CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2025-53516

    Last Modified: 29 Jan 2026

    A reflected cross-site scripting (xss) vulnerability exists in the downloadZip functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious url can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability.

    Published: 20 Jan 2026
    6.1
    Medium

    CVE-2025-54495

    Last Modified: 29 Jan 2026

    A reflected cross-site scripting (xss) vulnerability exists in the emailfailedjob functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious url can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability.

    Published: 20 Jan 2026
    6.1
    Medium

    CVE-2025-54157

    Last Modified: 29 Jan 2026

    A reflected cross-site scripting (xss) vulnerability exists in the encapsulatedDoc functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability.

    Published: 20 Jan 2026
    6.1
    Medium

    CVE-2025-54778

    Last Modified: 29 Jan 2026

    A reflected cross-site scripting (xss) vulnerability exists in the existingUser functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability.

    Published: 20 Jan 2026
    6.1
    Medium

    CVE-2025-46270

    Last Modified: 29 Jan 2026

    A reflected cross-site scripting (xss) vulnerability exists in the fetchPriorStudies functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability.

    Published: 20 Jan 2026
    6.1
    Medium

    CVE-2025-55071

    Last Modified: 29 Jan 2026

    A reflected cross-site scripting (xss) vulnerability exists in the modifyAnonymize functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability.

    Published: 20 Jan 2026
    6.1
    Medium

    CVE-2025-54852

    Last Modified: 29 Jan 2026

    A reflected cross-site scripting (xss) vulnerability exists in the modifyAeTitle functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability.

    Published: 20 Jan 2026
    6.1
    Medium

    CVE-2025-54814

    Last Modified: 29 Jan 2026

    A reflected cross-site scripting (xss) vulnerability exists in the modifyAutopurgeFilter functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability.

    Published: 20 Jan 2026
    6.1
    Medium

    CVE-2025-54861

    Last Modified: 29 Jan 2026

    A reflected cross-site scripting (xss) vulnerability exists in the modifyCoercion functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability.

    Published: 20 Jan 2026
    6.1
    Medium

    CVE-2025-57881

    Last Modified: 29 Jan 2026

    A reflected cross-site scripting (xss) vulnerability exists in the modifyEmail functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability.

    Published: 20 Jan 2026
    6.1
    Medium

    CVE-2025-58080

    Last Modified: 29 Jan 2026

    A reflected cross-site scripting (xss) vulnerability exists in the modifyHL7App functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability.

    Published: 20 Jan 2026
    6.1
    Medium

    CVE-2025-53854

    Last Modified: 29 Jan 2026

    A reflected cross-site scripting (xss) vulnerability exists in the modifyHL7Route functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability.

    Published: 20 Jan 2026
    6.1
    Medium

    CVE-2025-57787

    Last Modified: 29 Jan 2026

    A reflected cross-site scripting (xss) vulnerability exists in the modifyRoute functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability.

    Published: 20 Jan 2026
    6.1
    Medium

    CVE-2025-53707

    Last Modified: 29 Jan 2026

    A reflected cross-site scripting (xss) vulnerability exists in the modifyTranscript functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability.

    Published: 20 Jan 2026
    6.1
    Medium

    CVE-2025-54853

    Last Modified: 29 Jan 2026

    A reflected cross-site scripting (xss) vulnerability exists in the modifyUser functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability.

    Published: 20 Jan 2026
    6.1
    Medium

    CVE-2025-57786

    Last Modified: 29 Jan 2026

    A reflected cross-site scripting (xss) vulnerability exists in the notifynewstudy functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability.

    Published: 20 Jan 2026
    6.1
    Medium

    CVE-2025-44000

    Last Modified: 29 Jan 2026

    A reflected cross-site scripting (xss) vulnerability exists in the sendOruReport functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability.

    Published: 20 Jan 2026
    6.1
    Medium

    CVE-2025-58095

    Last Modified: 29 Jan 2026

    Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Premium 7.3.6.870. Specially crafted malicious URLs can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger these vulnerabilities.This vulnerability affects the imagedir parameter.

    Published: 20 Jan 2026
    6.1
    Medium

    CVE-2025-58094

    Last Modified: 29 Jan 2026

    Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Premium 7.3.6.870. Specially crafted malicious URLs can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger these vulnerabilities.This vulnerability affects the worklistsrc parameter.

    Published: 20 Jan 2026
    6.1
    Medium

    CVE-2025-58093

    Last Modified: 29 Jan 2026

    Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Premium 7.3.6.870. Specially crafted malicious URLs can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger these vulnerabilities.This vulnerability affects the phpdir parameter.

    Published: 20 Jan 2026
    6.1
    Medium

    CVE-2025-58092

    Last Modified: 29 Jan 2026

    Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Premium 7.3.6.870. Specially crafted malicious URLs can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger these vulnerabilities.This vulnerability affects the phpexe parameter.

    Published: 20 Jan 2026
    6.1
    Medium

    CVE-2025-58091

    Last Modified: 29 Jan 2026

    Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Premium 7.3.6.870. Specially crafted malicious URLs can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger these vulnerabilities.This vulnerability affects the thumbnaildir parameter.

    Published: 20 Jan 2026
    6.1
    Medium

    CVE-2025-58090

    Last Modified: 29 Jan 2026

    Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Premium 7.3.6.870. Specially crafted malicious URLs can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger these vulnerabilities.This vulnerability affects the uploaddir parameter.

    Published: 20 Jan 2026
    6.1
    Medium

    CVE-2025-58089

    Last Modified: 29 Jan 2026

    Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Premium 7.3.6.870. Specially crafted malicious URLs can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger these vulnerabilities.This vulnerability affects the longtermdir parameter.

    Published: 20 Jan 2026
    6.1
    Medium

    CVE-2025-58088

    Last Modified: 29 Jan 2026

    Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Premium 7.3.6.870. Specially crafted malicious URLs can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger these vulnerabilities.This vulnerability affects the archivedir parameter.

    Published: 20 Jan 2026
    6.1
    Medium

    CVE-2025-58087

    Last Modified: 29 Jan 2026

    Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Premium 7.3.6.870. Specially crafted malicious URLs can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger these vulnerabilities.This vulnerability affects the status parameter.

    Published: 20 Jan 2026
    6.1
    Medium

    CVE-2025-36556

    Last Modified: 29 Jan 2026

    A reflected cross-site scripting (xss) vulnerability exists in the ldapUser functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability.

    Published: 20 Jan 2026
    9.6
    Critical

    CVE-2025-53912

    Last Modified: 29 Jan 2026

    An arbitrary file read vulnerability exists in the encapsulatedDoc functionality of MedDream PACS Premium 7.3.6.870. A specially crafted HTTP request can lead to an arbitrary file read. An attacker can send http request to trigger this vulnerability.

    Published: 20 Jan 2026
    4.3
    Medium

    CVE-2026-0554

    Last Modified: 16 Apr 2026

    The NotificationX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'regenerate' and 'reset' REST API endpoints in all versions up to, and including, 3.1.11. This makes it possible for authenticated attackers, with Contributor-level access and above, to reset analytics for any NotificationX campaign, regardless of ownership.

    Published: 20 Jan 2026
    7.2
    High

    CVE-2025-15380

    Last Modified: 21 Apr 2026

    The NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via the 'nx-preview' POST parameter in all versions up to, and including, 3.2.0. This is due to insufficient input sanitization and output escaping when processing preview data. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute when a user visits a malicious page that auto-submits a form to the vulnerable site.

    Published: 20 Jan 2026
    6.4
    Medium

    CVE-2026-0608

    Last Modified: 16 Apr 2026

    The Head Meta Data plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'head-meta-data' post meta field in all versions up to, and including, 20251118 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 20 Jan 2026
    8.8
    High

    CVE-2025-15347

    Last Modified: 20 Apr 2026

    The Creator LMS – The LMS for Creators, Coaches, and Trainers plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check in the get_items_permissions_check function in all versions up to, and including, 1.1.12. This makes it possible for authenticated attackers, with contributor level access and above, to update arbitrary WordPress options.

    Published: 20 Jan 2026
    5.4
    Medium

    CVE-2025-15043

    Last Modified: 21 Apr 2026

    The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'start_migration', 'cancel_migration', and 'revert_migration' functions in all versions up to, and including, 6.15.13. This makes it possible for authenticated attackers, with subscriber level access and above, to start, cancel, or revert the Custom Tables V1 database migration, including dropping the custom database tables entirely via the revert action.

    Published: 20 Jan 2026
    6.4
    Medium

    CVE-2026-0690

    Last Modified: 18 Apr 2026

    The FlatPM – Ad Manager, AdSense and Custom Code plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rank_math_description' custom field in all versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 20 Jan 2026
    5.4
    Medium

    CVE-2026-0548

    Last Modified: 15 Apr 2026

    The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized attachment deletion due to a missing capability check on the `delete_existing_user_photo` function in all versions up to, and including, 3.9.4. This makes it possible for authenticated attackers, with subscriber level access and above, to delete arbitrary attachments on the site.

    Published: 20 Jan 2026
    8.1
    High

    CVE-2026-0726

    Last Modified: 15 Apr 2026

    The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.4.6 via deserialization of untrusted input in the 'nxt_unserialize_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.

    Published: 20 Jan 2026
    8.7
    High

    CVE-2025-9283

    Last Modified: 2 Feb 2026

    A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limits Storms tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.

    Published: 20 Jan 2026
    8.7
    High

    CVE-2025-9282

    Last Modified: 2 Feb 2026

    A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive limited storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.

    Published: 20 Jan 2026
    8.7
    High

    CVE-2025-9281

    Last Modified: 2 Feb 2026

    A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive step limit storm tests, the device reboots

    Published: 20 Jan 2026
    9.9
    Critical

    CVE-2026-22844

    Last Modified: 18 Apr 2026

    A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to conduct remote code execution of the MMR via network access.

    Published: 20 Jan 2026
    8.7
    High

    CVE-2025-9280

    Last Modified: 2 Feb 2026

    A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. Fuzzing performed using Defensics causes the device to become unresponsive, requiring a reboot.

    Published: 20 Jan 2026
    8.7
    High

    CVE-2025-14027

    Last Modified: 15 Apr 2026

    Multiple denial-of-service vulnerabilities exist in the affected product. These issues can be triggered through various crafted inputs, including malformed Class 3 messages, memory leak conditions, and other resource exhaustion scenarios. Exploitation may cause the device to become unresponsive and, in some cases, result in a major nonrecoverable fault. Recovery may require a restart.

    Published: 20 Jan 2026
    8.7
    High

    CVE-2025-9279

    Last Modified: 2 Feb 2026

    A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limit Storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.

    Published: 20 Jan 2026
    8.7
    High

    CVE-2025-9278

    Last Modified: 2 Feb 2026

    A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. After running a Burp Suite active scan, the device loses ICMP connectivity, causing the web application to become inaccessible.

    Published: 20 Jan 2026
    8.7
    High

    CVE-2025-9466

    Last Modified: 2 Feb 2026

    A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP and CIP grammar tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.

    Published: 20 Jan 2026
    7.1
    High

    CVE-2025-11743

    Last Modified: 15 Apr 2026

    A denial-of-service security issue in the affected product. The security issue occurs when a malformed CIP forward open message is sent. This could result in a major nonrecoverable fault a restart is required to recover.

    Published: 20 Jan 2026
    8.7
    High

    CVE-2025-9465

    Last Modified: 2 Feb 2026

    A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive grammar tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.

    Published: 20 Jan 2026
    8.7
    High

    CVE-2025-9464

    Last Modified: 2 Feb 2026

    A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. This vulnerability is triggered during fuzzing of multiple CIP classes, which causes the CIP port to become unresponsive.

    Published: 20 Jan 2026
    7.5
    High

    CVE-2025-15281

    Last Modified: 5 Feb 2026

    Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

    Published: 20 Jan 2026
    8.8
    High

    CVE-2025-14377

    Last Modified: 15 Apr 2026

    A security issue was discovered within the legacy Ansible playbook component of Verve Asset Manager, caused by plaintext secrets incorrectly stored when a playbook is running. This component has been retired and has been optional since the 1.36 release in 2024.

    Published: 20 Jan 2026