CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2026-24054

    Last Modified: 18 Apr 2026

    Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 3.26.0, when a container image is malformed or contains no layers, containerd falls back to bind-mounting an empty snapshotter directory for the container rootfs. When the Kata runtime attempts to mount the container rootfs, the bind mount causes the rootfs to be detected as a block device, leading to the underlying device being hotplugged to the guest. This can cause filesystem-level errors on the host due to double inode allocation, and may lead to the host's block device being mounted as read-only. Version 3.26.0 contains a patch for the issue.

    Published: 29 Jan 2026
    7.2
    High

    CVE-2026-23896

    Last Modified: 18 Apr 2026

    immich is a high performance self-hosted photo and video management solution. Prior to version 2.5.0, API keys can escalate their own permissions by calling the update endpoint, allowing a low-privilege API key to grant itself full administrative access to the system. Version 2.5.0 fixes the issue.

    Published: 29 Jan 2026
    2
    Low

    CVE-2026-1598

    Last Modified: 18 Apr 2026

    A vulnerability was found in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. Impacted is an unknown function of the file /dashboard/home/profile of the component User Information Module. Performing a manipulation of the argument fullname results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Jan 2026
    2.1
    Low

    CVE-2026-1597

    Last Modified: 18 Apr 2026

    A vulnerability has been found in Bdtask SalesERP up to 20260116. This issue affects some unknown processing of the component Administrative Endpoint. Such manipulation of the argument ci_session leads to improper authorization. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Jan 2026
    8.3
    High

    CVE-2025-62514

    Last Modified: 2 Mar 2026

    Parsec is a cloud-based application for cryptographically secure file sharing. In versions on the 3.x branch prior to 3.6.0, `libparsec_crypto`, a component of the Parsec application, does not check for weak order point of Curve25519 when compiled with its RustCrypto backend. In practice this means an attacker in a man-in-the-middle position would be able to provide weak order points to both parties in the Diffie-Hellman exchange, resulting in a high probability to for both parties to obtain the same shared key (hence leading to a successful SAS code exchange, misleading both parties into thinking no MITM has occurred) which is also known by the attacker. Note only Parsec web is impacted (as Parsec desktop uses `libparsec_crypto` with the libsodium backend). Version 3.6.0 of Parsec patches the issue.

    Published: 29 Jan 2026
    2.1
    Low

    CVE-2026-1596

    Last Modified: 18 Apr 2026

    A flaw has been found in D-Link DWR-M961 1.1.47. This vulnerability affects the function sub_419920 of the file /boafrm/formLtefotaUpgradeQuectel. This manipulation of the argument fota_url causes command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.

    Published: 29 Jan 2026
    5.5
    Medium

    CVE-2026-1595

    Last Modified: 18 Apr 2026

    A vulnerability was detected in itsourcecode Society Management System 1.0. This affects an unknown part of the file /admin/edit_student_query.php. The manipulation of the argument student_id results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.

    Published: 29 Jan 2026
    5.1
    Medium

    CVE-2026-0936

    Last Modified: 18 Apr 2026

    An Insertion of Sensitive Information into Log File vulnerability in B&R PVI client versions prior to 6.5 may be abused by an authenticated local attacker to gather credential information which is processed by the PVI client application. The logging function of the PVI client application is disabled by default and must be explicitly enabled by the user.

    Published: 29 Jan 2026
    7
    High

    CVE-2025-13905

    Last Modified: 15 Apr 2026

    CWE-276: Incorrect Default Permissions vulnerability exists that could cause privilege escalation through the reverse shell when one or more executable service binaries are modified in the installation folder by a local user with normal privilege upon service restart.

    Published: 29 Jan 2026
    7.5
    High

    CVE-2025-7714

    Last Modified: 5 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Global Interactive Design Media Software Inc. Content Management System (CMS) allows Command Line Execution through SQL Injection. This issue affects Content Management System (CMS): through 21072025.

    Published: 29 Jan 2026
    7.5
    High

    CVE-2025-7713

    Last Modified: 5 Jun 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Global Interactive Design Media Software Inc. Content Management System (CMS) allows XSS Through HTTP Headers. This issue affects Content Management System (CMS): through 21072025.

    Published: 29 Jan 2026
    5.5
    Medium

    CVE-2026-1594

    Last Modified: 18 Apr 2026

    A security vulnerability has been detected in itsourcecode Society Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/add_expenses.php. The manipulation of the argument detail leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.

    Published: 29 Jan 2026
    5.5
    Medium

    CVE-2026-1593

    Last Modified: 18 Apr 2026

    A weakness has been identified in itsourcecode Society Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/edit_expenses_query.php. Executing a manipulation of the argument detail can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.

    Published: 29 Jan 2026
    8.5
    High

    CVE-2020-37021

    Last Modified: 15 Apr 2026

    10-Strike Bandwidth Monitor 3.9 contains an unquoted service path vulnerability in multiple services that allows local attackers to escalate privileges. Attackers can place a malicious executable in specific file path locations to achieve privilege escalation to SYSTEM during service startup.

    Published: 29 Jan 2026
    8.5
    High

    CVE-2020-37020

    Last Modified: 15 Apr 2026

    SonarQube 8.3.1 contains an unquoted service path vulnerability that allows local attackers to gain SYSTEM privileges by exploiting the service executable path. Attackers can replace the wrapper.exe in the service path with a malicious executable to execute code with highest system privileges during service restart.

    Published: 29 Jan 2026
    5.1
    Medium

    CVE-2020-37018

    Last Modified: 15 Apr 2026

    GOautodial 4.0 contains a persistent cross-site scripting vulnerability that allows authenticated agents to inject malicious scripts through message subjects. Attackers can craft messages with embedded JavaScript that will execute when an administrator reads the message, potentially stealing session cookies or executing client-side attacks.

    Published: 29 Jan 2026
    8.5
    High

    CVE-2020-37017

    Last Modified: 15 Apr 2026

    CodeMeter 6.60 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the CodeMeter Runtime Server service to inject malicious code that would execute with LocalSystem permissions.

    Published: 29 Jan 2026
    8.5
    High

    CVE-2020-37016

    Last Modified: 15 Apr 2026

    BarcodeOCR 19.3.6 contains an unquoted service path vulnerability that allows local attackers to execute code with elevated privileges during system startup. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will run with LocalSystem privileges.

    Published: 29 Jan 2026
    7.1
    High

    CVE-2020-37015

    Last Modified: 26 May 2026

    The Ruijie Networks Switch eWeb S29_RGOS version 11.4 contains a directory traversal vulnerability that allows unauthenticated attackers to access sensitive configuration files by manipulating file path parameters. Attackers can exploit the /download.do endpoint with '../' sequences to retrieve system configuration files containing credentials and network settings.

    Published: 29 Jan 2026
    8.4
    High

    CVE-2020-37013

    Last Modified: 12 May 2026

    Audio Playback Recorder 3.2.2 contains a local buffer overflow vulnerability in the eject and registration parameters that allows attackers to execute arbitrary code. Attackers can craft malicious payloads and overwrite Structured Exception Handler (SEH) to execute shellcode when pasting specially crafted input into the application's input fields.

    Published: 29 Jan 2026
    9.3
    Critical

    CVE-2020-37012

    Last Modified: 15 Apr 2026

    Tea LaTex 1.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary shell commands through the /api.php endpoint. Attackers can craft a malicious LaTeX payload with shell commands that are executed when processed by the application's tex2png API action.

    Published: 29 Jan 2026
    8.4
    High

    CVE-2020-37011

    Last Modified: 26 May 2026

    Gnome Fonts Viewer 3.34.0 contains a heap corruption vulnerability that allows attackers to trigger an out-of-bounds write by crafting a malicious TTF font file. Attackers can generate a specially crafted TTF file with an oversized pattern to exhaust memory through repeated malloc() calls and potentially crash the gnome-font-viewer process.

    Published: 29 Jan 2026
    8.4
    High

    CVE-2020-37010

    Last Modified: 15 Jul 2026

    BearShare Lite 5.2.5 contains a buffer overflow vulnerability in the Advanced Search keywords input that allows attackers to execute arbitrary code. Attackers can craft a specially designed payload to overwrite the EIP register and execute shellcode by pasting malicious content into the search keywords field.

    Published: 29 Jan 2026
    8.7
    High

    CVE-2020-37009

    Last Modified: 15 Apr 2026

    MedDream PACS Server 6.8.3.751 contains an authenticated remote code execution vulnerability that allows authorized users to upload malicious PHP files. Attackers can exploit the uploadImage.php endpoint by authenticating and uploading a PHP shell to execute arbitrary system commands with elevated privileges.

    Published: 29 Jan 2026
    8.7
    High

    CVE-2020-37008

    Last Modified: 12 May 2026

    EasyPMS 1.0.0 contains an authentication bypass vulnerability that allows unprivileged users to manipulate SQL queries in JSON requests to access admin user information. Attackers can exploit weak input validation by injecting single quotes in ID parameters and modify admin user passwords without proper token authentication.

    Published: 29 Jan 2026
    5.1
    Medium

    CVE-2020-37007

    Last Modified: 5 Mar 2026

    Liman 0.7 contains a cross-site request forgery vulnerability that allows attackers to manipulate user account settings without proper request validation. Attackers can craft malicious HTML forms to change user passwords or modify account information by tricking logged-in users into submitting unauthorized requests.

    Published: 29 Jan 2026
    7.1
    High

    CVE-2020-37006

    Last Modified: 12 May 2026

    berliCRM 1.0.24 contains a SQL injection vulnerability in the 'src_record' parameter that allows remote attackers to manipulate database queries. Attackers can inject malicious SQL code through a crafted POST request to the index.php endpoint to potentially extract or modify database information.

    Published: 29 Jan 2026
    7.1
    High

    CVE-2020-37005

    Last Modified: 15 Apr 2026

    TimeClock Software 1.01 contains an authenticated time-based SQL injection vulnerability that allows attackers to enumerate valid usernames by manipulating the 'notes' parameter. Attackers can inject conditional time delays in the add_entry.php endpoint to determine user existence by measuring response time differences.

    Published: 29 Jan 2026
    7.1
    High

    CVE-2020-37004

    Last Modified: 15 Jul 2026

    The Ultimate Project Manager CRM PRO version 2.0.5 contains a blind SQL injection vulnerability that allows attackers to extract usernames and password hashes from the tbl_users database table. Attackers can exploit the /frontend/get_article_suggestion/ endpoint by crafting malicious search parameters to progressively guess and retrieve user credentials through boolean-based inference techniques.

    Published: 29 Jan 2026
    8.7
    High

    CVE-2020-37002

    Last Modified: 25 May 2026

    Ajenti 2.1.36 contains a post-authenticated remote command execution vulnerability that allows remote attackers to execute arbitrary commands after successful login. Attackers can leverage the /api/terminal/create endpoint to send a netcat reverse shell payload targeting a specified IP and port.

    Published: 29 Jan 2026
    8.4
    High

    CVE-2020-37001

    Last Modified: 12 May 2026

    Frigate Professional 3.36.0.9 contains a local buffer overflow vulnerability in the Pack File feature that allows attackers to execute arbitrary code by overflowing the 'Archive To' input field. Attackers can craft a malicious payload that overwrites the Structured Exception Handler (SEH) and uses an egghunter technique to execute a reverse shell payload.

    Published: 29 Jan 2026
    8.4
    High

    CVE-2020-37000

    Last Modified: 12 May 2026

    Free MP3 CD Ripper 2.8 contains a stack buffer overflow vulnerability that allows remote attackers to execute arbitrary code by crafting a malicious WAV file with oversized payload. Attackers can leverage a specially crafted exploit file with shellcode, SEH bypass, and egghunter technique to achieve remote code execution on vulnerable Windows systems.

    Published: 29 Jan 2026
    8.8
    High

    CVE-2020-36999

    Last Modified: 15 Apr 2026

    Elaniin CMS 1.0 contains an authentication bypass vulnerability that allows attackers to access the dashboard by manipulating the login page with SQL injection. Attackers can bypass authentication by sending crafted email and password parameters with '=''or' payload to login.php, granting unauthorized access to the system.

    Published: 29 Jan 2026
    8.4
    High

    CVE-2020-36997

    Last Modified: 12 May 2026

    BacklinkSpeed 2.4 contains a buffer overflow vulnerability that allows attackers to corrupt the Structured Exception Handler (SEH) chain through malicious file import. Attackers can craft a specially designed payload file to overwrite SEH addresses, potentially executing arbitrary code and gaining control of the application.

    Published: 29 Jan 2026
    4.6
    Medium

    CVE-2020-36995

    Last Modified: 12 May 2026

    Mocha Telnet Lite for iOS 4.2 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the user configuration input. Attackers can overwrite the 'User' field with 350 bytes of repeated characters to trigger an application crash and prevent normal functionality.

    Published: 29 Jan 2026
    4.6
    Medium

    CVE-2020-36994

    Last Modified: 12 May 2026

    QlikView 12.50.20000.0 contains a denial of service vulnerability in the FTP server address input field that allows local attackers to crash the application. Attackers can paste a 300-character buffer into the FTP server address field to trigger an application crash and prevent normal functionality.

    Published: 29 Jan 2026
    5.5
    Medium

    CVE-2026-1590

    Last Modified: 18 Apr 2026

    A vulnerability was identified in itsourcecode School Management System 1.0. This impacts an unknown function of the file /ramonsys/faculty/index.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.

    Published: 29 Jan 2026
    5.5
    Medium

    CVE-2026-1589

    Last Modified: 18 Apr 2026

    A vulnerability was determined in itsourcecode School Management System 1.0. This affects an unknown function of the file /ramonsys/inquiry/index.php. This manipulation of the argument txtsearch causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.

    Published: 29 Jan 2026
    5.7
    Medium

    CVE-2025-7014

    Last Modified: 5 Jun 2026

    Session Fixation vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Session Hijacking. This issue affects Menu Panel: through 29012026.  NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Jan 2026
    5.7
    Medium

    CVE-2025-7013

    Last Modified: 5 Jun 2026

    Authorization Bypass Through User-Controlled Key vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Exploitation of Trusted Identifiers. This issue affects Menu Panel: through 29012026.  NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Jan 2026
    7.5
    High

    CVE-2026-1616

    Last Modified: 18 Apr 2026

    The $uri$args concatenation in nginx configuration file present in Open Security Issue Management (OSIM) prior v2025.9.0 allows path traversal attacks via query parameters.

    Published: 29 Jan 2026
    2
    Low

    CVE-2026-1588

    Last Modified: 18 Apr 2026

    A vulnerability was found in jishenghua jshERP up to 3.6. The impacted element is the function install of the file /jshERP-boot/plugin/installByPath of the component com.gitee.starblues.integration.operator.DefaultPluginOperator. The manipulation of the argument path results in path traversal. It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 29 Jan 2026
    5.5
    Medium

    CVE-2026-1587

    Last Modified: 18 Apr 2026

    A vulnerability has been found in Open5GS up to 2.7.6. The affected element is the function sgwc_s11_handle_modify_bearer_request of the file /sgwc/s11-handler.c of the component SGWC. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Applying a patch is the recommended action to fix this issue. The issue report is flagged as already-fixed.

    Published: 29 Jan 2026
    5.5
    Medium

    CVE-2026-1586

    Last Modified: 18 Apr 2026

    A flaw has been found in Open5GS up to 2.7.5. Impacted is the function ogs_gtp2_f_teid_to_ip of the file /sgwc/s11-handler.c of the component SGWC. Executing a manipulation can lead to denial of service. The attack may be performed from remote. The exploit has been published and may be used. It is advisable to implement a patch to correct this issue. The issue report is flagged as already-fixed.

    Published: 29 Jan 2026
    8
    High

    CVE-2025-7016

    Last Modified: 5 Jun 2026

    Improper Access Control vulnerability in Akın Software Computer Import Export Industry and Trade Ltd. QR Menu allows Authentication Abuse. This issue affects QR Menu: before s1.05.12.

    Published: 29 Jan 2026
    5.7
    Medium

    CVE-2025-7015

    Last Modified: 5 Jun 2026

    Session Fixation vulnerability in Akın Software Computer Import Export Industry and Trade Ltd. QR Menu allows Session Fixation. This issue affects QR Menu: before s1.05.12.

    Published: 29 Jan 2026
    6.9
    Medium

    CVE-2026-1469

    Last Modified: 18 Apr 2026

    Stored Cross-Site Scripting (XSS) in RLE NOVA's PlanManager. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by injecting malicious payload through the ‘comment’ and ‘brand’ parameters in ‘/index.php’. The payload is stored by the application and subsequently displayed without proper sanitization when other users access it. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.

    Published: 29 Jan 2026
    4.3
    Medium

    CVE-2026-22764

    Last Modified: 18 Apr 2026

    Dell OpenManage Network Integration, versions prior to 3.9, contains an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

    Published: 29 Jan 2026
    Unknown

    CVE-2026-25097

    Last Modified: 30 Jan 2026

    Not used

    Published: 29 Jan 2026
    Unknown

    CVE-2026-25091

    Last Modified: 30 Jan 2026

    Not used

    Published: 29 Jan 2026