3.32 - Missing Authorization to Authenticated (Contributor+) Installed Plugin Disclosure

CVE-2025-9988
MEDIUM 4.3

Broadstreet <= 1.53.1 - Missing Authorization to Authenticated (Subscriber+) Advertiser Creation

CVE-2025-9294
MEDIUM 4.3

Quiz And Survey Master <= 10.3.1 - Missing Authorization to Authenticated (Subscriber+) Quiz Results Deletion

CVE-2025-4202
MEDIUM 4.3

Multicollab: Content Team Collaboration and Editorial Workflow <= 5.2 - Missing Authorization to Authenticated (Subscriber+) Collaboration Comment

CVE-2026-106552
MEDIUM 4.2

In sftp in OpenSSH before 10.6, a server can trigger directory traversal (causing files to be written to unintended locations) during a recursive copy operation.

CVE-2026-106413
MEDIUM 4.2

Race condition in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-106410
MEDIUM 4.2

Missing authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106391
MEDIUM 4.2

Incorrect authorization in WebShare in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106345
MEDIUM 4.2

Use of released resource in Session in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-106320
MEDIUM 4.2

Use of released resource in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-106295
MEDIUM 4.2

Incorrect authorization in Unbounded Element in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106262
MEDIUM 4.2

Incomplete cleanup in GetUserMedia in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106226
MEDIUM 4.2

Improper input validation in Compositing in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106187
MEDIUM 4.2

Missing authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-97354
MEDIUM 4.1

PowerPress 11.13.12 - 11.17.9 - Contributor+ SSRF via Media URL Redirects

CVE-2025-64391
MEDIUM 4.1

This vulnerability in Veeam Agent for Microsoft Windows allows a low-privileged local user to make the agent write files to arbitrary locations when an administrator installs it.

CVE-2025-43883
MEDIUM 4.1

Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper check for unusual or exceptional conditions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service.

CVE-2025-14972
MEDIUM 4.1

Insufficient DPA countermeasure reseeding

CVE-2026-90996
MEDIUM 4

Sssd: sssd: denial of service in nss responder via crafted zero-length requests

CVE-2025-31974
LOW 3.9

HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only

CVE-2025-69015
LOW 3.8

WordPress Crowdsignal Forms plugin <= 1.7.2 - Broken Access Control vulnerability

CVE-2025-36228
LOW 3.8

Incorrect Execution-Assigned Permissions in IBM Aspera Faspex

CVE-2026-106582
LOW 3.7

In sshd and ssh in OpenSSH before 10.6, an LZ77 dictionary coder can be used even though this is contraindicated by the arXiv 2609.07709 "Crossing the Streams" findings.

CVE-2026-106449
LOW 3.7

yawkat LZ4 Java: LZ4BlockInputStream with stopOnEmptyBlock=false recurses once per empty block, causing StackOverflowError

CVE-2026-18173
LOW 3.7

IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

CVE-2025-59852
LOW 3.7

HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability

CVE-2025-59851
LOW 3.7

HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability

CVE-2025-31984
LOW 3.7

HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header

CVE-2025-31983
LOW 3.7

HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header

CVE-2025-31982
LOW 3.7

HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directl

CVE-2025-31958
LOW 3.7

HCL BigFix Service Management (SM) is susceptible to HTTP Request Smuggling

CVE-2026-106587
LOW 3.6

In sshd in OpenSSH before 10.6, the value "none" for a configuration option is sometimes interpreted as a filename but was intended to mean that a feature is disabled.

CVE-2026-106487
LOW 3.5

Backstage: Unsupported catalog cluster authentication mode in kubernetes backend

CVE-2025-31959
LOW 3.5

HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images.

CVE-2025-9543
LOW 3.5

FlexTable Google Sheets Connector < 3.19.2 - Admin+ Stored XSS

CVE-2026-58856
LOW 3.3

In returnOutputBufferLocked of DeprecatedCamera3StreamSplitter.cpp, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2025-46279
LOW 3.3

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. An app may be able to identify what other apps a user has installed.

CVE-2026-106588
LOW 3.1

In sshd in OpenSSH through 10.6, use of the macOS 27 (or later) SDK has the side effect of loss of sandboxing, which is potentially unexpected.

CVE-2026-106496
LOW 3.1

Backstage: Inconsistent enforcement of allowed location types during catalog processing

CVE-2026-106339
LOW 3.1

Use of released resource in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-106224
LOW 3.1

Missing authorization in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106210
LOW 3.1

Observable discrepancy in Scroll in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)

CVE-2026-106180
LOW 3.1

Observable discrepancy in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVE-2025-59854
LOW 3.1

HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability

CVE-2025-59853
LOW 3.1

HCL DFXAnalytics is affected by an Improper Error Handling vulnerability

CVE-2025-43531
LOW 3.1

A race condition was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2025-36229
LOW 3.1

Exposure of Sensitive System Information to an Unauthorized Control Sphere in IBM Aspera Faspex

CVE-2026-106493
LOW 3

Backstage: Cloud storage catalog locations may cross configured storage boundaries

CVE-2025-62312
LOW 3

HCL AION is affected by a vulnerability where basic authorization tokens are used for authentication

CVE-2026-107170
LOW 2.9

M17n-lib: null dereference in minput_open_im() after failed m17n_init()

CVE-2026-106589
LOW 2.9

In sshd in OpenSSH through 10.6, in certain environments such as QNX 6 and SCO OpenServer 5, sshd-session can unexpectedly have root privileges. This is related to the GatewayPorts and StreamLocalForwarding configuration options, and lack of support for file-descriptor passing and unprivileged allocation of PTY devices.

CVE-2025-52641
LOW 2.9

Internal Filesystem Exploration vulnerability

CVE-2025-31963
LOW 2.9

HCL BigFix IVR is impacted by improper authentication and missing CSRF protection

CVE-2025-15151
LOW 2.9

TaleLin Lin-CMS Tests Folder config.py password in configuration file

CVE-2025-15108
LOW 2.9

PandaXGO PandaX JWT Secret config.yml hard-coded key

CVE-2025-15107
LOW 2.9

actiontech sqle JWT Secret jwt.go hard-coded key

CVE-2025-15105
LOW 2.9

getmaxun auth.ts hard-coded key

CVE-2025-43532
LOW 2.8

A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing malicious data may lead to unexpected app termination.

CVE-2026-104678
LOW 2.7

CP Media Player < 1.3.4 - Contributor+ Media Player Settings Update

CVE-2025-68585
LOW 2.7

WordPress WP Document Revisions plugin <= 3.7.2 - Broken Access Control vulnerability

CVE-2025-66487
LOW 2.7

Multiple vulnerabilities have been addressed in IBM Aspera Shares

CVE-2025-62345
LOW 2.7

HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” Vulnerability

CVE-2025-15480
LOW 2.7

Senstive information disclosure was affecting ubuntu-desktop-provision

CVE-2025-14551
LOW 2.7

Senstive information disclosure was affecting subiquity

CVE-2025-62317
LOW 2.6

HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters.

CVE-2025-62309
LOW 2.6

HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields.

CVE-2025-31975
LOW 2.6

HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified.

CVE-2025-31957
LOW 2.6

HCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability.

CVE-2026-106586
LOW 2.5

In sshd in OpenSSH before 10.6, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not, a different vulnerability than CVE-2026-73283.

CVE-2026-106584
LOW 2.5

In ssh-keygen in OpenSSH before 10.6, certificates could have incorrect expiration times because of Daylight Saving mishandling. There can be a slightly more severe effect on users in certain Antarctic locations.

CVE-2026-106583
LOW 2.5

In ssh in OpenSSH before 10.6, a $ or \ character can occur in a command-line username, leading to injection.

CVE-2026-105140
LOW 2.3

Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 Race Condition Restores Revoked Group Membership

CVE-2026-105111
LOW 2.3

Apache Commons BCEL: Class2HTML emits unescaped class strings, enabling stored XSS

CVE-2026-102164
LOW 2.3

Security Advisory 0196

CVE-2025-62316
LOW 2.3

HCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configured

CVE-2025-15117
LOW 2.3

Dromara Sa-Token SaJdkSerializer.java ObjectInputStream.readObject deserialization

CVE-2026-106555
LOW 2.2

In sshd in OpenSSH before 10.6, GSSAPIAuthentication authentication state can incorrectly be persisted across authentication attempts.

CVE-2026-106553
LOW 2.2

In sshd in OpenSSH before 10.6, credentials can incorrectly persist after failure of a GSSAPIAuthentication authentication attempt.

CVE-2025-31964
LOW 2.2

HCL BigFix IVR is impacted by an improper service binding configuration

CVE-2026-107125
LOW 2.1

XnView Classic FLI File heap-based overflow

CVE-2026-78243
LOW 2.1

Apache YuniKorn: LDAP Group provider panics on lowercase attribute name

CVE-2025-15450
LOW 2.1

sfturing hosp_order orderHos findOrderHosNum sql injection

CVE-2025-15423
LOW 2.1

EmpireSoft EmpireCMS connect.php CheckSaveTranFiletype unrestricted upload

CVE-2025-15406
LOW 2.1

PHPGurukul Online Course Registration authorization

CVE-2025-15404
LOW 2.1

campcodes School File Management System save_file.php unrestricted upload

CVE-2025-15246
LOW 2.1

aizuda snail-job API FurySerializer.deserialize deserialization

CVE-2025-15220
LOW 2.1

SohuTV CacheCloud LoginController.java init cross site scripting

CVE-2025-15213
LOW 2.1

code-projects Student File Management System File Download download.php improper authorization

CVE-2025-15212
LOW 2.1

code-projects Refugee Food Management System regfood.php sql injection

CVE-2025-15211
LOW 2.1

code-projects Refugee Food Management System refugee.php sql injection

CVE-2025-15210
LOW 2.1

code-projects Refugee Food Management System editrefugee.php sql injection

CVE-2025-15209
LOW 2.1

code-projects Refugee Food Management System editfood.php sql injection

CVE-2025-15205
LOW 2.1

code-projects Student File Management System download.php sql injection

CVE-2025-15199
LOW 2.1

code-projects College Notes Uploading System userprofile.php unrestricted upload

CVE-2025-15192
LOW 2.1

D-Link DWR-M920 formLtefotaUpgradeQuectel sub_415328 command injection

CVE-2025-15191
LOW 2.1

D-Link DWR-M920 formLtefotaUpgradeFibocom sub_4155B4 command injection

CVE-2025-15170
LOW 2.1

Advaya Softech GEMS ERP Portal Error Message home.jsp cross site scripting

CVE-2025-15156
LOW 2.1

omec-project UPF PFCP Session Establishment Request messages_session.go handleSessionEstablishmentRequest null pointer dereference

CVE-2025-15144
LOW 2.1

dayrui XunRuiCMS JSONP Callback Init.php dr_exit_msg cross site scripting

CVE-2025-15139
LOW 2.1

TRENDnet TEW-822DRE formWsc sub_43ACF4  command injection

CVE-2025-15135
LOW 2.1

joey-zhou xiaozhi-esp32-server-java Cookie AuthenticationInterceptor.java tryAuthenticateWithCookies improper authentication

CVE-2025-15133
LOW 2.1

ZSPACE Z4Pro+ HTTP POST Request close zfilev2_api_CloseSafe command injection

CVE-2025-15132
LOW 2.1

ZSPACE Z4Pro+ HTTP POST Request open zfilev2_api_open command injection

CVE-2025-15131
LOW 2.1

ZSPACE Z4Pro+ HTTP POST Request status zfilev2_api_SafeStatus command injection

CVE-2025-15129
LOW 2.1

ChenJinchuang Lin-CMS-TP5 File Upload LocalUploader.php upload code injection

CVE-2025-15118
LOW 2.1

macrozheng mall Member Endpoint update improper authorization

CVE-2025-15106
LOW 2.1

getmaxun Authentication Endpoint auth.ts router.get improper authorization

CVE-2025-15094
LOW 2.1

sunkaifei FlyCMS User Login UserController.java userLogin cross site scripting

CVE-2025-15093
LOW 2.1

sunkaifei FlyCMS Admin Login IndexAdminController.java cross site scripting

CVE-2025-15088
LOW 2.1

ketr JEPaaS loadPostil postilService.loadPostils sql injection

CVE-2025-15087
LOW 2.1

youlaitech youlai-mall OrderController.java submitOrderPayment improper authorization

CVE-2025-15086
LOW 2.1

youlaitech youlai-mall MemberController.java getMemberByMobile access control

CVE-2025-15085
LOW 2.1

youlaitech youlai-mall Balance MemberController.java deductBalance improper authorization

CVE-2025-15081
LOW 2.1

JD Cloud BE6500 jdcapi sub_4780 command injection

CVE-2026-92393
LOW 2

Apache YuniKorn: Admission control bypass via workload UPDATE operation

CVE-2025-31962
LOW 2

HCL BigFix IVR is impacted by an insufficient session expiration vulnerability

CVE-2025-15632
LOW 2

1Panel-dev MaxKB MdPreview chat.ts cross site scripting

CVE-2025-15415
LOW 2

xnx3 wangmarket XML File uploadImage.do uploadImage unrestricted upload

CVE-2025-15414
LOW 2

go-sonic Theme Fetching API git_fetcher.go FetchTheme server-side request forgery

CVE-2025-15245
LOW 2

D-Link DCS-850L Firmware Update Service uploadfirmware path traversal

CVE-2025-15241
LOW 2

CloudPanel Community Edition HTTP Header users redirect

CVE-2025-15221
LOW 2

SohuTV CacheCloud AppDataMigrateController.java index cross site scripting

CVE-2025-15219
LOW 2

SohuTV CacheCloud MachineManageController.java doPodList cross site scripting

CVE-2025-15201
LOW 2

SohuTV CacheCloud WebResourceController.java redirectNoPower cross site scripting

CVE-2025-15197
LOW 2

code-projects/anirbandutta9 Content Management System/News-Buzz editposts.php unrestricted upload

CVE-2025-15175
LOW 2

SohuTV CacheCloud AppController.java appCommandAnalysis cross site scripting

CVE-2025-15174
LOW 2

SohuTV CacheCloud AppManageController.java doAppAuditList cross site scripting

CVE-2025-15173
LOW 2

SohuTV CacheCloud InstanceController.java advancedAnalysis cross site scripting

CVE-2025-15172
LOW 2

SohuTV CacheCloud RedisConfigTemplateController.java preview cross site scripting

CVE-2025-15171
LOW 2

SohuTV CacheCloud ServerController.java index cross site scripting

CVE-2025-15169
LOW 2

BiggiDroid Simple PHP CMS editsite.php sql injection

CVE-2025-15138
LOW 2

prasathmani TinyFileManager tinyfilemanager.php path traversal

CVE-2025-15134
LOW 2

yourmaileyes MOOC Submission MainController.java subreview cross site scripting

CVE-2025-15130
LOW 2

shanyu SyCms Administrative Panel FileManageController.class.php addPost code injection

CVE-2025-15110
LOW 2

jackq XCMS Backend ProductImageController.class.php upload unrestricted upload

CVE-2025-15452
LOW 1.9

xnx3 wangmarket Backend Variable Search variableList.do variableList cross site scripting

CVE-2025-15451
LOW 1.9

xnx3 wangmarket System Variables variableSave.do cross site scripting

CVE-2025-15416
LOW 1.9

xnx3 wangmarket Add Global Variable save.do cross site scripting

CVE-2025-15412
LOW 1.9

WebAssembly wabt wasm-decompile VarName out-of-bounds

CVE-2025-15411
LOW 1.9

WebAssembly wabt wasm-decompile InsertNode memory corruption

CVE-2025-15214
LOW 1.9

Campcodes Park Ticketing System admin_class.php save_pricing cross site scripting

CVE-2025-15204
LOW 1.9

SohuTV CacheCloud QuartzManageController.java doQuartzList cross site scripting

CVE-2025-15203
LOW 1.9

SohuTV CacheCloud ResourceController.java index cross site scripting

CVE-2025-15202
LOW 1.9

SohuTV CacheCloud TaskController.java taskQueueList cross site scripting

CVE-2025-15200
LOW 1.9

SohuTV CacheCloud AppClientDataShowController.java doIndex cross site scripting

CVE-2025-15188
LOW 1.9

Campcodes Complete Online Beauty Parlor Management System search-invoices.php cross site scripting

CVE-2025-15155
LOW 1.9

floooh sokol sokol_gfx.h _sg_pipeline_desc_defaults stack-based overflow

CVE-2025-15149
LOW 1.9

rawchen ecms Add New Product updateProductServlet.java updateProductServlet cross site scripting

CVE-2025-15146
LOW 1.9

SohuTV CacheCloud UserManageController.java doUserList cross site scripting

CVE-2025-15145
LOW 1.9

SohuTV CacheCloud TotalManageController.java doTotalList cross site scripting

CVE-2025-5154
LOW 1.8

PhonePe App SQLite Database databases cleartext storage in file

CVE-2025-15454
LOW 1.3

zhanglun lettura RSS ContentRender.tsx cross site scripting

CVE-2025-15222
LOW 1.3

Dromara Sa-Token SaSerializerTemplateForJdkUseBase64.java ObjectInputStream.readObject deserialization

CVE-2025-15084
LOW 1.3

youlaitech youlai-mall Order Payment OrderController.java orderService.payOrder access control

CVE-2025-12141
LOW 1.3

Grafana Alerting Editors can edit destination of webhooks they did not create

CVE-2025-62852
LOW 1.2

QTS, QuTS hero

CVE-2025-48721
LOW 1.2

QTS, QuTS hero

CVE-2025-15083
LOW 0.3

TOZED ZLT M30s UART on-chip debug and test interface with improper access control

CVE-2026-107202
NONE

CVE-2026-107202

CVE-2026-106550
NONE

CVE-2026-106550

CVE-2026-106511
NONE

CVE-2026-106511

CVE-2026-105268
NONE

Gitea issue attachment API allows changing comment attachments

CVE-2026-105267
NONE

Gitea tag delete route deletes releases without release permission

CVE-2026-104636
NONE

Gitea SSRF through Git HTTP redirects in mirrors and fetches

CVE-2026-104633
NONE

Gitea migration memory exhaustion from zero page size

CVE-2026-104632
NONE

Gitea fork workflow approval bypass through cancel and rerun

CVE-2026-104626
NONE

Gitea fork workflow job revival through later approval

CVE-2026-103670
NONE

Gitea trusted workflow cancellation by unapproved fork runs

CVE-2026-103667
NONE

Gitea container registry stored XSS through blob media type

CVE-2026-103504
NONE

Gitea API team demotion not applied to unit permissions

CVE-2026-102255
NONE

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.

CVE-2026-101029
NONE

Gitea migration and pull mirror SSRF through multi-answer DNS

CVE-2026-101023
NONE

Gitea OAuth2 refresh token grant accepts access tokens

CVE-2026-98374
NONE

tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack()

CVE-2026-98373
NONE

mm/hugetlb: preserve mremap address delta when skipping page tables

CVE-2026-98266
NONE

ALSA: core: Fix potential UAF after asynchronous card release

CVE-2026-98177
NONE

drm/amdkfd: Avoid integer underflow in EOP ring size calculation.

CVE-2026-98176
NONE

drm/amdkfd: Avoid integer underflow with ffs in EOP ring size calc

CVE-2026-97720
NONE

Apache Impala: Impala Executor Webserver Auth Bypass

CVE-2026-97626
NONE

Gitea profile feed disclosure bypassing user visibility

CVE-2026-97208
NONE

Gitea push mirror API bypass of DISABLE_NEW_PUSH policy

CVE-2026-96594
NONE

Gitea repository media API stored XSS

CVE-2026-96580
NONE

Gitea Actions memory exhaustion through large static matrices

CVE-2026-96399
NONE

Gitea denial of service through external issue tracker patterns

CVE-2026-95112
NONE

Gitea issue reference parsing CPU exhaustion

CVE-2026-95106
NONE

Gitea review and execution mismatch through duplicate tree entries

CVE-2026-94205
NONE

Gitea fork workflow approval bypass through maintainer-triggered events

CVE-2026-93684
NONE

Apache Impala: Stored XSS in Impala query plans

CVE-2026-90466
NONE

Apache Impala: Path traversal executes JARs outside trusted paths

CVE-2026-89430
NONE

Gitea push mirror SSRF and forced writes to internal Git hosts

CVE-2026-88514
NONE

An issue in iTerm2 macOS before 3.6.12 allows a local attacker to obtain sensitive information.

CVE-2026-86684
NONE

Gitea push mirror local path check uses the repository owner

CVE-2026-80048
NONE

Sssd: sssd-kcm: local denial of service via excessive memory preallocation

CVE-2026-73278
NONE

Gitea WebAuthn bypass during OAuth and OIDC sign-in

CVE-2026-70357
NONE

Gitea repository migration SSRF through DNS rebinding

CVE-2026-46572
NONE

In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ib_cut_tail() in libntfs-3g/index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by creating a file in a specially crafted directory.

CVE-2026-46570
NONE

In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_index_walk_down() in libntfs-3g/index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by reading the special crafted file metadata.

CVE-2026-46569
NONE

In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ib_copy_tail(), in libntfs-3g/index.c, that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by extending a directory, e.g., by creating a file.

CVE-2026-42617
NONE

In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ir_to_ib() in index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by extending a directory, e.g., by creating a file.

CVE-2026-42616
NONE

In NTFS-3G before 2026.7.7, a heap buffer overflow exists in cat() in ntfscat.c that allows an attacker to corrupt heap memory in the ntfscat binary by crafting a malicious NTFS image. The overflow is triggered by reading a file.

CVE-2025-70522
NONE

The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applications. Due to the lack of protection, cross-origin boundary can be completely bypassed, allowing for Cross-Site Request Forgery Attacks against any endpoint.

CVE-2025-70521
NONE

The management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user supplied input securely. The lack of secure user input handling allows any unauthenticated attacker to inject commands and run code in the underlying Android operating system.

CVE-2025-70520
NONE

The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce proper authentication restrictions against sessionless users. The lack of restrictions grants anyone the ability to view any device resources such as operational logs or perform diagnostic requests.

CVE-2025-70519
NONE

The device log component of Fanvil x7a firmware version 2.6.0.1182 does not properly sanitize or encode reflected user supplied data. The lack of sanitization allows for the injection of HTML which can be used to execute malicious JavaScript code on any target browser which renders the device log component.

CVE-2025-70518
NONE

The management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user supplied input securely. The lack of secure user input handling allows any unauthenticated attacker to inject commands and run code in the underlying Android operating system.

CVE-2025-70517
NONE

The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applications. Due to the lack of protection, cross-origin boundary can be completely bypassed, allowing for Cross-Site Request Forgery Attacks against any endpoint.

CVE-2025-70516
NONE

The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce proper authentication restrictions against sessionless users. The lack of restrictions grants anyone the ability to view any device resources such as operational logs or perform diagnostic requests.

CVE-2025-70515
NONE

The device log component of Fanvil x7a firmware version 2.6.0.1182 does not properly sanitize or encode reflected user supplied data. The lack of sanitization allows for the injection of HTML which can be used to execute malicious JavaScript code on any target browser which renders the device log component.

CVE-2025-68473
NONE

ESF-IDF Has Out-of-Bounds Read in ESP32 Bluetooth SDP Result Handling

CVE-2025-66447
NONE

Chamilo LMS has validation-less redirect on login page

CVE-1999-1598
NONE

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none