CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2025-14894

    Last Modified: 23 Jan 2026

    Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE through upload of a malicious php file that can then be executed via the /storage/ URL if a commonly performed setup process within Laravel applications has been completed.

    Published: 16 Jan 2026
    6.8
    Medium

    CVE-2025-14435

    Last Modified: 20 Jan 2026

    Mattermost versions 10.11.x <= 10.11.8, 11.1.x <= 11.1.1, 11.0.x <= 11.0.6 fail to prevent infinite re-renders on API errors which allows authenticated users to cause application-level DoS via triggering unbounded component re-render loops.

    Published: 16 Jan 2026
    7.5
    High

    CVE-2025-68675

    Last Modified: 24 Feb 2026

    In Apache Airflow versions before 3.1.6, and 2.11.1 the proxies and proxy fields within a Connection may include proxy URLs containing embedded authentication information. These fields were not treated as sensitive by default and therefore were not automatically masked in log output. As a result, when such connections are rendered or printed to logs, proxy credentials embedded in these fields could be exposed. Users are recommended to upgrade to 3.1.6 or later for Airflow 3, and 2.11.1 or later for Airflow 2 which fixes this issue

    Published: 16 Jan 2026
    7.4
    High

    CVE-2025-59870

    Last Modified: 23 Jan 2026

    HCL MyXalytics  is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk

    Published: 16 Jan 2026
    7.5
    High

    CVE-2025-68438

    Last Modified: 21 Jan 2026

    In Apache Airflow versions before 3.1.6, when rendered template fields in a Dag exceed [core] max_templated_field_length, sensitive values could be exposed in cleartext in the Rendered Templates UI. This occurred because serialization of those fields used a secrets masker instance that did not include user-registered mask_secret() patterns, so secrets were not reliably masked before truncation and display. Users are recommended to upgrade to 3.1.6 or later, which fixes this issue

    Published: 16 Jan 2026
    8.2
    High

    CVE-2025-14844

    Last Modified: 22 Apr 2026

    The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Missing Authentication in all versions up to, and including, 3.2.16 via the 'rcp_stripe_create_setup_intent_for_saved_card' function due to missing capability check. Additionally, the plugin does not check a user-controlled key, which makes it possible for unauthenticated attackers to leak Stripe SetupIntent client_secret values for any membership.

    Published: 16 Jan 2026
    3.1
    Low

    CVE-2025-14822

    Last Modified: 20 Jan 2026

    Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which allows an authenticated attacker to exhaust CPU resources via a single HTTP request containing a post with thousands space-separated tokens

    Published: 16 Jan 2026
    8.4
    High

    CVE-2025-12007

    Last Modified: 15 Apr 2026

    There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can update the system firmware with a specially crafted image.

    Published: 16 Jan 2026
    9.8
    Critical

    CVE-2025-60021

    Last Modified: 26 Feb 2026

    Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to inject remote command. Root Cause: The bRPC heap profiler built-in service (/pprof/heap) does not validate the user-provided extra_options parameter and executes it as a command-line argument. Attackers can execute remote commands using the extra_options parameter.. Affected scenarios: Use the built-in bRPC heap profiler service to perform jemalloc memory profiling. How to Fix: we provide two methods, you can choose one of them: 1. Upgrade bRPC to version 1.15.0. 2. Apply this patch ( https://github.com/apache/brpc/pull/3101 ) manually.

    Published: 16 Jan 2026
    5.3
    Medium

    CVE-2025-14757

    Last Modified: 21 Apr 2026

    The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Payment Status Bypass in all versions up to, and including, 3.6.9 only when used in combination with Cost Calculator Builder PRO. This is due to the complete_payment AJAX action being registered via wp_ajax_nopriv, making it accessible to unauthenticated users, and the complete() function only verifying a nonce without checking user capabilities or order ownership. Since nonces are exposed to all visitors via window.ccb_nonces in the page source, any unauthenticated attacker can mark any order's payment status as "completed" without actual payment.

    Published: 16 Jan 2026
    7.2
    High

    CVE-2025-12006

    Last Modified: 15 Apr 2026

    There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW-F . An attacker can update the system firmware with a specially crafted image.

    Published: 16 Jan 2026
    6.4
    Medium

    CVE-2026-0913

    Last Modified: 15 Apr 2026

    The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'usp_access' shortcode in all versions up to, and including, 20260110 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 16 Jan 2026
    5.3
    Medium

    CVE-2026-1004

    Last Modified: 16 Apr 2026

    The Essential Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including 6.5.5 via the 'eael_product_quickview_popup' function. This makes it possible for unauthenticated attackers to retrieve WooCommerce product information for products with draft, pending, or private status, which should normally be restricted.

    Published: 16 Jan 2026
    7.1
    High

    CVE-2026-22876

    Last Modified: 18 Apr 2026

    Path Traversal vulnerability exists in multiple Network Cameras TRIFORA 3 series provided by TOA Corporation. If this vulnerability is exploited, arbitrary files on the affected product may be retrieved by a logged-in user with the low("monitoring user") or higher privilege.

    Published: 16 Jan 2026
    4.8
    Medium

    CVE-2026-20894

    Last Modified: 18 Apr 2026

    Cross-site scripting vulnerability exists in multiple Network Cameras TRIFORA 3 series provided by TOA Corporation. If an attacking administrator configures the affected product with some malicious input, an arbitrary script may be executed on the web browser of a victim administrator who accesses the setting screen.

    Published: 16 Jan 2026
    8.7
    High

    CVE-2026-20759

    Last Modified: 18 Jun 2026

    OS Command Injection vulnerability exists in multiple Network Cameras TRIFORA 3 series provided by TOA Corporation, which may allow a logged-in user with the low("monitoring user") or higher privilege to execute an arbitrary OS command.

    Published: 16 Jan 2026
    6.1
    Medium

    CVE-2025-14375

    Last Modified: 22 Apr 2026

    The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 5.0.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 16 Jan 2026
    4.3
    Medium

    CVE-2026-1003

    Last Modified: 15 Apr 2026

    The GetGenie plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.3.0. This is due to the plugin not properly verifying that a user is authorized to delete a specific post. This makes it possible for authenticated attackers, with Author-level access and above, to delete any post on the WordPress site, including posts authored by other users.

    Published: 16 Jan 2026
    5
    Medium

    CVE-2025-14793

    Last Modified: 20 Apr 2026

    The DK PDF – WordPress PDF Generator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.3.0 via the 'addContentToMpdf' function. This makes it possible for authenticated attackers, author level and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

    Published: 16 Jan 2026
    4.3
    Medium

    CVE-2025-14853

    Last Modified: 21 Apr 2026

    The LEAV Last Email Address Validator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions <= 1.7.1. This is due to missing or incorrect nonce validation on the display_settings_page function. This makes it possible for unauthenticated attackers to modify plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 16 Jan 2026
    5.3
    Medium

    CVE-2026-0939

    Last Modified: 15 Apr 2026

    The Rede Itaú for WooCommerce plugin for WordPress is vulnerable to order status manipulation due to insufficient verification of data authenticity in all versions up to, and including, 5.1.2. This is due to the plugin failing to verify the authenticity of payment callbacks. This makes it possible for unauthenticated attackers to manipulate WooCommerce order statuses, either marking unpaid orders as paid, or failed.

    Published: 16 Jan 2026
    5.3
    Medium

    CVE-2026-0942

    Last Modified: 15 Apr 2026

    The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clearOrderLogs() function in all versions up to, and including, 5.1.5. This makes it possible for unauthenticated attackers to delete the Rede Order Logs metadata from all WooCommerce orders.

    Published: 16 Jan 2026
    6.4
    Medium

    CVE-2026-0916

    Last Modified: 15 Apr 2026

    The Related Posts by Taxonomy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'related_posts_by_tax' shortcode in all versions up to, and including, 2.7.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 16 Jan 2026
    7.8
    High

    CVE-2026-0975

    Last Modified: 18 Apr 2026

    Delta Electronics DIAView has Command Injection vulnerability.

    Published: 16 Jan 2026
    6.1
    Medium

    CVE-2026-23769

    Last Modified: 18 Apr 2026

    lucy-xss-filter before commit e5826c0 allows an attacker to execute malicious JavaScript due to improper sanitization caused by misconfigured default superset rule files.

    Published: 16 Jan 2026
    6.1
    Medium

    CVE-2026-23768

    Last Modified: 18 Apr 2026

    lucy-xss-filter before commit 7c1de6d allows an attacker to induce server-side HEAD requests to arbitrary URLs when the ObjectSecurityListener or EmbedSecurityListener option is enabled and embed or object tags are used with a src attribute missing a file extension.

    Published: 16 Jan 2026
    2
    Low

    CVE-2026-0858

    Last Modified: 18 Apr 2026

    Versions of the package net.sourceforge.plantuml:plantuml before 1.2026.0 are vulnerable to Stored XSS due to insufficient sanitization of interactive attributes in GraphViz diagrams. As a result, a crafted PlantUML diagram can inject malicious JavaScript into generated SVG output, leading to arbitrary script execution in the context of applications that render the SVG.

    Published: 16 Jan 2026
    4.3
    Medium

    CVE-2025-14384

    Last Modified: 20 Apr 2026

    The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the `/aioseo/v1/ai/credits` REST route in all versions up to, and including, 4.9.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to disclose the global AI access token.

    Published: 16 Jan 2026
    6.5
    Medium

    CVE-2026-1000

    Last Modified: 15 Apr 2026

    The MailerLite - WooCommerce integration plugin for WordPress is vulnerable to unauthorized data modification and deletion in all versions up to, and including, 3.1.3. This is due to missing capability checks on the resetIntegration() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset the plugin's integration settings, delete all plugin options, and drop the plugin's database tables (woo_mailerlite_carts and woo_mailerlite_jobs), resulting in complete loss of plugin data including customer abandoned cart information and sync job history.

    Published: 16 Jan 2026
    4.3
    Medium

    CVE-2025-15370

    Last Modified: 21 Apr 2026

    The Shield: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 21.0.9 via the MfaGoogleAuthToggle class due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to disable Google Authenticator for any user.

    Published: 16 Jan 2026
    8.8
    High

    CVE-2025-12957

    Last Modified: 21 Apr 2026

    The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 4.5.7. This is due to insufficient file type validation detecting VTT files, allowing double extension files to bypass sanitization while being accepted as a valid VTT file. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

    Published: 16 Jan 2026
    6.5
    Medium

    CVE-2025-12641

    Last Modified: 21 Apr 2026

    The Awesome Support - WordPress HelpDesk & Support Plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in all versions up to, and including, 6.3.6. This is due to the 'wpas_do_mr_activate_user' function not verifying that a user has permission to modify other users' roles, combined with a nonce reuse vulnerability where public registration nonces are valid for privileged actions because all actions share the same nonce namespace. This makes it possible for unauthenticated attackers to demote administrators to low-privilege roles via the 'wpas-do=mr_activate_user' action with a user-controlled 'user_id' parameter, granted they can access the publicly available registration/submit ticket page to extract a valid nonce.

    Published: 16 Jan 2026
    5.3
    Medium

    CVE-2025-15526

    Last Modified: 21 Apr 2026

    The Fancy Product Designer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 6.4.8. This is due to improper error handling in the PDF upload functionality that exposes server filesystem paths and stack traces in error messages. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

    Published: 16 Jan 2026
    4.3
    Medium

    CVE-2025-15527

    Last Modified: 20 Apr 2026

    The WP Recipe Maker plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 10.2.2 via the api_get_post_summary function due to insufficient restrictions on which posts can be retrieved. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from posts they may not be able to edit or read otherwise. This also affects password protected, private, or draft posts that they should not have access to.

    Published: 16 Jan 2026
    4.3
    Medium

    CVE-2025-14982

    Last Modified: 22 Apr 2026

    The Booking Calendar plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Exposure in all versions up to, and including, 10.14.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view all booking records in the database, including personally identifiable information (PII) such as names, email addresses, phone numbers, physical addresses, payment status, booking costs, and booking hashes belonging to other users.

    Published: 16 Jan 2026
    8.7
    High

    CVE-2026-1023

    Last Modified: 18 Apr 2026

    Statistics Database System developed by Gotac has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly exploit a specific functionality to query database contents.

    Published: 16 Jan 2026
    8.7
    High

    CVE-2026-1022

    Last Modified: 18 Apr 2026

    Statistics Database System developed by Gotac has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.

    Published: 16 Jan 2026
    9.8
    Critical

    CVE-2026-1021

    Last Modified: 30 Jul 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 16 Jan 2026
    5.3
    Medium

    CVE-2026-1020

    Last Modified: 30 Jul 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 16 Jan 2026
    9.8
    Critical

    CVE-2026-1019

    Last Modified: 30 Jul 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 16 Jan 2026
    7.5
    High

    CVE-2026-1018

    Last Modified: 30 Jul 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 16 Jan 2026
    9.8
    Critical

    CVE-2025-62581

    Last Modified: 4 Jun 2026

    Delta Electronics DIAView has multiple vulnerabilities.

    Published: 16 Jan 2026
    9.8
    Critical

    CVE-2025-62582

    Last Modified: 4 Jun 2026

    Delta Electronics DIAView has multiple vulnerabilities.

    Published: 16 Jan 2026
    7.6
    High

    CVE-2025-64769

    Last Modified: 22 Jan 2026

    The Process Optimization application suite leverages connection channels/protocols that by-default are not encrypted and could become subject to hijacking or data leakage in certain man-in-the-middle or passive inspection scenarios.

    Published: 16 Jan 2026
    8.5
    High

    CVE-2025-65117

    Last Modified: 22 Jan 2026

    The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Designer User) to embed OLE objects into graphics, and escalate their privileges to the identity of a victim user who subsequently interacts with the graphical elements.

    Published: 16 Jan 2026
    8.6
    High

    CVE-2025-64729

    Last Modified: 22 Jan 2026

    The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Process Optimization project files, embed code, and escalate their privileges to the identity of a victim user who subsequently interacts with the project files.

    Published: 16 Jan 2026
    9.3
    Critical

    CVE-2025-65118

    Last Modified: 22 Jan 2026

    The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to trick Process Optimization services into loading arbitrary code and escalate privileges to OS System, potentially resulting in complete compromise of the Model Application Server.

    Published: 16 Jan 2026
    9.3
    Critical

    CVE-2025-61943

    Last Modified: 22 Jan 2026

    The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Standard User) to tamper with queries in Captive Historian and achieve code execution under SQL Server administrative privileges, potentially resulting in complete compromise of the SQL Server.

    Published: 16 Jan 2026
    9.3
    Critical

    CVE-2025-64691

    Last Modified: 22 Jan 2026

    The vulnerability, if exploited, could allow an authenticated miscreant (OS standard user) to tamper with TCL Macro scripts and escalate privileges to OS system, potentially resulting in complete compromise of the model application server.

    Published: 16 Jan 2026
    10
    Critical

    CVE-2025-61937

    Last Modified: 22 Jan 2026

    The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS system privileges of “taoimr” service, potentially resulting in complete compromise of the  model application server.

    Published: 16 Jan 2026