CVE Feed

    Dashboard / CVE

    5.1
    Medium

    CVE-2021-47838

    Last Modified: 15 Apr 2026

    Markright 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to embed malicious payloads in markdown files. Attackers can upload specially crafted markdown files that execute arbitrary JavaScript when opened, potentially enabling remote code execution on the victim's system.

    Published: 16 Jan 2026
    5.1
    Medium

    CVE-2021-47839

    Last Modified: 15 Apr 2026

    Marky 0.0.1 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into markdown files. Attackers can upload crafted markdown files with embedded JavaScript payloads that execute when the file is opened, potentially enabling remote code execution.

    Published: 16 Jan 2026
    5.1
    Medium

    CVE-2021-47837

    Last Modified: 15 Apr 2026

    Markdownify 1.2.0 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious payloads within markdown files. Attackers can upload crafted markdown files with embedded scripts that execute when the file is opened, potentially enabling remote code execution.

    Published: 16 Jan 2026
    5.1
    Medium

    CVE-2021-47836

    Last Modified: 25 May 2026

    Markdown Explorer 0.1.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious code through file uploads and editor inputs. Attackers can upload markdown files with embedded JavaScript payloads that execute in the application's privileged renderer context, allowing code execution on the host.

    Published: 16 Jan 2026
    5.1
    Medium

    CVE-2021-47835

    Last Modified: 15 Apr 2026

    Freeter 1.2.1 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious payloads in custom widget titles and files. Attackers can craft malicious files with embedded scripts that execute when victims interact with the application, potentially enabling remote code execution.

    Published: 16 Jan 2026
    5.1
    Medium

    CVE-2021-47834

    Last Modified: 15 Apr 2026

    Schlix CMS 2.2.6-6 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into category titles. Attackers can create a new contact category with a script payload that will execute when the page is viewed by other users.

    Published: 16 Jan 2026
    8.5
    High

    CVE-2021-47833

    Last Modified: 15 Apr 2026

    WifiHotSpot 1.0.0.0 contains an unquoted service path vulnerability in its WifiHotSpotService.exe that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path during system startup or reboot to inject and run malicious executables with LocalSystem permissions.

    Published: 16 Jan 2026
    Unknown

    CVE-2021-47832

    Last Modified: 21 Jan 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as a duplicate.

    Published: 16 Jan 2026
    4.6
    Medium

    CVE-2021-47831

    Last Modified: 15 Apr 2026

    Sandboxie 5.49.7 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the container folder input field. Attackers can paste a large buffer of repeated characters into the Sandbox container folder setting to trigger an application crash.

    Published: 16 Jan 2026
    8.5
    High

    CVE-2021-47829

    Last Modified: 15 Apr 2026

    DHCP Broadband 4.1.0.1503 contains an unquoted service path vulnerability in its service configuration that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path in 'C:\Program Files\DHCP Broadband 4\dhcpt.exe' to inject malicious code that will execute during service startup with LocalSystem permissions.

    Published: 16 Jan 2026
    8.5
    High

    CVE-2021-47828

    Last Modified: 15 Apr 2026

    BOOTP Turbo 2.0.0.1253 contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path to execute arbitrary code with elevated LocalSystem privileges during system startup or reboot.

    Published: 16 Jan 2026
    4.6
    Medium

    CVE-2021-47827

    Last Modified: 15 Apr 2026

    WebSSH for iOS 14.16.10 contains a denial of service vulnerability in the mashREPL tool that allows attackers to crash the application by pasting malformed input. Attackers can trigger the vulnerability by copying a 300-character buffer of repeated 'A' characters into the mashREPL input field, causing the application to crash.

    Published: 16 Jan 2026
    8.5
    High

    CVE-2021-47826

    Last Modified: 15 Apr 2026

    Acer Backup Manager 3.0.0.99 contains an unquoted service path vulnerability in the NTI IScheduleSvc service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\NTI\Acer Backup Manager\ to inject malicious executables that would run with elevated LocalSystem privileges.

    Published: 16 Jan 2026
    8.5
    High

    CVE-2021-47825

    Last Modified: 15 Apr 2026

    Acer Updater Service 1.2.3500.0 contains an unquoted service path vulnerability that allows local users to execute code with elevated system privileges. Attackers can exploit the unquoted path in C:\Program Files\Acer\Acer Updater\ to inject malicious executables that will run with LocalSystem permissions during service startup.

    Published: 16 Jan 2026
    4.6
    Medium

    CVE-2021-47824

    Last Modified: 15 Apr 2026

    iDailyDiary 4.30 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the preferences tab name field. Attackers can paste a 2,000,000 character buffer into the default diary tab name to trigger an application crash.

    Published: 16 Jan 2026
    8.5
    High

    CVE-2021-47823

    Last Modified: 15 Apr 2026

    Acer ePowerSvc 6.0.3008.0 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem permissions during service startup.

    Published: 16 Jan 2026
    8.5
    High

    CVE-2021-47822

    Last Modified: 15 Apr 2026

    DiskBoss Service 12.2.18 contains an unquoted service path vulnerability in its binary path configuration that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path by placing malicious executables in potential path locations to gain system-level access during service startup.

    Published: 16 Jan 2026
    4.6
    Medium

    CVE-2021-47821

    Last Modified: 15 Apr 2026

    RarmaRadio 2.72.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing network configuration fields with large character buffers. Attackers can generate a 100,000 character buffer and paste it into multiple network settings fields to trigger application instability and potential crash.

    Published: 16 Jan 2026
    5.1
    Medium

    CVE-2021-47820

    Last Modified: 15 Apr 2026

    Ubee EVW327 contains a cross-site request forgery vulnerability that allows attackers to enable remote access without user interaction. Attackers can craft a malicious webpage that automatically submits a form to change router remote access settings to port 8080 without the user's consent.

    Published: 16 Jan 2026
    4.6
    Medium

    CVE-2021-47818

    Last Modified: 15 Apr 2026

    DupTerminator 1.4.5639.37199 contains a denial of service vulnerability that allows attackers to crash the application by inputting a long character string in the Excluded text box. Attackers can generate a payload of 8000 repeated characters to trigger the application to stop working on Windows 10.

    Published: 16 Jan 2026
    5.3
    Medium

    CVE-2021-47816

    Last Modified: 28 Jul 2026

    Thecus N4800Eco NAS Server Control Panel contains a command injection vulnerability that allows authenticated attackers to execute arbitrary system commands through user management endpoints. Attackers can inject commands via username and batch user creation parameters to execute shell commands with administrative privileges.

    Published: 16 Jan 2026
    8
    High

    CVE-2026-23535

    Last Modified: 18 Apr 2026

    wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.2, the multi-translation download could write to an arbitrary location when instructed by a crafted server. This vulnerability is fixed in 1.17.2.

    Published: 16 Jan 2026
    7.5
    High

    CVE-2026-23490

    Last Modified: 14 Aug 2026

    pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.

    Published: 16 Jan 2026
    7.8
    High

    CVE-2025-48647

    Last Modified: 26 Feb 2026

    In cpm_fwtp_msg_handler of cpm/google/lib/tracepoint/cpm_fwtp_ipc.c, there is a possible memory overwrite due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 16 Jan 2026
    7.4
    High

    CVE-2025-15032

    Last Modified: 15 Apr 2026

    Missing about:blank indicator in custom-sized new windows in Dia before 1.9.0 on macOS could allow an attacker to spoof a trusted domain in the window title and mislead users about the current site.

    Published: 16 Jan 2026
    8.7
    High

    CVE-2026-0629

    Last Modified: 18 Apr 2026

    Authentication bypass in the password recovery feature of the local web interface across multiple VIGI camera models allows an attacker on the LAN to reset the admin password without verification by manipulating client-side state. Attackers can gain full administrative access to the device, compromising configuration and network security.

    Published: 16 Jan 2026
    3.3
    Low

    CVE-2025-31186

    Last Modified: 27 Apr 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 16.3. An app may be able to bypass Privacy preferences.

    Published: 16 Jan 2026
    3.3
    Low

    CVE-2025-24090

    Last Modified: 27 Apr 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app may be able to enumerate a user's installed apps.

    Published: 16 Jan 2026
    5.5
    Medium

    CVE-2025-43508

    Last Modified: 22 Apr 2026

    A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.

    Published: 16 Jan 2026
    3.3
    Low

    CVE-2024-44210

    Last Modified: 2 Apr 2026

    This issue was addressed with improved permissions checking. This issue is fixed in macOS Sequoia 15.1. An app may be able to access user-sensitive data.

    Published: 16 Jan 2026
    5.3
    Medium

    CVE-2025-24089

    Last Modified: 27 Apr 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app may be able to enumerate a user's installed apps.

    Published: 16 Jan 2026
    2.4
    Low

    CVE-2024-54556

    Last Modified: 2 Apr 2026

    This issue was addressed through improved state management. This issue is fixed in iOS 18.1 and iPadOS 18.1. A user may be able to view restricted content from the lock screen.

    Published: 16 Jan 2026
    7.8
    High

    CVE-2024-44238

    Last Modified: 2 Apr 2026

    The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An app may be able to corrupt coprocessor memory.

    Published: 16 Jan 2026
    7.7
    High

    CVE-2026-23529

    Last Modified: 18 Apr 2026

    Kafka Connect BigQuery Connector is an implementation of a sink connector from Apache Kafka to Google BigQuery. Prior to 2.11.0, there is an arbitrary file read in Google BigQuery Sink connector. Aiven's Google BigQuery Kafka Connect Sink connector requires Google Cloud credential configurations for authentication to BigQuery services. During connector configuration, users can supply credential JSON files that are processed by Google authentication libraries. The service fails to validate externally-sourced credential configurations before passing them to the authentication libraries. An attacker can exploit this by providing a malicious credential configuration containing crafted credential_source.file paths or credential_source.url endpoints, resulting in arbitrary file reads or SSRF attacks.

    Published: 16 Jan 2026
    5.3
    Medium

    CVE-2026-23528

    Last Modified: 18 Apr 2026

    Dask distributed is a distributed task scheduler for Dask. Prior to 2026.1.0, when Jupyter Lab, jupyter-server-proxy, and Dask distributed are all run together, it is possible to craft a URL which will result in code being executed by Jupyter due to a cross-side-scripting (XSS) bug in the Dask dashboard. It is possible for attackers to craft a phishing URL that assumes Jupyter Lab and Dask may be running on localhost and using default ports. If a user clicks on the malicious link it will open an error page in the Dask Dashboard via the Jupyter Lab proxy which will cause code to be executed by the default Jupyter Python kernel. This vulnerability is fixed in 2026.1.0.

    Published: 16 Jan 2026
    9.6
    Critical

    CVE-2026-23523

    Last Modified: 18 Apr 2026

    Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. Prior to 0.13.0, crafted deeplink can install an attacker-controlled MCP server configuration without sufficient user confirmation and can lead to arbitrary local command execution on the victim’s machine. This vulnerability is fixed in 0.13.0.

    Published: 16 Jan 2026
    6.5
    Medium

    CVE-2026-0949

    Last Modified: 18 Apr 2026

    PEM versions prior to 9.8.1 are affected by a stored Cross-site Scripting (XSS) vulnerability that allows users with access to the Manage Charts menu to inject arbitrary JavaScript when creating a new chart, which is then executed by any user accessing the chart. By default only the superuser and users with pem_admin or pem_super_admin privileges are able to access the Manage Charts menu.

    Published: 16 Jan 2026
    2.9
    Low

    CVE-2026-22782

    Last Modified: 18 Apr 2026

    RustFS is a distributed object storage system built in Rust. From >= 1.0.0-alpha.1 to 1.0.0-alpha.79, invalid RPC signatures cause the server to log the shared HMAC secret (and expected signature), which exposes the secret to log readers and enables forged RPC calls. In crates/ecstore/src/rpc/http_auth.rs, the invalid signature branch logs sensitive data. This log line includes secret and expected_signature, both derived from the shared HMAC key. Any invalidly signed request triggers this path. The function is reachable from RPC and admin request handlers. This vulnerability is fixed in 1.0.0-alpha.80.

    Published: 16 Jan 2026
    4.6
    Medium

    CVE-2025-29943

    Last Modified: 15 Apr 2026

    Write what were condition within AMD CPUs may allow an admin-privileged attacker to modify the configuration of the CPU pipeline potentially resulting in the corruption of the stack pointer inside an SEV-SNP guest.

    Published: 16 Jan 2026
    4.8
    Medium

    CVE-2026-21625

    Last Modified: 18 Apr 2026

    User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by file extensions, no mime type checks are happening.

    Published: 16 Jan 2026
    9.4
    Critical

    CVE-2026-21624

    Last Modified: 18 Apr 2026

    Lack of input filterung leads to a persistent XSS vulnerability in the user avatar text handling of the Easy Discuss component for Joomla.

    Published: 16 Jan 2026
    9.4
    Critical

    CVE-2026-21623

    Last Modified: 18 Apr 2026

    Lack of input filterung leads to a persistent XSS vulnerability in the forum post handling of the Easy Discuss component for Joomla.

    Published: 16 Jan 2026
    6.9
    Medium

    CVE-2025-15104

    Last Modified: 23 Jan 2026

    Nu Html Checker (validator.nu) contains a restriction bypass that allows remote attackers to make the server perform arbitrary HTTP/HTTPS requests to internal resources, including localhost services. While the validator implements hostname-based protections to block direct access to localhost and 127.0.0.1, these controls can be bypassed using DNS rebinding techniques or domains that resolve to loopback addresses.This issue affects The Nu Html Checker (vnu): latest (commit 23f090a11bab8d0d4e698f1ffc197a4fe226a9cd).

    Published: 16 Jan 2026
    6.5
    Medium

    CVE-2026-0696

    Last Modified: 18 Apr 2026

    In ConnectWise PSA versions older than 2026.1, certain session cookies were not set with the HttpOnly attribute. In some scenarios, this could allow client-side scripts access to session cookie values.

    Published: 16 Jan 2026
    8.7
    High

    CVE-2026-0695

    Last Modified: 18 Apr 2026

    In ConnectWise PSA versions older than 2026.1, Time Entry notes stored in the Time Entry Audit Trail may be rendered without applying output encoding to certain content. Under specific conditions, this may allow stored script code to execute in the context of a user’s browser when the affected content is displayed.

    Published: 16 Jan 2026
    9.2
    Critical

    CVE-2025-14510

    Last Modified: 15 Apr 2026

    Incorrect Implementation of Authentication Algorithm vulnerability in ABB ABB Ability OPTIMAX.This issue affects ABB Ability OPTIMAX: 6.1, 6.2, from 6.3.0 before 6.3.1-251120, from 6.4.0 before 6.4.1-251120.

    Published: 16 Jan 2026
    7.3
    High

    CVE-2026-0615

    Last Modified: 18 Apr 2026

    The Librarian `supervisord` status page can be retrieved by the `web_fetch` tool, which can be used to retrieve running processes within TheLibrarian backend. The vendor has fixed the vulnerability in all affected versions.

    Published: 16 Jan 2026
    7.5
    High

    CVE-2026-0616

    Last Modified: 18 Apr 2026

    TheLibrarians web_fetch tool can be used to retrieve the Adminer interface content, which can then be used to log into the internal TheLibrarian backend system. The vendor has fixed the vulnerability in all affected versions.

    Published: 16 Jan 2026
    7.5
    High

    CVE-2026-0613

    Last Modified: 18 Apr 2026

    The Librarian contains an internal port scanning vulnerability, facilitated by the `web_fetch` tool, which can be used with SSRF-style behavior to perform GET requests to internal IP addresses and services, enabling scanning of the Hertzner cloud environment that TheLibrarian uses. The vendor has fixed the vulnerability in all affected versions.

    Published: 16 Jan 2026
    7.5
    High

    CVE-2026-0612

    Last Modified: 18 Apr 2026

    The Librarian contains a information leakage vulnerability through the `web_fetch` tool, which can be used to retrieve arbitrary external content provided by an attacker, which can be used to proxy requests through The Librarian infrastructure. The vendor has fixed the vulnerability in all versions of TheLibrarian.

    Published: 16 Jan 2026