CVE Feed

    Dashboard / CVE

    Unknown

    CVE-2026-25092

    Last Modified: 30 Jan 2026

    Not used

    Published: 29 Jan 2026
    Unknown

    CVE-2026-25093

    Last Modified: 30 Jan 2026

    Not used

    Published: 29 Jan 2026
    Unknown

    CVE-2026-25094

    Last Modified: 30 Jan 2026

    Not used

    Published: 29 Jan 2026
    Unknown

    CVE-2026-25095

    Last Modified: 30 Jan 2026

    Not used

    Published: 29 Jan 2026
    Unknown

    CVE-2026-25096

    Last Modified: 30 Jan 2026

    Not used

    Published: 29 Jan 2026
    Unknown

    CVE-2026-25090

    Last Modified: 30 Jan 2026

    Not used

    Published: 29 Jan 2026
    6.5
    Medium

    CVE-2026-23570

    Last Modified: 18 Apr 2026

    A missing validation of a user-controlled value in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an adjacent network attacker to tamper with log timestamps via crafted UDP Sync command. This could result in forged or nonsensical datetime prefixes and compromising log integrity and forensic correlation.

    Published: 29 Jan 2026
    6.5
    Medium

    CVE-2026-23569

    Last Modified: 18 Apr 2026

    An out-of-bounds read vulnerability in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows a remote attacker to leak stack memory and cause a denial of service via a crafted request. The leaked stack memory could be used to bypass ASLR remotely and facilitate exploitation of other vulnerabilities on the affected system.

    Published: 29 Jan 2026
    5.4
    Medium

    CVE-2026-23568

    Last Modified: 18 Apr 2026

    An out-of-bounds read vulnerability in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to cause information disclosure or denial-of-service via a special crafted packet. The leaked memory could be used to bypass ASLR and facilitate further exploitation.

    Published: 29 Jan 2026
    6.5
    Medium

    CVE-2026-23567

    Last Modified: 18 Apr 2026

    An integer underflow in the UDP command handler of the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an adjacent network attacker to trigger a heap-based buffer overflow and cause a denial-of-service (service crash) via specially crafted UDP packets.

    Published: 29 Jan 2026
    6.5
    Medium

    CVE-2026-23566

    Last Modified: 18 Apr 2026

    A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to inject, tamper with, or forge log entries in \Nomad Branch.log via crafted data sent to the UDP network handler. This can impact log integrity and nonrepudiation.

    Published: 29 Jan 2026
    6.5
    Medium

    CVE-2026-23565

    Last Modified: 18 Apr 2026

    A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to cause the NomadBranch.exe process to terminate via crafted requests. This can result in a denial-of-service condition of the Content Distribution Service.

    Published: 29 Jan 2026
    6.5
    Medium

    CVE-2026-23564

    Last Modified: 18 Apr 2026

    A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to cause normally encrypted UDP traffic to be sent in cleartext. This can result in disclosure of sensitive information.

    Published: 29 Jan 2026
    6.8
    Medium

    CVE-2026-23571

    Last Modified: 18 Apr 2026

    A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-RunPkgStatusRequest instruction. Improper input validation allows authenticated attackers with actioner privilege to run elevated arbitrary commands on connected hosts via malicious commands injected into the instruction’s input field. Users of 1E Client version 24.5 or higher are not affected.

    Published: 29 Jan 2026
    5.7
    Medium

    CVE-2026-23563

    Last Modified: 18 Apr 2026

    Improper Link Resolution Before File Access (invoked by 1E‑Explorer‑TachyonCore‑DeleteFileByPath instruction) in TeamViewer DEX - 1E Client before version 26.1 on Windows allows a low‑privileged local attacker to delete protected system files via a crafted RPC control junction or symlink that is followed when the delete instruction executes.

    Published: 29 Jan 2026
    6.9
    Medium

    CVE-2026-1188

    Last Modified: 18 Apr 2026

    In the Eclipse OMR port library component since release 0.2.0, an API function to return the textual names of all supported processor features was not accounting for the separator inserted between processor features. If the output buffer supplied to this function was incorrectly sized, failing to account for the separator when determining when a write to the buffer was safe could lead to a buffer overflow. This issue is fixed in Eclipse OMR version 0.8.0.

    Published: 29 Jan 2026
    8.1
    High

    CVE-2025-14975

    Last Modified: 15 Apr 2026

    The Custom Login Page Customizer WordPress plugin before 2.5.4 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account

    Published: 29 Jan 2026
    6.9
    Medium

    CVE-2026-25067

    Last Modified: 18 Apr 2026

    SmarterTools SmarterMail versions prior to build 9518 contain an unauthenticated path coercion vulnerability in the background-of-the-day preview endpoint. The application base64-decodes attacker-supplied input and uses it as a filesystem path without validation. On Windows systems, this allows UNC paths to be resolved, causing the SmarterMail service to initiate outbound SMB authentication attempts to attacker-controlled hosts. This can be abused for credential coercion, NTLM relay attacks, and unauthorized network authentication.

    Published: 29 Jan 2026
    6.9
    Medium

    CVE-2025-55704

    Last Modified: 15 Apr 2026

    Hidden functionality issue exists in multiple MFPs provided by Brother Industries, Ltd., which may allow an attacker to obtain the logs of the affected product and obtain sensitive information within the logs.

    Published: 29 Jan 2026
    6.3
    Medium

    CVE-2025-53869

    Last Modified: 15 Apr 2026

    Multiple MFPs provided by Brother Industries, Ltd. does not properly validate server certificates, which may allow a man-in-the-middle attacker to replace the set of root certificates used by the product with a set of arbitrary certificates.

    Published: 29 Jan 2026
    2.1
    Low

    CVE-2026-1552

    Last Modified: 18 Apr 2026

    A security vulnerability has been detected in SEMCMS 5.0. This vulnerability affects unknown code of the file /SEMCMS_Info.php. The manipulation of the argument searchml leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Jan 2026
    9.8
    Critical

    CVE-2025-69929

    Last Modified: 27 Feb 2026

    An issue in N3uron Web User Interface v.1.21.7-240207.1047 allows a remote attacker to escalate privileges via the password hashing on the client side using the MD5 algorithm over a predictable string format

    Published: 29 Jan 2026
    7.5
    High

    CVE-2025-63651

    Last Modified: 19 Feb 2026

    A use-after-free in the mk_string_char_search function (mk_core/mk_string.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

    Published: 29 Jan 2026
    7.8
    High

    CVE-2025-69604

    Last Modified: 13 Feb 2026

    An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to install an arbitrary package that can run shell scripts with root privileges and Full Disk Access, thus bypassing macOS privacy controls.

    Published: 29 Jan 2026
    7.5
    High

    CVE-2025-63657

    Last Modified: 13 Feb 2026

    An out-of-bounds read in the mk_mimetype_find function (mk_server/mk_mimetype.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

    Published: 29 Jan 2026
    7.5
    High

    CVE-2025-63656

    Last Modified: 13 Feb 2026

    An out-of-bounds read in the header_cmp function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

    Published: 29 Jan 2026
    7.5
    High

    CVE-2025-63653

    Last Modified: 13 Feb 2026

    An out-of-bounds read in the mk_vhost_fdt_close function (mk_server/mk_vhost.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

    Published: 29 Jan 2026
    7.5
    High

    CVE-2025-63652

    Last Modified: 13 Feb 2026

    A use-after-free in the mk_http_request_end function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

    Published: 29 Jan 2026
    6.1
    Medium

    CVE-2025-69749

    Last Modified: 19 Feb 2026

    Cross Site Scripting vulnerability in tale v.2.0.5 allows an attacker to execute arbitrary code.

    Published: 29 Jan 2026
    7.5
    High

    CVE-2025-63655

    Last Modified: 13 Feb 2026

    A NULL pointer dereference in the mk_http_range_parse function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

    Published: 29 Jan 2026
    6.2
    Medium

    CVE-2025-71011

    Last Modified: 3 Feb 2026

    An input validation vulnerability in the flow.Tensor.new_empty/flow.Tensor.new_ones/flow.Tensor.new_zeros component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.

    Published: 29 Jan 2026
    7.5
    High

    CVE-2025-63658

    Last Modified: 13 Feb 2026

    A stack overflow in the mk_http_index_lookup function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

    Published: 29 Jan 2026
    5.4
    Medium

    CVE-2025-45160

    Last Modified: 15 Apr 2026

    A HTML injection vulnerability exists in the file upload functionality of Cacti <= 1.2.29. When a file with an invalid format is uploaded, the application reflects the submitted filename back into an error popup without proper sanitization. As a result, attackers can inject arbitrary HTML elements (e.g., <h1>, <b>, <svg>) into the rendered page. NOTE: Multiple third-parties including the maintainer have stated that they cannot reproduce this issue after 1.2.27.

    Published: 29 Jan 2026
    7.5
    High

    CVE-2025-63649

    Last Modified: 19 Feb 2026

    An out-of-bounds read in the http_parser_transfer_encoding_chunked function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted POST request to the server.

    Published: 29 Jan 2026
    8.8
    High

    CVE-2025-69516

    Last Modified: 13 Feb 2026

    A Server-Side Template Injection (SSTI) vulnerability in the /reporting/templates/preview/ endpoint of Amidaware Tactical RMM, affecting versions equal to or earlier than v1.3.1, allows low-privileged users with Report Viewer or Report Manager permissions to achieve remote command execution on the server. This occurs due to improper sanitization of the template_md parameter, enabling direct injection of Jinja2 templates. This occurs due to misuse of the generate_html() function, the user-controlled value is inserted into `env.from_string`, a function that processes Jinja2 templates arbitrarily, making an SSTI possible.

    Published: 29 Jan 2026
    6.2
    Medium

    CVE-2025-71008

    Last Modified: 3 Feb 2026

    A segmentation violation in the oneflow._oneflow_internal.autograd.Function.FunctionCtx.mark_non_differentiable component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.

    Published: 29 Jan 2026
    6.2
    Medium

    CVE-2025-71009

    Last Modified: 3 Feb 2026

    An input validation vulnerability in the flow.scatter/flow.scatter_add component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted indices.

    Published: 29 Jan 2026
    7.5
    High

    CVE-2025-63650

    Last Modified: 19 Feb 2026

    An out-of-bounds read in the mk_ptr_to_buf in mk_core function (mk_memory.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

    Published: 29 Jan 2026
    6.3
    Medium

    CVE-2025-15344

    Last Modified: 9 Mar 2026

    Tanium addressed a SQL injection vulnerability in Asset.

    Published: 28 Jan 2026
    2.1
    Low

    CVE-2026-1551

    Last Modified: 18 Apr 2026

    A weakness has been identified in itsourcecode School Management System 1.0. This affects an unknown part of the file /ramonsys/course/controller.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.

    Published: 28 Jan 2026
    2.1
    Low

    CVE-2026-1550

    Last Modified: 18 Apr 2026

    A security flaw has been discovered in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /hms/hospital/docappsystem/adminviews.py of the component Admin Dashboard Page. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.

    Published: 28 Jan 2026
    2.1
    Low

    CVE-2026-1549

    Last Modified: 18 Apr 2026

    A vulnerability was identified in jishenghua jshERP up to 3.6. Affected by this vulnerability is an unknown functionality of the file /jshERP-boot/plugin/uploadPluginConfigFile of the component PluginController. Such manipulation of the argument configFile leads to path traversal. The attack may be launched remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 28 Jan 2026
    2.1
    Low

    CVE-2026-1548

    Last Modified: 18 Apr 2026

    A flaw has been found in Totolink A7000R 4.1cu.4154. This impacts the function CloudACMunualUpdateUserdata of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument url causes command injection. The attack can be initiated remotely. The exploit has been published and may be used.

    Published: 28 Jan 2026
    10
    Critical

    CVE-2026-24897

    Last Modified: 18 Apr 2026

    Erugo is a self-hosted file-sharing platform. In versions up to and including 0.2.14, an authenticated low-privileged user can upload arbitrary files to any specified location due to insufficient validation of user‑supplied paths when creating shares. By specifying a writable path within the public web root, an attacker can upload and execute arbitrary code on the server, resulting in remote code execution (RCE). This vulnerability allows a low-privileged user to fully compromise the affected Erugo instance. Version 0.2.15 fixes the issue.

    Published: 28 Jan 2026
    2.1
    Low

    CVE-2026-1547

    Last Modified: 18 Apr 2026

    A vulnerability was detected in Totolink A7000R 4.1cu.4154. This affects the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument plugin_name results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.

    Published: 28 Jan 2026
    2.1
    Low

    CVE-2026-1546

    Last Modified: 18 Apr 2026

    A security vulnerability has been detected in jishenghua jshERP up to 3.6. The impacted element is the function getBillItemByParam of the file /jshERP-boot/depotItem/importItemExcel of the component com.jsh.erp.datasource.mappers.DepotItemMapperEx. The manipulation of the argument barCodes leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 28 Jan 2026
    5.3
    Medium

    CVE-2026-24889

    Last Modified: 18 Apr 2026

    soroban-sdk is a Rust SDK for Soroban contracts. Arithmetic overflow can be triggered in the `Bytes::slice`, `Vec::slice`, and `Prng::gen_range` (for `u64`) methods in the `soroban-sdk` in versions up to and including `25.0.1`, `23.5.1`, and `25.0.2`. Contracts that pass user-controlled or computed range bounds to `Bytes::slice`, `Vec::slice`, or `Prng::gen_range` may silently operate on incorrect data ranges or generate random numbers from an unintended range, potentially resulting in corrupted contract state. Note that the best practice when using the `soroban-sdk` and building Soroban contracts is to always enable `overflow-checks = true`. The `stellar contract init` tool that prepares the boiler plate for a Soroban contract, as well as all examples and docs, encourage the use of configuring `overflow-checks = true` on `release` profiles so that these arithmetic operations fail rather than silently wrap. Contracts are only impacted if they use `overflow-checks = false` either explicitly or implicitly. It is anticipated the majority of contracts could not be impacted because the best practice encouraged by tooling is to enable `overflow-checks`. The fix available in `25.0.1`, `23.5.1`, and `25.0.2` replaces bare arithmetic with `checked_add` / `checked_sub`, ensuring overflow traps regardless of the `overflow-checks` profile setting. As a workaround, contract workspaces can be configured with a profile available in the GitHub Securtity Advisory to enable overflow checks on the arithmetic operations. This is the best practice when developing Soroban contracts, and the default if using the contract boilerplate generated using `stellar contract init`. Alternatively, contracts can validate range bounds before passing them to `slice` or `gen_range` to ensure the conversions cannot overflow.

    Published: 28 Jan 2026
    Unknown

    CVE-2026-25074

    Last Modified: 10 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 28 Jan 2026
    6.5
    Medium

    CVE-2026-24888

    Last Modified: 18 Apr 2026

    Maker.js is a 2D vector line drawing and shape modeling for CNC and laser cutters. In versions up to and including 0.19.1, the `makerjs.extendObject` function copies properties from source objects without proper validation, potentially exposing applications to security risks. The function lacks `hasOwnProperty()` checks and does not filter dangerous keys, allowing inherited properties and potentially malicious properties to be copied to target objects. A patch is available in commit 85e0f12bd868974b891601a141974f929dec36b8, which is expected to be part of version 0.19.2.

    Published: 28 Jan 2026
    5.5
    Medium

    CVE-2026-1545

    Last Modified: 18 Apr 2026

    A weakness has been identified in itsourcecode School Management System 1.0. The affected element is an unknown function of the file /course/index.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.

    Published: 28 Jan 2026