CVE Feed

    Dashboard / CVE

    9.1
    Critical

    CVE-2025-68670

    Last Modified: 6 Feb 2026

    xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from improper bounds checking when processing user domain information during the connection sequence. If exploited, the vulnerability could allow remote attackers to execute arbitrary code on the target system. The vulnerability allows an attacker to overwrite the stack buffer and the return address, which could theoretically be used to redirect the execution flow. The impact of this vulnerability is lessened if a compiler flag has been used to build the xrdp executable with stack canary protection. If this is the case, a second vulnerability would need to be used to leak the stack canary value. Upgrade to version 0.10.5 to receive a patch. Additionally, do not rely on stack canary protection on production systems.

    Published: 27 Jan 2026
    9.8
    Critical

    CVE-2026-24872

    Last Modified: 18 Apr 2026

    improper pointer arithmetic vulnerability in ProjectSkyfire SkyFire_548.This issue affects SkyFire_548: before 5.4.8-stable5.

    Published: 27 Jan 2026
    10
    Critical

    CVE-2026-24871

    Last Modified: 18 Apr 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in pilgrimage233 Minecraft-Rcon-Manage.This issue affects Minecraft-Rcon-Manage: before 3.0.

    Published: 27 Jan 2026
    3.7
    Low

    CVE-2026-24870

    Last Modified: 18 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3.

    Published: 27 Jan 2026
    9.8
    Critical

    CVE-2026-24832

    Last Modified: 18 Apr 2026

    Out-of-bounds Write vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3.

    Published: 27 Jan 2026
    7.5
    High

    CVE-2026-24831

    Last Modified: 18 Apr 2026

    Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3.

    Published: 27 Jan 2026
    7.8
    High

    CVE-2026-0648

    Last Modified: 18 Apr 2026

    The vulnerability stems from an incorrect error-checking logic in the CreateCounter() function (in threadx/utility/rtos_compatibility_layers/OSEK/tx_osek.c) when handling the return value of osek_get_counter(). Specifically, the current code checks if cntr_id equals 0u to determine failure, but @osek_get_counter() actually returns E_OS_SYS_STACK (defined as 12U) when it fails. This mismatch causes the error branch to never execute even when the counter pool is exhausted. As a result, when the counter pool is depleted, the code proceeds to cast the error code (12U) to a pointer (OSEK_COUNTER *), creating a wild pointer. Subsequent writes to members of this pointer lead to writes to illegal memory addresses (e.g., 0x0000000C), which can trigger immediate HardFaults or silent memory corruption. This vulnerability poses significant risks, including potential denial-of-service attacks (via repeated calls to exhaust the counter pool) and unauthorized memory access.

    Published: 27 Jan 2026
    4.2
    Medium

    CVE-2025-55095

    Last Modified: 2 Apr 2026

    The function _ux_host_class_storage_media_mount() is responsible for mounting partitions on a USB mass storage device. When it encounters an extended partition entry in the partition table, it recursively calls itself to mount the next logical partition. This recursion occurs in _ux_host_class_storage_partition_read(), which parses up to four partition entries. If an extended partition is found (with type UX_HOST_CLASS_STORAGE_PARTITION_EXTENDED or EXTENDED_LBA_MAPPED), the code invokes: _ux_host_class_storage_media_mount(storage, sector + _ux_utility_long_get(...)); There is no limit on the recursion depth or tracking of visited sectors. As a result, a malicious or malformed disk image can include cyclic or excessively deep chains of extended partitions, causing the function to recurse until stack overflow occurs.

    Published: 27 Jan 2026
    8.7
    High

    CVE-2025-55102

    Last Modified: 2 Apr 2026

    A denial-of-service vulnerability exists in the NetX IPv6 component functionality of Eclipse ThreadX NetX Duo. A specially crafted network packet of "Packet Too Big" with more than 15 different source address can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.

    Published: 27 Jan 2026
    8.8
    High

    CVE-2021-47902

    Last Modified: 15 Apr 2026

    Testa Online Test Management System 3.4.7 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'q' search parameter. Attackers can inject malicious SQL code in the search field to extract database information, potentially accessing sensitive user or system data.

    Published: 27 Jan 2026
    5.1
    Medium

    CVE-2021-47901

    Last Modified: 15 Apr 2026

    Dirsearch 0.4.1 contains a CSV injection vulnerability when using the --csv-report flag that allows attackers to inject formulas through redirected endpoints. Attackers can craft malicious server redirects with comma-separated paths containing Excel formulas to manipulate the generated CSV report.

    Published: 27 Jan 2026
    9.3
    Critical

    CVE-2021-47900

    Last Modified: 15 Apr 2026

    Gila CMS versions prior to 2.0.0 contain a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands through manipulated HTTP headers. Attackers can inject PHP code in the User-Agent header with shell_exec() to run system commands by sending crafted requests to the admin endpoint.

    Published: 27 Jan 2026
    8.8
    High

    CVE-2020-36951

    Last Modified: 15 Apr 2026

    Phpscript-sgh 0.1.0 contains a time-based blind SQL injection vulnerability in the admin interface that allows attackers to manipulate database queries through the 'id' parameter. Attackers can exploit this vulnerability by crafting malicious payloads that trigger time delays, enabling them to extract sensitive database information through conditional sleep techniques.

    Published: 27 Jan 2026
    8.7
    High

    CVE-2020-36950

    Last Modified: 14 Aug 2026

    Laravel Nova 3.7.0 contains a denial of service vulnerability that allows authenticated users to crash the application by manipulating the 'range' parameter. Attackers can send simultaneous requests with an extremely high range value to overwhelm and crash the server.

    Published: 27 Jan 2026
    6.7
    Medium

    CVE-2020-36949

    Last Modified: 20 Feb 2026

    TapinRadio 2.13.7 contains a denial of service vulnerability in the application proxy settings that allows attackers to crash the program by overflowing input fields. Attackers can paste a large buffer of 20,000 characters into the username and address fields to cause the application to become unresponsive and require reinstallation.

    Published: 27 Jan 2026
    8.7
    High

    CVE-2020-36948

    Last Modified: 15 Apr 2026

    VestaCP 0.9.8-26 contains a session token vulnerability in the LoginAs module that allows remote attackers to manipulate authentication tokens. Attackers can exploit insufficient token validation to access user accounts and perform unauthorized login requests without proper administrative permissions.

    Published: 27 Jan 2026
    7.1
    High

    CVE-2020-36947

    Last Modified: 5 Mar 2026

    LibreNMS 1.46 contains an authenticated SQL injection vulnerability in the MAC accounting graph endpoint that allows remote attackers to extract database information. Attackers can exploit the vulnerability by manipulating the 'sort' parameter with crafted SQL injection techniques to retrieve sensitive database contents through time-based blind SQL injection.

    Published: 27 Jan 2026
    8.7
    High

    CVE-2020-36946

    Last Modified: 7 Apr 2026

    SyncBreeze 10.0.28 contains a denial of service vulnerability in the login endpoint that allows remote attackers to crash the service. Attackers can send an oversized payload in the login request to overwhelm the application and potentially disrupt service availability.

    Published: 27 Jan 2026
    8.7
    High

    CVE-2020-36942

    Last Modified: 10 Feb 2026

    Victor CMS 1.0 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the profile image upload feature. Attackers can upload a PHP shell to the /img directory and execute system commands by accessing the uploaded file via web browser.

    Published: 27 Jan 2026
    5.3
    Medium

    CVE-2020-36941

    Last Modified: 24 Mar 2026

    Knockpy 4.1.1 contains a CSV injection vulnerability that allows attackers to inject malicious formulas into CSV reports through unfiltered server headers. Attackers can manipulate server response headers to include spreadsheet formulas that will execute when the CSV is opened in spreadsheet applications.

    Published: 27 Jan 2026
    5.1
    Medium

    CVE-2020-36940

    Last Modified: 15 Apr 2026

    Easy CD & DVD Cover Creator 4.13 contains a buffer overflow vulnerability in the serial number input field that allows attackers to crash the application. Attackers can generate a 6000-byte payload and paste it into the serial number field to trigger an application crash.

    Published: 27 Jan 2026
    8.7
    High

    CVE-2020-36939

    Last Modified: 15 Apr 2026

    Cassandra Web 0.5.0 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating path traversal parameters. Attackers can exploit the disabled Rack::Protection module to read sensitive system files like /etc/passwd and retrieve Apache Cassandra database credentials.

    Published: 27 Jan 2026
    7
    High

    CVE-2020-36938

    Last Modified: 15 Apr 2026

    WinAVR version 20100110 contains an insecure permissions vulnerability that allows authenticated users to modify system files and executables. Attackers can leverage the overly permissive access controls to potentially modify critical DLLs and executable files in the WinAVR installation directory.

    Published: 27 Jan 2026
    Unknown

    CVE-2026-24867

    Last Modified: 28 Jan 2026

    Not used

    Published: 27 Jan 2026
    Unknown

    CVE-2026-24866

    Last Modified: 28 Jan 2026

    Not used

    Published: 27 Jan 2026
    Unknown

    CVE-2026-24865

    Last Modified: 28 Jan 2026

    Not used

    Published: 27 Jan 2026
    Unknown

    CVE-2026-24864

    Last Modified: 28 Jan 2026

    Not used

    Published: 27 Jan 2026
    Unknown

    CVE-2026-24863

    Last Modified: 28 Jan 2026

    Not used

    Published: 27 Jan 2026
    Unknown

    CVE-2026-24862

    Last Modified: 28 Jan 2026

    Not used

    Published: 27 Jan 2026
    Unknown

    CVE-2026-24861

    Last Modified: 28 Jan 2026

    Not used

    Published: 27 Jan 2026
    Unknown

    CVE-2026-24860

    Last Modified: 28 Jan 2026

    Not used

    Published: 27 Jan 2026
    Unknown

    CVE-2026-24859

    Last Modified: 28 Jan 2026

    Not used

    Published: 27 Jan 2026
    9.9
    Critical

    CVE-2026-1470

    Last Modified: 22 Apr 2026

    n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow Expression evaluation system. Expressions supplied by authenticated users during workflow configuration may be evaluated in an execution context that is not sufficiently isolated from the underlying runtime. An authenticated attacker could abuse this behavior to execute arbitrary code with the privileges of the n8n process. Successful exploitation may lead to full compromise of the affected instance, including unauthorized access to sensitive data, modification of workflows, and execution of system-level operations.

    Published: 27 Jan 2026
    5.3
    Medium

    CVE-2026-1213

    Last Modified: 18 Apr 2026

    All versions of askbot before and including 0.12.2 allow an attacker authenticated with normal user permissions to modify the profile picture of other application users.This issue affects askbot: 0.12.2.

    Published: 27 Jan 2026
    8.8
    High

    CVE-2025-15467

    Last Modified: 9 Jun 2026

    Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs. Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue. OpenSSL 1.1.1 and 1.0.2 are not affected by this issue.

    Published: 27 Jan 2026
    2.7
    Low

    CVE-2025-13881

    Last Modified: 15 Apr 2026

    A flaw was found in Keycloak Admin API. This vulnerability allows an administrator with limited privileges to retrieve sensitive custom attributes via the /unmanagedAttributes endpoint, bypassing User Profile visibility settings.

    Published: 27 Jan 2026
    6.9
    Medium

    CVE-2025-12387

    Last Modified: 15 Apr 2026

    A vulnerability in the Pix-Link LV-WR21Q router's language module allows remote attackers to trigger a denial of service (DoS) by sending a specially crafted HTTP POST request containing non-existing language parameter. This renders the server unable to serve correct lang.js file, which causes administrator panel to not work, resulting in DoS until the language settings is reverted to a correct value. The Denial of Service affects only the administrator panel and does not affect other router functionalities. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version V108_108 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.

    Published: 27 Jan 2026
    6.9
    Medium

    CVE-2025-12386

    Last Modified: 15 Apr 2026

    Pix-Link LV-WR21Q does not enforce any form of authentication for endpoint /goform/getHomePageInfo. Remote unauthenticated attacker is able to use this endpoint to e.g: retrieve cleartext password to the access point. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version V108_108 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.

    Published: 27 Jan 2026
    5.3
    Medium

    CVE-2025-41728

    Last Modified: 15 Apr 2026

    A low privileged remote attacker may be able to disclose confidential information from the memory of a privileged process by sending specially crafted calls to the Device Manager web service that cause an out-of-bounds read operation under certain circumstances due to ASLR and thereby potentially copy confidential information into a response.

    Published: 27 Jan 2026
    7.8
    High

    CVE-2025-41727

    Last Modified: 15 Apr 2026

    A local low privileged attacker can bypass the authentication of the Device Manager user interface, allowing them to perform privileged operations and gain administrator access.

    Published: 27 Jan 2026
    8.8
    High

    CVE-2025-41726

    Last Modified: 15 Apr 2026

    A low privileged remote attacker can execute arbitrary code by sending specially crafted calls to the web service of the Device Manager or locally via an API and can cause integer overflows which then may lead to arbitrary code execution within privileged processes.

    Published: 27 Jan 2026
    7.4
    High

    CVE-2026-24348

    Last Modified: 18 Apr 2026

    Multiple cross-site scripting vulnerabilities in Admin UI of EZCast Pro II version 1.17478.146 allow attackers to execute arbitrary JavaScript code in the browser of other Admin UI users.

    Published: 27 Jan 2026
    9.8
    Critical

    CVE-2026-24830

    Last Modified: 18 Apr 2026

    Integer Overflow or Wraparound vulnerability in Ralim IronOS.This issue affects IronOS: before v2.23-rc2.

    Published: 27 Jan 2026
    7
    High

    CVE-2026-21417

    Last Modified: 18 Apr 2026

    Dell CloudBoost Virtual Appliance, versions prior to 19.14.0.0, contains a Plaintext Storage of Password vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

    Published: 27 Jan 2026
    5.7
    Medium

    CVE-2026-24347

    Last Modified: 18 Apr 2026

    Improper input validation in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to manipulate files in the /tmp directory

    Published: 27 Jan 2026
    7.6
    High

    CVE-2026-24346

    Last Modified: 18 Apr 2026

    Use of well-known default credentials in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to access protected areas in the web application

    Published: 27 Jan 2026
    6.5
    Medium

    CVE-2026-24829

    Last Modified: 18 Apr 2026

    Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in Is-Daouda is-Engine.This issue affects is-Engine: before 3.3.4.

    Published: 27 Jan 2026
    7.5
    High

    CVE-2026-24828

    Last Modified: 18 Apr 2026

    Missing Release of Memory after Effective Lifetime vulnerability in Is-Daouda is-Engine.This issue affects is-Engine: before 3.3.4.

    Published: 27 Jan 2026
    6.8
    Medium

    CVE-2026-24345

    Last Modified: 18 Apr 2026

    Cross-Site Request Forgery in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to bypass authorization checks and gain full access to the admin UI

    Published: 27 Jan 2026
    7.5
    High

    CVE-2026-24827

    Last Modified: 18 Apr 2026

    Out-of-bounds Write vulnerability in gerstrong Commander-Genius.This issue affects Commander-Genius: before Release refs/pull/358/merge.

    Published: 27 Jan 2026