CVE Feed

    Dashboard / CVE

    6.9
    Medium

    CVE-2024-9432

    Last Modified: 15 Apr 2026

    Cleartext Storage of Sensitive Information vulnerability in OpenText™ Vertica allows Retrieve Embedded Sensitive Data.   The vulnerability could read Vertica agent plaintext apikey.This issue affects Vertica versions: 23.X, 24.X, 25.X.

    Published: 30 Jan 2026
    3.8
    Low

    CVE-2025-15497

    Last Modified: 15 Apr 2026

    Insufficient epoch key slot processing in OpenVPN 2.7_alpha1 through 2.7_rc5 allows remote authenticated users to trigger an assert resulting in a denial of service

    Published: 30 Jan 2026
    2.1
    Low

    CVE-2026-1702

    Last Modified: 18 Apr 2026

    A vulnerability was detected in SourceCodester Pet Grooming Management Software 1.0. Impacted is an unknown function of the file /admin/operation/user.php of the component User Management. Performing a manipulation of the argument group_id results in improper authorization. The attack can be initiated remotely. The exploit is now public and may be used.

    Published: 30 Jan 2026
    5.5
    Medium

    CVE-2026-1701

    Last Modified: 18 Apr 2026

    A security vulnerability has been detected in itsourcecode School Management System 1.0. This issue affects some unknown processing of the file /enrollment/index.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. Due to contradicting product definitions in the original disclosure, this CVE was initially incorrectly assigned to the Student Management System.

    Published: 30 Jan 2026
    2
    Low

    CVE-2026-1700

    Last Modified: 18 Apr 2026

    A weakness has been identified in projectworlds House Rental and Property Listing 1.0. This vulnerability affects unknown code of the file /app/sms.php. This manipulation of the argument Message causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.

    Published: 30 Jan 2026
    2.1
    Low

    CVE-2026-1691

    Last Modified: 18 Apr 2026

    A vulnerability has been found in bolo-solo up to 2.6.4. This impacts the function importMarkdownsSync of the file src/main/java/org/b3log/solo/bolo/prop/BackupService.java of the component SnakeYAML. Such manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jan 2026
    2
    Low

    CVE-2026-1690

    Last Modified: 18 Apr 2026

    A flaw has been found in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. This affects the function system of the file /boaform/formSysCmd. This manipulation of the argument sysCmd causes command injection. The attack may be initiated remotely. The exploit has been published and may be used.

    Published: 30 Jan 2026
    5.5
    Medium

    CVE-2026-1689

    Last Modified: 18 Apr 2026

    A vulnerability was detected in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. The impacted element is the function checkUserFromLanOrWan of the file /boaform/admin/formLogin of the component Login Interface. The manipulation of the argument Host results in command injection. The attack can be launched remotely. The exploit is now public and may be used.

    Published: 30 Jan 2026
    8.5
    High

    CVE-2020-37060

    Last Modified: 15 Apr 2026

    Atomic Alarm Clock 6.3 contains a local privilege escalation vulnerability in its service configuration that allows attackers to execute arbitrary code with SYSTEM privileges. Attackers can exploit the unquoted service path by placing a malicious executable named 'Program.exe' to gain persistent system-level access.

    Published: 30 Jan 2026
    8.5
    High

    CVE-2020-37059

    Last Modified: 15 Apr 2026

    Popcorn Time 6.2.1.14 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can insert malicious executables in Program Files (x86) or system root directories to be executed with SYSTEM-level permissions during service startup.

    Published: 30 Jan 2026
    8.5
    High

    CVE-2020-37058

    Last Modified: 15 Apr 2026

    Andrea ST Filters Service 1.0.64.7 contains an unquoted service path vulnerability in its Windows service configuration. Local attackers can exploit the unquoted path to inject malicious code that will execute with elevated LocalSystem privileges during service startup.

    Published: 30 Jan 2026
    8.5
    High

    CVE-2020-37030

    Last Modified: 15 Apr 2026

    Outline Service 1.3.3 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in C:\Program Files (x86)\Outline to inject malicious code that would execute with LocalSystem permissions during service startup.

    Published: 30 Jan 2026
    5.1
    Medium

    CVE-2020-37022

    Last Modified: 15 Apr 2026

    OpenZ ERP 3.6.60 contains a persistent cross-site scripting vulnerability in the Employee module's name and description parameters. Attackers can inject malicious scripts through POST requests to , enabling session hijacking and manipulation of application modules.

    Published: 30 Jan 2026
    5.1
    Medium

    CVE-2020-37019

    Last Modified: 15 Apr 2026

    Orchard Core RC1 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicious scripts through blog post creation. Attackers can create blog posts with embedded JavaScript in the MarkdownBodyPart.Source parameter to execute arbitrary scripts in victim browsers.

    Published: 30 Jan 2026
    5.1
    Medium

    CVE-2020-37014

    Last Modified: 15 Apr 2026

    Tryton 5.4 contains a persistent cross-site scripting vulnerability in the user profile name input that allows remote attackers to inject malicious scripts. Attackers can exploit the vulnerability by inserting script payloads in the name field, which execute in the frontend and backend user interfaces.

    Published: 30 Jan 2026
    5.1
    Medium

    CVE-2020-37003

    Last Modified: 15 Apr 2026

    Sellacious eCommerce 4.6 contains a persistent cross-site scripting vulnerability in the Manage Your Addresses module that allows attackers to inject malicious scripts. Attackers can exploit multiple address input fields like full name, company, and address to execute persistent script code that can hijack user sessions and manipulate application modules.

    Published: 30 Jan 2026
    5.1
    Medium

    CVE-2020-36998

    Last Modified: 15 Apr 2026

    Forma.lms The E-Learning Suite 2.3.0.2 contains a persistent cross-site scripting vulnerability in multiple course and profile parameters. Attackers can inject malicious scripts in course code, name, description fields, and email parameter to execute arbitrary JavaScript without proper input sanitization.

    Published: 30 Jan 2026
    5.1
    Medium

    CVE-2020-36996

    Last Modified: 15 Apr 2026

    PHPFusion 9.03.50 contains a persistent cross-site scripting vulnerability in the print.php page that fails to properly sanitize user-submitted message content. Attackers can inject malicious JavaScript through forum messages that will execute when the print page is generated, allowing script execution in victim browsers.

    Published: 30 Jan 2026
    5.1
    Medium

    CVE-2020-36966

    Last Modified: 15 Apr 2026

    Dolibarr 11.0.3 contains a persistent cross-site scripting vulnerability in LDAP synchronization settings that allows attackers to inject malicious scripts through multiple parameters. Attackers can exploit the host, slave, and port parameters in /dolibarr/admin/ldap.php to execute arbitrary JavaScript and potentially steal user cookie information.

    Published: 30 Jan 2026
    5.5
    Medium

    CVE-2026-1688

    Last Modified: 18 Apr 2026

    A security vulnerability has been detected in itsourcecode Directory Management System 1.0. The affected element is an unknown function of the file /admin/index.php. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.

    Published: 30 Jan 2026
    5.5
    Medium

    CVE-2026-1687

    Last Modified: 18 Apr 2026

    A weakness has been identified in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. Impacted is an unknown function of the file /boaform/formSamba of the component Boa Webserver. Executing a manipulation of the argument serverString can lead to command injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.

    Published: 30 Jan 2026
    8.6
    High

    CVE-2025-4686

    Last Modified: 5 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kodmatic Computer Software Tourism Construction Industry and Trade Ltd. Co. Online Exam and Assessment allows SQL Injection. This issue affects Online Exam and Assessment: through 30012026.  NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 30 Jan 2026
    7.5
    High

    CVE-2026-25128

    Last Modified: 18 Apr 2026

    fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 5.0.9 through 5.3.3, a RangeError vulnerability exists in the numeric entity processing of fast-xml-parser when parsing XML with out-of-range entity code points (e.g., `�` or `�`). This causes the parser to throw an uncaught exception, crashing any application that processes untrusted XML input. Version 5.3.4 fixes the issue.

    Published: 30 Jan 2026
    2.7
    Low

    CVE-2026-25050

    Last Modified: 18 Apr 2026

    Vendure is an open-source headless commerce platform. Prior to version 3.5.3, the `NativeAuthenticationStrategy.authenticate()` method is vulnerable to a timing attack that allows attackers to enumerate valid usernames (email addresses). In `packages/core/src/config/auth/native-authentication-strategy.ts`, the authenticate method returns immediately if a user is not found. The significant timing difference (~200-400ms for bcrypt vs ~1-5ms for DB miss) allows attackers to reliably distinguish between existing and non-existing accounts. Version 3.5.3 fixes the issue.

    Published: 30 Jan 2026
    7.2
    High

    CVE-2026-24855

    Last Modified: 18 Apr 2026

    ChurchCRM is an open-source church management system. Versions prior to 6.7.2 have a Stored Cross-Site Scripting (XSS) vulnerability occurs in Create Events in Church Calendar. Users with low privileges can create XSS payloads in the Description field. This payload is stored in the database, and when other users view that event (including the admin), the payload is triggered, leading to account takeover. Version 6.7.2 fixes the vulnerability.

    Published: 30 Jan 2026
    8.8
    High

    CVE-2026-24854

    Last Modified: 18 Apr 2026

    ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in endpoint `/PaddleNumEditor.php` in ChurchCRM prior to version 6.7.2. Any authenticated user, including one with zero assigned permissions, can exploit SQL injection through the `PerID` parameter. Version 6.7.2 contains a patch for the issue.

    Published: 30 Jan 2026
    9.2
    Critical

    CVE-2025-7964

    Last Modified: 15 Apr 2026

    After receiving a malformed 802.15.4 MAC Data Request the Zigbee Coordinator sends a ‘network leave’ request to Zigbee router resulting in the Zigbee Router getting stuck in a non-rejoinable state. If a suitable parent is not available, the end devices will be unable to rejoin. A manual recommissioning is required to recover the Zigbee Router.

    Published: 30 Jan 2026
    7.4
    High

    CVE-2026-1686

    Last Modified: 18 Apr 2026

    A security flaw has been discovered in Totolink A3600R 5.9c.4959. This issue affects the function setAppEasyWizardConfig in the library /lib/cste_modules/app.so. Performing a manipulation of the argument apcliSsid results in buffer overflow. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.

    Published: 30 Jan 2026
    2.9
    Low

    CVE-2026-1685

    Last Modified: 18 Apr 2026

    A vulnerability was identified in D-Link DIR-823X 250416. This vulnerability affects the function sub_40AC74 of the component Login. Such manipulation leads to improper restriction of excessive authentication attempts. The attack may be performed from remote. This attack is characterized by high complexity. It is stated that the exploitability is difficult. The exploit is publicly available and might be used.

    Published: 30 Jan 2026
    6.9
    Medium

    CVE-2026-1684

    Last Modified: 18 Apr 2026

    A vulnerability was found in Free5GC SMF up to 4.1.0. Affected by this issue is the function HandleReports of the file /internal/context/pfcp_reports.go of the component PFCP UDP Endpoint. The manipulation results in denial of service. The attack can be executed remotely. It is advisable to implement a patch to correct this issue.

    Published: 30 Jan 2026
    5.8
    Medium

    CVE-2025-6723

    Last Modified: 15 Apr 2026

    Chef InSpec versions up to 5.23 and before 7.0.107 creates named pipes with overly permissive default Windows access controls. A local attacker may interfere with the pipe connection process and exploit the insufficient access restrictions to assume the InSpec execution context, potentially resulting in elevated privileges or operational disruption. This issue affects Chef Inspec: through 5.23 and before 7.0.107

    Published: 30 Jan 2026
    5.5
    Medium

    CVE-2026-1683

    Last Modified: 18 Apr 2026

    A vulnerability has been found in Free5GC SMF up to 4.1.0. Affected by this vulnerability is the function HandlePfcpSessionReportRequest of the file internal/pfcp/handler/handler.go of the component PFCP. The manipulation leads to denial of service. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. To fix this issue, it is recommended to deploy a patch.

    Published: 30 Jan 2026
    5.5
    Medium

    CVE-2026-1682

    Last Modified: 18 Apr 2026

    A flaw has been found in Free5GC SMF up to 4.1.0. Affected is the function HandlePfcpAssociationReleaseRequest of the file internal/pfcp/handler/handler.go of the component PFCP UDP Endpoint. Executing a manipulation can lead to null pointer dereference. The attack may be launched remotely. The exploit has been published and may be used. A patch should be applied to remediate this issue.

    Published: 30 Jan 2026
    7.5
    High

    CVE-2024-4027

    Last Modified: 31 Aug 2026

    A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an OutOfMemoryError when the client sends a request with large parameter names. This issue can be exploited by an unauthorized user to cause a remote denial-of-service (DoS) attack.

    Published: 30 Jan 2026
    4.6
    Medium

    CVE-2025-9226

    Last Modified: 15 Apr 2026

    Zohocorp ManageEngine OpManager, NetFlow Analyzer, and OpUtils versions prior to 128582 are affected by a stored cross-site scripting vulnerability in the Subnet Details.

    Published: 30 Jan 2026
    7
    High

    CVE-2026-1498

    Last Modified: 10 Aug 2026

    An LDAP Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensitive information from a connected LDAP authentication server through an exposed authentication or management web interface. This vulnerability may also allow a remote attacker to authenticate as an LDAP user with a partial identifier if they additionally have that user's valid passphrase.

    Published: 30 Jan 2026
    8.4
    High

    CVE-2025-13176

    Last Modified: 15 Apr 2026

    Planting a custom configuration file in ESET Inspect Connector allow load a malicious DLL.

    Published: 30 Jan 2026
    9.5
    Critical

    CVE-2025-26385

    Last Modified: 15 Apr 2026

    Johnson Controls Metasys component listed below have Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability . Successful exploitation of this vulnerability could allow remote SQL execution This issue affects  * Metasys: Application and Data Server (ADS) installed with SQL Express deployed as part of the Metasys 14.1 and prior installation,  * Extended Application and Data Server (ADX) installed with SQL Express deployed as part of the Metasys 14.1 installation,  * LCS8500 or NAE8500 installed with SQL Express deployed as part of the Metasys installation Releases 12.0 through 14.1,  * System Configuration Tool (SCT) installed with SQL Express deployed as part of the SCT installation 17.1 and prior,  * Controller Configuration Tool (CCT) installed with SQL Express deployed as part of the CCT installation 17.0 and prior.

    Published: 30 Jan 2026
    4.9
    Medium

    CVE-2026-22626

    Last Modified: 18 Apr 2026

    Due to insufficient input parameter validation on the interface, authenticated users of certain HIKSEMI NAS products can cause abnormal device behavior by crafting specific messages.

    Published: 30 Jan 2026
    4.6
    Medium

    CVE-2026-22625

    Last Modified: 18 Apr 2026

    Improper handling of filenames in certain HIKSEMI NAS products may lead to the exposure of sensitive system files.

    Published: 30 Jan 2026
    4.3
    Medium

    CVE-2026-22624

    Last Modified: 18 Apr 2026

    Due to inadequate access control, authenticated users of certain HIKSEMI NAS products can manipulate other users' file resources without proper authorization.

    Published: 30 Jan 2026
    7.2
    High

    CVE-2026-22623

    Last Modified: 18 Apr 2026

    Due to insufficient input parameter validation on the interface, authenticated users of certain HIKSEMI NAS products can execute arbitrary commands on the device by crafting specific messages.

    Published: 30 Jan 2026
    7.2
    High

    CVE-2026-0709

    Last Modified: 18 Apr 2026

    Some Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution.

    Published: 30 Jan 2026
    10
    Critical

    CVE-2026-1699

    Last Modified: 18 Apr 2026

    In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_target trigger while checking out and executing untrusted pull request code. This allowed any GitHub user to execute arbitrary code in the repository's CI environment with access to repository secrets and a GITHUB_TOKEN with extensive write permissions (contents:write, packages:write, pages:write, actions:write). An attacker could exfiltrate secrets, publish malicious packages to the eclipse-theia organization, modify the official Theia website, and push malicious code to the repository.

    Published: 30 Jan 2026
    7.8
    High

    CVE-2026-21418

    Last Modified: 18 Apr 2026

    Dell Unity, version(s) 5.5.2 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.

    Published: 30 Jan 2026
    8.2
    High

    CVE-2025-1395

    Last Modified: 7 Aug 2026

    Generation of Error Message Containing Sensitive Information vulnerability in Codriapp Innovation and Software Technologies Inc. HeyGarson allows Fuzzing for application mapping. This issue affects HeyGarson: through 30012026.  NOTE: The vendor was contacted and it was learned that the product is not supported.

    Published: 30 Jan 2026
    7.8
    High

    CVE-2026-22277

    Last Modified: 18 Apr 2026

    Dell UnityVSA, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.

    Published: 30 Jan 2026
    6.9
    Medium

    CVE-2026-25210

    Last Modified: 2 Jun 2026

    In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.

    Published: 30 Jan 2026
    8.2
    High

    CVE-2026-0805

    Last Modified: 18 Apr 2026

    An input neutralization vulnerability in the Backup Configuration component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remote code execution via path traversal.

    Published: 30 Jan 2026
    9.9
    Critical

    CVE-2026-0963

    Last Modified: 18 Apr 2026

    An input neutralization vulnerability in the File Operations API Endpoint component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remote code execution via path traversal.

    Published: 30 Jan 2026