CVE Feed

    Dashboard / CVE

    5.1
    Medium

    CVE-2025-9522

    Last Modified: 11 Mar 2026

    Blind Server-Side Request Forgery (SSRF) in Omada Controllers through webhook functionality, enabling crafted requests to internal services, which may lead to enumeration of information.

    Published: 26 Jan 2026
    2.1
    Low

    CVE-2025-9521

    Last Modified: 11 Mar 2026

    Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypass secondary verification, and change the user’s password without proper confirmation, leading to weakened account security.

    Published: 26 Jan 2026
    8.3
    High

    CVE-2025-9520

    Last Modified: 11 Mar 2026

    An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate requests and potentially hijack the Owner account.

    Published: 26 Jan 2026
    7.5
    High

    CVE-2026-23864

    Last Modified: 18 Apr 2026

    Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack. The vulnerabilities are triggered by sending specially crafted HTTP requests to Server Function endpoints, and could lead to server crashes, out-of-memory exceptions or excessive CPU usage; depending on the vulnerable code path being exercised, the application configuration and application code. Strongly consider upgrading to the latest package versions to reduce risk and prevent availability issues in applications using React Server Components.

    Published: 26 Jan 2026
    8.5
    High

    CVE-2025-14756

    Last Modified: 9 Mar 2026

    Command injection vulnerability was found in the admin interface component of TP-Link Archer MR600 v5 firmware, allowing authenticated attackers to execute system commands with a limited character length via crafted input in the browser developer console, possibly leading to service disruption or full compromise.

    Published: 26 Jan 2026
    Unknown

    CVE-2026-1452

    Last Modified: 17 Feb 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 26 Jan 2026
    7.1
    High

    CVE-2025-71178

    Last Modified: 15 Apr 2026

    Crucial Storage Executive installer versions prior to 11.08.082025.00 contain a DLL preloading vulnerability. During installation, the installer runs with elevated privileges and loads Windows DLLs using an uncontrolled search path, which can cause a malicious DLL placed alongside the installer to be loaded instead of the intended system library. A local attacker who can convince a victim to run the installer from a directory containing the attacker-supplied DLL can achieve arbitrary code execution with administrator privileges.

    Published: 26 Jan 2026
    2.7
    Low

    CVE-2026-0925

    Last Modified: 18 Apr 2026

    Tanium addressed an improper input validation vulnerability in Discover.

    Published: 26 Jan 2026
    7.1
    High

    CVE-2026-24435

    Last Modified: 16 Apr 2026

    Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) implement an insecure Cross-Origin Resource Sharing (CORS) policy on authenticated administrative endpoints. The device sets Access-Control-Allow-Origin: * in combination with Access-Control-Allow-Credentials: true, allowing attacker-controlled origins to issue credentialed cross-origin requests.

    Published: 26 Jan 2026
    2.1
    Low

    CVE-2026-24439

    Last Modified: 16 Apr 2026

    Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) fail to include the X-Content-Type-Options: nosniff response header on web management interfaces. As a result, browsers that perform MIME sniffing may incorrectly interpret attacker-influenced responses as executable script.

    Published: 26 Jan 2026
    3.3
    Low

    CVE-2025-57784

    Last Modified: 18 Feb 2026

    Tomahawk auth timing attack due to usage of `strcmp` has been identified in Hiawatha webserver version 11.7 which allows a local attacker to access the management client.

    Published: 26 Jan 2026
    5.1
    Medium

    CVE-2026-24432

    Last Modified: 16 Apr 2026

    Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) lack cross-site request forgery (CSRF) protections on administrative endpoints, including those used to change administrator account credentials. As a result, an attacker can craft malicious requests that, when triggered by an authenticated user’s browser, modify administrative passwords and other configuration settings.

    Published: 26 Jan 2026
    6.5
    Medium

    CVE-2025-57785

    Last Modified: 13 Feb 2026

    A Double Free in XSLT `show_index` has been identified in Hiawatha webserver version 11.7 which allows an unauthenticated attacker to corrupt data which may lead to arbitrary code execution.

    Published: 26 Jan 2026
    5.3
    Medium

    CVE-2025-57783

    Last Modified: 18 Feb 2026

    Improper header parsing may lead to request smuggling has been identified in Hiawatha webserver version 11.7 which allows an unauthenticated attacker to access restricted resources managed by Hiawatha webserver.

    Published: 26 Jan 2026
    5.1
    Medium

    CVE-2020-36960

    Last Modified: 15 Apr 2026

    Forma LMS 2.3 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts into user profile first and last name fields. Attackers can craft scripts like '<script>alert(document.cookie)</script>' to execute arbitrary JavaScript when the profile is viewed by other users.

    Published: 26 Jan 2026
    8.5
    High

    CVE-2020-36959

    Last Modified: 15 Apr 2026

    IDT PC Audio 1.0.6499.0 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the STacSV service to inject malicious code that would execute with LocalSystem account permissions during service startup.

    Published: 26 Jan 2026
    8.5
    High

    CVE-2020-36958

    Last Modified: 15 Apr 2026

    Kite 1.2020.1119.0 contains an unquoted service path vulnerability in the KiteService Windows service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Kite\KiteService.exe' to inject malicious executables and escalate privileges on the system.

    Published: 26 Jan 2026
    8.5
    High

    CVE-2020-36957

    Last Modified: 15 Jul 2026

    PDF Complete 3.5.310.2002 contains an unquoted service path vulnerability in its pdfsvc.exe service configuration. Attackers can exploit the unquoted path to inject and execute malicious code with elevated LocalSystem privileges.

    Published: 26 Jan 2026
    5.1
    Medium

    CVE-2020-36956

    Last Modified: 15 Apr 2026

    Openfire 4.6.0 contains a stored cross-site scripting vulnerability in the nodejs plugin that allows attackers to inject malicious scripts through the 'path' parameter. Attackers can craft a payload with script tags to execute arbitrary JavaScript in the context of administrative users viewing the nodejs configuration page.

    Published: 26 Jan 2026
    5.1
    Medium

    CVE-2020-36955

    Last Modified: 15 Apr 2026

    Grav CMS 1.6.30 with Admin Plugin 1.9.18 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the page title field. Attackers can create a new page with a malicious script in the title, which will be executed when the page is viewed in the admin panel or on the site.

    Published: 26 Jan 2026
    5.1
    Medium

    CVE-2020-36954

    Last Modified: 15 Apr 2026

    Xeroneit Library Management System 3.1 contains a stored cross-site scripting vulnerability in the Book Category feature that allows administrators to inject malicious scripts. Attackers can insert a payload in the Category Name field to execute arbitrary JavaScript code when the page is loaded.

    Published: 26 Jan 2026
    8.5
    High

    CVE-2020-36953

    Last Modified: 15 Apr 2026

    MiniTool ShadowMaker 3.2 contains an unquoted service path vulnerability in the MTAgentService that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\MiniTool ShadowMaker\AgentService.exe' to inject malicious executables and escalate privileges.

    Published: 26 Jan 2026
    5.1
    Medium

    CVE-2026-24433

    Last Modified: 16 Apr 2026

    Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain a stored cross-site scripting vulnerability in the user creation functionality. Insufficient input validation allows attacker-controlled script content to be stored and later executed when administrative users access the affected management pages.

    Published: 26 Jan 2026
    7.1
    High

    CVE-2026-24431

    Last Modified: 16 Apr 2026

    Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) display stored user account passwords in plaintext within the administrative web interface. Any user with access to the affected management pages can directly view credentials.

    Published: 26 Jan 2026
    4.8
    Medium

    CVE-2026-24437

    Last Modified: 16 Apr 2026

    Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) serve sensitive administrative content without appropriate cache-control directives. As a result, browsers may store credential-bearing responses locally, exposing them to subsequent unauthorized access.

    Published: 26 Jan 2026
    9.2
    Critical

    CVE-2026-24436

    Last Modified: 18 Apr 2026

    Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) do not enforce rate limiting or account lockout mechanisms on authentication endpoints. This allows attackers to perform unrestricted brute-force attempts against administrative credentials.

    Published: 26 Jan 2026
    8.7
    High

    CVE-2026-24428

    Last Modified: 16 Apr 2026

    Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain an authorization flaw in the user management API that allows a low-privileged authenticated user to change the administrator account password. By sending a crafted request directly to the backend endpoint, an attacker can bypass role-based restrictions enforced by the web interface and obtain full administrative privileges.

    Published: 26 Jan 2026
    8.2
    High

    CVE-2026-24430

    Last Modified: 16 Apr 2026

    Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) disclose sensitive account credentials in cleartext within HTTP responses generated by the maintenance interface. Because the management interface is accessible over unencrypted HTTP by default, credentials may be exposed to network-based interception.

    Published: 26 Jan 2026
    9.3
    Critical

    CVE-2026-24429

    Last Modified: 16 Apr 2026

    Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) ship with a predefined default password for a built-in authentication account that is not required to be changed during initial configuration. An attacker can leverage these default credentials to gain authenticated access to the management interface.

    Published: 26 Jan 2026
    8.7
    High

    CVE-2026-24440

    Last Modified: 16 Apr 2026

    Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) allow account passwords to be changed through the maintenance interface without requiring verification of the existing password. This enables unauthorized password changes when access to the affected endpoint is obtained.

    Published: 26 Jan 2026
    4.9
    Medium

    CVE-2026-1224

    Last Modified: 18 Apr 2026

    Tanium addressed an uncontrolled resource consumption vulnerability in Discover.

    Published: 26 Jan 2026
    5
    Medium

    CVE-2026-1446

    Last Modified: 18 Apr 2026

    There is a Cross‑Site Scripting (XSS) issue in Esri ArcGIS Pro versions 3.6.0 and earlier. ArcGIS Pro is a desktop application, and exploitation is limited to local users interacting with the application; no privileged role or elevated permissions are required beyond standard local user access. A local attacker can supply malicious strings that may be rendered and executed when a specific dialog within ArcGIS Pro is opened. This issue is fixed in ArcGIS Pro version 3.6.1.

    Published: 26 Jan 2026
    7.8
    High

    CVE-2026-21509

    Last Modified: 22 Apr 2026

    Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

    Published: 26 Jan 2026
    8.5
    High

    CVE-2020-36952

    Last Modified: 15 Apr 2026

    IObit Uninstaller 10 Pro contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted service path in the IObit Uninstaller Service to insert malicious code that would execute with SYSTEM-level permissions during service startup.

    Published: 26 Jan 2026
    7.8
    High

    CVE-2026-1284

    Last Modified: 18 Apr 2026

    An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file.

    Published: 26 Jan 2026
    7.8
    High

    CVE-2026-1283

    Last Modified: 18 Apr 2026

    A Heap-based Buffer Overflow vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file.

    Published: 26 Jan 2026
    9.9
    Critical

    CVE-2016-15057

    Last Modified: 27 Jan 2026

    ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Continuum. This issue affects Apache Continuum: all versions. Attackers with access to the installations REST API can use this to invoke arbitrary commands on the server. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 26 Jan 2026
    5.1
    Medium

    CVE-2025-59109

    Last Modified: 15 Apr 2026

    The dormakaba registration units 9002 (PIN Pad Units) have an exposed UART header on the backside. The PIN pad is sending every button press to the UART interface. An attacker can use the interface to exfiltrate PINs. As the devices are explicitly built as Plug-and-Play to be easily replaced, an attacker is easily able to remove the device, install a hardware implant which connects to the UART and exfiltrates the data exposed via UART to another system (e.g. via WiFi).

    Published: 26 Jan 2026
    9.2
    Critical

    CVE-2025-59108

    Last Modified: 15 Apr 2026

    By default, the password for the Access Manager's web interface, is set to 'admin'. In the tested version changing the password was not enforced.

    Published: 26 Jan 2026
    8.5
    High

    CVE-2025-59107

    Last Modified: 15 Apr 2026

    Dormakaba provides the software FWServiceTool to update the firmware version of the Access Managers via the network. The firmware in some instances is provided in an encrypted ZIP file. Within this tool, the password used to decrypt the ZIP and extract the firmware is set statically and can be extracted. This password was valid for multiple observed firmware versions.

    Published: 26 Jan 2026
    8.8
    High

    CVE-2025-59106

    Last Modified: 12 Feb 2026

    The binary serving the web server and executing basically all actions launched from the Web UI is running with root privileges. This is against the least privilege principle. If an attacker is able to execute code on the system via other vulnerabilities it is possible to directly execute commands with highest privileges.

    Published: 26 Jan 2026
    7
    High

    CVE-2025-59105

    Last Modified: 15 Apr 2026

    With physical access to the device and enough time an attacker can desolder the flash memory, modify it and then reinstall it because of missing encryption. Thus, essential files, such as "/etc/passwd", as well as stored certificates, cryptographic keys, stored PINs and so on can be modified and read, in order to gain SSH root access on the Linux-based K7 model. On the Windows CE based K5 model, the password for the Access Manager can additionally be read in plain text from the stored SQLite database.

    Published: 26 Jan 2026
    7
    High

    CVE-2025-59104

    Last Modified: 15 Apr 2026

    With physical access to the device and enough time an attacker is able to solder test leads to the debug footprint (or use the 6-Pin tag-connect cable). Thus, the attacker gains access to the bootloader, where the kernel command line can be changed. An attacker is able to gain a root shell through this vulnerability.

    Published: 26 Jan 2026
    9.2
    Critical

    CVE-2025-59103

    Last Modified: 15 Apr 2026

    The Access Manager 92xx in hardware revision K7 is based on Linux instead of Windows CE embedded in older hardware revisions. In this new hardware revision it was noticed that an SSH service is exposed on port 22. By analyzing the firmware of the devices, it was noticed that there are two users with hardcoded and weak passwords that can be used to access the devices via SSH. The passwords can be also guessed very easily. The password of at least one user is set to a random value after the first deployment, with the restriction that the password is only randomized if the configured date is prior to 2022. Therefore, under certain circumstances, the passwords are not randomized. For example, if the clock is never set on the device, the battery of the clock module has been changed, the Access Manager has been factory reset and has not received a time yet.

    Published: 26 Jan 2026
    6.9
    Medium

    CVE-2025-59102

    Last Modified: 15 Apr 2026

    The web server of the Access Manager offers a functionality to download a backup of the local database stored on the device. This database contains the whole configuration. This includes encrypted MIFARE keys, card data, user PINs and much more. The PINs are even stored unencrypted. Combined with the fact that an attacker can easily get access to the backup functionality by abusing the session management issue (CVE-2025-59101), or by exploiting the weak default password (CVE-2025-59108), or by simply setting a new password without prior authentication via the SOAP API (CVE-2025-59097), it is easily possible to access the sensitive data on the device.

    Published: 26 Jan 2026
    7.7
    High

    CVE-2025-59101

    Last Modified: 15 Apr 2026

    Instead of typical session tokens or cookies, it is verified on a per-request basis if the originating IP address has once successfully logged in. As soon as an authentication request from a certain source IP is successful, the IP address is handled as authenticated. No other session information is stored. Therefore, it is possible to spoof the IP address of a logged-in user to gain access to the Access Manager web interface.

    Published: 26 Jan 2026
    5.9
    Medium

    CVE-2025-59100

    Last Modified: 15 Apr 2026

    The web interface offers a functionality to export the internal SQLite database. After executing the database export, an automatic download is started and the device reboots. After rebooting, the exported database is deleted and cannot be accessed anymore. However, it was noticed that sometimes the device does not reboot and therefore the exported database is not deleted, or the device reboots and the export is not deleted for unknown reasons. The path where the database export is located can be accessed without prior authentication. This leads to the fact that an attacker might be able to get access to the exported database without prior authentication. The database includes sensitive data like passwords, card pins, encrypted Mifare sitekeys and much more.

    Published: 26 Jan 2026
    8.8
    High

    CVE-2025-59099

    Last Modified: 15 Apr 2026

    The Access Manager is using the open source web server CompactWebServer written in C#. This web server is affected by a path traversal vulnerability, which allows an attacker to directly access files via simple GET requests without prior authentication. Hence, it is possible to retrieve all files stored on the file system, including the SQLite database Database.sq3, containing badge information and the corresponding PIN codes. Additionally, when trying to access certain files, the web server crashes and becomes unreachable for about 60 seconds. This can be abused to continuously send the request and cause denial of service.

    Published: 26 Jan 2026
    8.7
    High

    CVE-2025-59098

    Last Modified: 15 Apr 2026

    The Access Manager is offering a trace functionality to debug errors and issues with the device. The trace functionality is implemented as a simple TCP socket. A tool called TraceClient.exe, provided by dormakaba via the Access Manager web interface, is used to connect to the socket and receive debug information. The data is permanently broadcasted on the TCP socket. The socket can be accessed without any authentication or encryption. The transmitted data is based on the set verbosity level. The verbosity level can be set using the http(s) endpoint with the service interface password or with the guessable identifier of the device via the SOAP interface. The transmitted data contains sensitive data like the Card ID as well as all button presses on Registration units. This allows an attacker with network level access to retrieve all entered PINs on a registration unit.

    Published: 26 Jan 2026
    9.3
    Critical

    CVE-2025-59097

    Last Modified: 15 Apr 2026

    The exos 9300 application can be used to configure Access Managers (e.g. 92xx, 9230 and 9290). The configuration is done in a graphical user interface on the dormakaba exos server. As soon as the save button is clicked in exos 9300, the whole configuration is sent to the selected Access Manager via SOAP. The SOAP request is sent without any prior authentication or authorization by default. Though authentication and authorization can be configured using IPsec for 92xx-K5 devices and mTLS for 92xx-K7 devices, it is not enabled by default and must therefore be activated with additional steps. This insecure default allows an attacker with network level access to completely control the whole environment. An attacker is for example easily able to conduct the following tasks without prior authentication: - Re-configure Access Managers (e.g. remove alarming system requirements) - Freely re-configure the inputs and outputs - Open all connected doors permanently - Open all doors for a defined time interval - Change the admin password - and many more Network level access can be gained due to an insufficient network segmentation as well as missing LAN firewalls. Devices with an insecure configuration have been identified to be directly exposed to the internet.

    Published: 26 Jan 2026