CVE Feed

    Dashboard / CVE

    0.9
    Low

    CVE-2026-1735

    Last Modified: 18 Apr 2026

    A weakness has been identified in Yealink MeetingBar A30 133.321.0.3. This issue affects some unknown processing of the component Diagnostic Handler. This manipulation causes command injection. It is feasible to perform the attack on the physical device. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 2 Feb 2026
    5.3
    Medium

    CVE-2026-1760

    Last Modified: 16 Apr 2026

    A flaw was found in SoupServer. This HTTP request smuggling vulnerability occurs because SoupServer improperly handles requests that combine Transfer-Encoding: chunked and Connection: keep-alive headers. A remote, unauthenticated client can exploit this by sending specially crafted requests, causing SoupServer to fail to close the connection as required by RFC 9112. This allows the attacker to smuggle additional requests over the persistent connection, leading to unintended request processing and potential denial-of-service (DoS) conditions.

    Published: 2 Feb 2026
    6.2
    Medium

    CVE-2026-1757

    Last Modified: 22 Apr 2026

    A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command execution but fails to free the allocated buffer. Repeating this action causes memory to continuously accumulate. Over time, this can exhaust system memory and terminate the xmllint process, creating a denial-of-service condition on the local system.

    Published: 2 Feb 2026
    8.6
    High

    CVE-2026-1761

    Last Modified: 16 Apr 2026

    A flaw was found in libsoup. This stack-based buffer overflow vulnerability occurs during the parsing of multipart HTTP responses due to an incorrect length calculation. A remote attacker can exploit this by sending a specially crafted multipart HTTP response, which can lead to memory corruption. This issue may result in application crashes or arbitrary code execution in applications that process untrusted server responses, and it does not require authentication or user interaction.

    Published: 2 Feb 2026
    5.4
    Medium

    CVE-2025-70959

    Last Modified: 11 Feb 2026

    A stored cross-site scripting (XSS) vulnerability in the Jobs module of Tendenci CMS v15.3.7 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.

    Published: 2 Feb 2026
    6.1
    Medium

    CVE-2025-70958

    Last Modified: 11 Feb 2026

    Multiple reflected cross-site scripting (XSS) vulnerabilities in the installation module of Subrion CMS v4.2.1 allows attackers to execute arbitrary Javascript in the context of the user's browser via injecting a crafted payload into the dbuser, dbpwd, and dbname parameters.

    Published: 2 Feb 2026
    5.4
    Medium

    CVE-2025-70960

    Last Modified: 11 Feb 2026

    A stored cross-site scripting (XSS) vulnerability in the Forums module of Tendenci CMS v15.3.7 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.

    Published: 2 Feb 2026
    5.5
    Medium

    CVE-2026-1734

    Last Modified: 18 Apr 2026

    A security flaw has been discovered in Zhong Bang CRMEB up to 5.6.3. This vulnerability affects unknown code of the file crmeb/app/api/controller/v1/CrontabController.php of the component crontab Endpoint. The manipulation results in missing authorization. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 1 Feb 2026
    2.1
    Low

    CVE-2026-1733

    Last Modified: 18 Apr 2026

    A vulnerability was identified in Zhong Bang CRMEB up to 5.6.3. This affects the function detail/tidyOrder of the file /api/store_integral/order/detail/:uni. The manipulation of the argument order_id leads to improper authorization. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 1 Feb 2026
    8.8
    High

    CVE-2026-25253

    Last Modified: 24 Aug 2026

    OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.

    Published: 1 Feb 2026
    8.5
    High

    CVE-2020-37064

    Last Modified: 15 Apr 2026

    EPSON EasyMP Network Projection 2.81 contains an unquoted service path vulnerability in the EMP_NSWLSV service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\EPSON Projector\EasyMP Network Projection V2\ to inject malicious code that would execute with LocalSystem privileges.

    Published: 1 Feb 2026
    8.5
    High

    CVE-2020-37063

    Last Modified: 15 Apr 2026

    TFTP Turbo 4.6.1273 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will be launched with LocalSystem permissions.

    Published: 1 Feb 2026
    8.5
    High

    CVE-2020-37062

    Last Modified: 15 Apr 2026

    DHCP Turbo 4.61298 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code by exploiting the service binary path. Attackers can place malicious executables in the service path to gain elevated privileges when the service starts.

    Published: 1 Feb 2026
    8.5
    High

    CVE-2020-37061

    Last Modified: 15 Apr 2026

    BOOTP Turbo 2.0.1214 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted executable path to inject malicious code that will be executed when the service starts with LocalSystem permissions.

    Published: 1 Feb 2026
    8.5
    High

    CVE-2020-37055

    Last Modified: 15 Apr 2026

    SpyHunter 4 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path by placing malicious executables in specific file system locations to gain elevated access during service startup.

    Published: 1 Feb 2026
    8.5
    High

    CVE-2020-37048

    Last Modified: 15 Apr 2026

    Iskysoft Application Framework Service 2.4.3.241 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that would be run with the service's high-level system permissions.

    Published: 1 Feb 2026
    8.5
    High

    CVE-2020-37047

    Last Modified: 15 Apr 2026

    Deep Instinct Windows Agent 1.2.29.0 contains an unquoted service path vulnerability in the DeepMgmtService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files\HP Sure Sense\DeepMgmtService.exe to inject malicious code that would execute with LocalSystem permissions during service startup.

    Published: 1 Feb 2026
    8.5
    High

    CVE-2020-37045

    Last Modified: 15 Apr 2026

    Veritas NetBackup 7.0 contains an unquoted service path vulnerability in the NetBackup INET Daemon service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files\Veritas\NetBackup\bin\bpinetd.exe to inject malicious code that would execute with elevated LocalSystem privileges.

    Published: 1 Feb 2026
    8.5
    High

    CVE-2020-37037

    Last Modified: 15 Apr 2026

    Avast SecureLine 5.5.522.0 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem account permissions during service startup.

    Published: 1 Feb 2026
    5.1
    Medium

    CVE-2023-54343

    Last Modified: 15 Apr 2026

    QWE DL 2.0.1 mobile web application contains a persistent input validation vulnerability allowing remote attackers to inject malicious script code through path parameter manipulation. Attackers can exploit the vulnerability to execute persistent cross-site scripting attacks, potentially leading to session hijacking and application module manipulation.

    Published: 1 Feb 2026
    5.1
    Medium

    CVE-2022-50952

    Last Modified: 15 Apr 2026

    Banco Guayaquil 8.0.0 mobile iOS application contains a persistent cross-site scripting vulnerability in the TextBox Name Profile input. Attackers can inject malicious script code through a POST request that executes on application review without user interaction.

    Published: 1 Feb 2026
    5.1
    Medium

    CVE-2022-50951

    Last Modified: 15 Apr 2026

    WiFi File Transfer 1.0.8 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicious script codes through file and folder names. Attackers can exploit the web server's input validation weakness to execute arbitrary JavaScript when users preview infected file paths, potentially compromising user browser sessions.

    Published: 1 Feb 2026
    7.1
    High

    CVE-2022-50950

    Last Modified: 15 Apr 2026

    Webile 1.0.1 contains a directory traversal vulnerability that allows remote attackers to manipulate file system paths without authentication. Attackers can exploit path manipulation to access sensitive system directories and potentially compromise the mobile device's local file system.

    Published: 1 Feb 2026
    7.1
    High

    CVE-2021-47921

    Last Modified: 15 Apr 2026

    Free Photo & Video Vault 0.0.2 contains a directory traversal web vulnerability that allows remote attackers to manipulate application path requests and access sensitive system files. Attackers can exploit the vulnerability without privileges to retrieve environment variables and access unauthorized system paths.

    Published: 1 Feb 2026
    4.8
    Medium

    CVE-2022-50942

    Last Modified: 15 Apr 2026

    Incinga Web 2.8.2 contains a client-side cross-site scripting vulnerability that allows remote attackers to inject malicious script codes through the icinga.min.js file. Attackers can exploit the EventListener.handleEvent method to execute arbitrary scripts, potentially leading to session hijacking and non-persistent phishing attacks.

    Published: 1 Feb 2026
    5.1
    Medium

    CVE-2022-50941

    Last Modified: 15 Apr 2026

    BootCommerce 3.2.1 contains persistent input validation vulnerabilities that allow remote attackers to inject malicious script code through guest order checkout input fields. Attackers can exploit unvalidated input parameters to execute arbitrary scripts, potentially leading to session hijacking, phishing attacks, and application module manipulation.

    Published: 1 Feb 2026
    5.1
    Medium

    CVE-2022-50940

    Last Modified: 15 Apr 2026

    Knap Advanced PHP Login 3.1.3 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicious script code in the name parameter. Attackers can exploit the vulnerability to execute arbitrary scripts in users and activity log backend modules, potentially leading to session hijacking and persistent phishing attacks.

    Published: 1 Feb 2026
    5.1
    Medium

    CVE-2022-50797

    Last Modified: 28 Jul 2026

    Stripe Green Downloads Wordpress Plugin 2.03 contains a persistent cross-site scripting vulnerability allowing remote attackers to inject malicious scripts in button label fields. Attackers can exploit input parameters to execute arbitrary scripts, potentially leading to session hijacking and application module manipulation.

    Published: 1 Feb 2026
    4.8
    Medium

    CVE-2021-47920

    Last Modified: 15 Apr 2026

    WebMO Job Manager 20.0 contains a cross-site scripting vulnerability in search parameters that allows remote attackers to inject malicious script code. Attackers can exploit the filterSearch and filterSearchType parameters to perform non-persistent attacks including session hijacking and external redirects.

    Published: 1 Feb 2026
    5.1
    Medium

    CVE-2021-47919

    Last Modified: 5 Mar 2026

    Simple CMS 2.1 contains a non-persistent cross-site scripting vulnerability in the preview.php file's id parameter. Attackers can inject malicious script code through a GET request to execute arbitrary scripts and potentially hijack user sessions or perform phishing attacks.

    Published: 1 Feb 2026
    8.6
    High

    CVE-2021-47918

    Last Modified: 5 Mar 2026

    Simple CMS 2.1 contains a remote SQL injection vulnerability that allows privileged attackers to inject unfiltered SQL commands in the users module. Attackers can exploit unvalidated input parameters in the admin.php file to compromise the database management system and web application.

    Published: 1 Feb 2026
    5.1
    Medium

    CVE-2021-47917

    Last Modified: 5 Mar 2026

    Simple CMS 2.1 contains a persistent cross-site scripting vulnerability in user input parameters that allows remote attackers to inject malicious script code. Attackers can exploit the newUser and editUser modules to inject persistent scripts that execute on user list preview, potentially leading to session hijacking and application manipulation.

    Published: 1 Feb 2026
    Unknown

    CVE-2021-47916

    Last Modified: 1 Feb 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 1 Feb 2026
    8.6
    High

    CVE-2021-47915

    Last Modified: 5 Mar 2026

    PHP Melody version 3.0 contains a remote SQL injection vulnerability in the video edit module that allows authenticated attackers to inject malicious SQL commands. Attackers can exploit the unvalidated 'vid' parameter to execute arbitrary database queries and potentially compromise the web application and database management system.

    Published: 1 Feb 2026
    5.1
    Medium

    CVE-2021-47914

    Last Modified: 5 Mar 2026

    PHP Melody version 3.0 contains a persistent cross-site scripting vulnerability in the edit-video.php submitted parameter that allows remote attackers to inject malicious script code. Attackers can exploit this vulnerability to execute arbitrary JavaScript, potentially leading to session hijacking, persistent phishing, and manipulation of application modules.

    Published: 1 Feb 2026
    5.1
    Medium

    CVE-2021-47913

    Last Modified: 5 Mar 2026

    PHP Melody 3.0 contains a persistent cross-site scripting vulnerability in the video editor that allows privileged users to inject malicious scripts. Attackers can exploit the WYSIWYG editor to execute persistent scripts, potentially leading to session hijacking and application manipulation.

    Published: 1 Feb 2026
    5.1
    Medium

    CVE-2021-47912

    Last Modified: 5 Mar 2026

    PHP Melody version 3.0 contains multiple non-persistent cross-site scripting vulnerabilities in categories, import, and user import files. Attackers can inject malicious scripts through unvalidated parameters to execute client-side attacks and potentially hijack user sessions.

    Published: 1 Feb 2026
    4.8
    Medium

    CVE-2021-47911

    Last Modified: 15 Apr 2026

    Affiliate Pro 1.7 contains multiple reflected cross-site scripting vulnerabilities in the index module's input fields. Attackers can inject malicious scripts through fullname, username, and email parameters to execute client-side attacks and manipulate browser requests.

    Published: 1 Feb 2026
    8.6
    High

    CVE-2021-47909

    Last Modified: 15 Apr 2026

    Mult-E-Cart Ultimate 2.4 contains multiple SQL injection vulnerabilities in inventory, customer, vendor, and order modules. Remote attackers with privileged vendor or admin roles can exploit the 'id' parameter to execute malicious SQL commands and compromise the database management system.

    Published: 1 Feb 2026
    5.1
    Medium

    CVE-2021-47908

    Last Modified: 15 Apr 2026

    Ultimate POS 4.4 contains a persistent cross-site scripting vulnerability in the product name parameter that allows remote attackers to inject malicious scripts. Attackers can exploit the vulnerability through product add or edit functions to execute arbitrary JavaScript and potentially hijack user sessions.

    Published: 1 Feb 2026
    5.1
    Medium

    CVE-2021-47885

    Last Modified: 15 Apr 2026

    Multiple payment terminal versions contain non-persistent cross-site scripting vulnerabilities in billing and payment information input fields. Attackers can inject malicious script code through vulnerable parameters to manipulate client-side requests and potentially execute session hijacking or phishing attacks.

    Published: 1 Feb 2026
    5.1
    Medium

    CVE-2021-47856

    Last Modified: 15 Apr 2026

    Easy Cart Shopping Cart 2021 contains a non-persistent cross-site scripting vulnerability in the search module's keyword parameter. Remote attackers can inject malicious script code through the search input to compromise user sessions and manipulate application content.

    Published: 1 Feb 2026
    Unknown

    CVE-2026-25251

    Last Modified: 10 Feb 2026

    This has been moved to the REJECTED state because the information source is under review. If circumstances change, it is possible that this will be moved to the PUBLISHED state at a later date.

    Published: 1 Feb 2026
    9.3
    Critical

    CVE-2026-25069

    Last Modified: 18 Apr 2026

    SunFounder Pironman Dashboard (pm_dashboard) version 1.3.13 and prior contain a path traversal vulnerability in the log file API endpoints. An unauthenticated remote attacker can supply traversal sequences via the filename parameter to read and delete arbitrary files. Successful exploitation can disclose sensitive information and delete critical system files, resulting in data loss and potential system compromise or denial of service.

    Published: 31 Jan 2026
    4.3
    Medium

    CVE-2026-1165

    Last Modified: 15 Apr 2026

    The Popup Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.1.1. This is due to a flawed nonce implementation in the 'publish_unpublish_popupbox' function that verifies a self-created nonce rather than one submitted in the request. This makes it possible for unauthenticated attackers to change the publish status of popups via a forged request, granted they can trick a site administrator into performing an action such as clicking a link.

    Published: 31 Jan 2026
    7.2
    High

    CVE-2025-14554

    Last Modified: 22 Apr 2026

    The Sell BTC - Cryptocurrency Selling Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'orderform_data' AJAX action in all versions up to, and including, 1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in order records that will execute whenever an administrator accesses the Orders page in the admin dashboard. The vulnerability was partially patched in version 1.5.

    Published: 31 Jan 2026
    5.4
    Medium

    CVE-2026-1251

    Last Modified: 16 Apr 2026

    The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.4 via the 'add_reply' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to steal file attachments uploaded by other users by specifying arbitrary attachment IDs in the 'description_attachments' parameter, re-associating those files to their own tickets and removing access from the original owners.

    Published: 31 Jan 2026
    6.5
    Medium

    CVE-2026-0683

    Last Modified: 15 Apr 2026

    The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to SQL Injection via the Number-type custom field filter in all versions up to, and including, 3.4.4. This is due to insufficient escaping on the user-supplied operand value when using the equals operator and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above (customers), to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 31 Jan 2026
    5.3
    Medium

    CVE-2025-15525

    Last Modified: 21 Apr 2026

    The Ajax Load More – Infinite Scroll, Load More, & Lazy Load plugin for WordPress is vulnerable to unauthorized access of data due to incorrect authorization on the parse_custom_args() function in all versions up to, and including, 7.8.1. This makes it possible for unauthenticated attackers to expose the titles and excerpts of private, draft, pending, scheduled, and trashed posts.

    Published: 31 Jan 2026
    5.3
    Medium

    CVE-2026-1431

    Last Modified: 16 Apr 2026

    The Booking Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wpbc_ajax_WPBC_FLEXTIMELINE_NAV() function in all versions up to, and including, 10.14.13. This makes it possible for unauthenticated attackers to retrieve booking information including customer names, phones and emails.

    Published: 31 Jan 2026