CVE Feed

    Dashboard / CVE

    8.7
    High

    CVE-2021-47757

    Last Modified: 5 Mar 2026

    Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability in the backup restoration functionality. Authenticated attackers can upload a modified backup zip file with a malicious PHP shell to execute arbitrary system commands on the server.

    Published: 15 Jan 2026
    8.7
    High

    CVE-2021-47755

    Last Modified: 7 Apr 2026

    Oliver Library Server v5 contains a file download vulnerability that allows unauthenticated attackers to access arbitrary system files through unsanitized input in the FileServlet endpoint. Attackers can exploit the vulnerability by manipulating the 'fileName' parameter to download sensitive files from the server's filesystem.

    Published: 15 Jan 2026
    6.9
    Medium

    CVE-2021-47754

    Last Modified: 7 Apr 2026

    Arunna 1.0.0 contains a cross-site request forgery vulnerability that allows attackers to manipulate user profile settings without authentication. Attackers can craft a malicious form to change user details, including passwords, email, and administrative privileges by tricking authenticated users into submitting the form.

    Published: 15 Jan 2026
    9.3
    Critical

    CVE-2021-47753

    Last Modified: 7 Apr 2026

    phpKF CMS 3.00 Beta y6 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arbitrary code by bypassing file extension checks. Attackers can upload a PHP file disguised as a PNG, rename it, and execute system commands through a crafted web shell parameter.

    Published: 15 Jan 2026
    8.7
    High

    CVE-2021-47752

    Last Modified: 7 Apr 2026

    AWebServer GhostBuilding 18 contains a denial of service vulnerability that allows remote attackers to overwhelm the server by sending multiple concurrent HTTP requests. Attackers can generate high-volume requests to multiple endpoints including /mysqladmin to potentially crash or render the service unresponsive.

    Published: 15 Jan 2026
    8.8
    High

    CVE-2025-61973

    Last Modified: 15 Apr 2026

    A local privilege escalation vulnerability exists during the installation of Epic Games Store via the Microsoft Store. A low-privilege user can replace a DLL file during the installation process, which may result in unintended elevation of privileges.

    Published: 15 Jan 2026
    7.1
    High

    CVE-2026-0897

    Last Modified: 18 Apr 2026

    Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion and a crash of the Python interpreter via a crafted .keras archive containing a valid model.weights.h5 file whose dataset declares an extremely large shape.

    Published: 15 Jan 2026
    Unknown

    CVE-2026-0991

    Last Modified: 23 Jan 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 15 Jan 2026
    6.4
    Medium

    CVE-2025-13859

    Last Modified: 15 Apr 2026

    The AffiliateX – Amazon Affiliate Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_customization_settings AJAX action in versions 1.0.0 to 1.3.9.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to store arbitrary JavaScript that executes whenever an AffiliateX block renders on the site.

    Published: 15 Jan 2026
    8.8
    High

    CVE-2025-13062

    Last Modified: 22 Apr 2026

    The Supreme Modules Lite plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2.5.62. This is due to insufficient file type validation detecting JSON files, allowing double extension files to bypass sanitization while being accepted as a valid JSON file. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

    Published: 15 Jan 2026
    5.3
    Medium

    CVE-2025-12895

    Last Modified: 22 Apr 2026

    The Kalium 3 | Creative WordPress & WooCommerce Theme theme for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the kalium_vc_contact_form_request() function in all versions up to, and including, 3.29. This makes it possible for unauthenticated attackers to use the theme an an open mail relay and send email to arbitrary email addresses on the server's behalf.

    Published: 15 Jan 2026
    4.3
    Medium

    CVE-2026-22646

    Last Modified: 18 Apr 2026

    Certain error messages returned by the application expose internal system details that should not be visible to end users, providing attackers with valuable reconnaissance information (like file paths, database errors, or software versions) that can be used to map the application's internal structure and discover other, more critical vulnerabilities.

    Published: 15 Jan 2026
    5.3
    Medium

    CVE-2026-22645

    Last Modified: 18 Apr 2026

    The application discloses all used components, versions and license information to unauthenticated actors, giving attackers the opportunity to target known security vulnerabilities of used components.

    Published: 15 Jan 2026
    5.3
    Medium

    CVE-2026-22644

    Last Modified: 18 Apr 2026

    Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft through server logs, proxy logs and Referer headers, which could allow an attacker to hijack the user's session and gain unauthorized access.

    Published: 15 Jan 2026
    Unknown

    CVE-2026-22643

    Last Modified: 22 Jan 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 15 Jan 2026
    Unknown

    CVE-2026-22642

    Last Modified: 22 Jan 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 15 Jan 2026
    Unknown

    CVE-2026-22641

    Last Modified: 22 Jan 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 15 Jan 2026
    Unknown

    CVE-2026-22640

    Last Modified: 22 Jan 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 15 Jan 2026
    Unknown

    CVE-2026-22639

    Last Modified: 22 Jan 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 15 Jan 2026
    Unknown

    CVE-2026-22638

    Last Modified: 22 Jan 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 15 Jan 2026
    Unknown

    CVE-2026-22637

    Last Modified: 22 Jan 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 15 Jan 2026
    Unknown

    CVE-2026-0713

    Last Modified: 22 Jan 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 15 Jan 2026
    Unknown

    CVE-2026-0712

    Last Modified: 22 Jan 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 15 Jan 2026
    Unknown

    CVE-2026-22920

    Last Modified: 12 May 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 15 Jan 2026
    3.8
    Low

    CVE-2026-22919

    Last Modified: 18 Apr 2026

    An attacker with administrative access may inject malicious content into the login page, potentially enabling cross-site scripting (XSS) attacks, leading to the extraction of sensitive data.

    Published: 15 Jan 2026
    4.3
    Medium

    CVE-2026-22918

    Last Modified: 18 Apr 2026

    An attacker may exploit missing protection against clickjacking by tricking users into performing unintended actions through maliciously crafted web pages, leading to the extraction of sensitive data.

    Published: 15 Jan 2026
    4.3
    Medium

    CVE-2026-22917

    Last Modified: 18 Apr 2026

    Improper input handling in a system endpoint may allow attackers to overload resources, causing a denial of service.

    Published: 15 Jan 2026
    4.3
    Medium

    CVE-2026-22916

    Last Modified: 18 Apr 2026

    An attacker with low privileges may be able to trigger critical system functions such as reboot or factory reset without proper restrictions, potentially leading to service disruption or loss of configuration.

    Published: 15 Jan 2026
    4.3
    Medium

    CVE-2026-22915

    Last Modified: 18 Apr 2026

    An attacker with low privileges may be able to read files from specific directories on the device, potentially exposing sensitive information.

    Published: 15 Jan 2026
    4.3
    Medium

    CVE-2026-22914

    Last Modified: 18 Apr 2026

    An attacker with limited permissions may still be able to write files to specific locations on the device, potentially leading to system manipulation.

    Published: 15 Jan 2026
    4.3
    Medium

    CVE-2026-22913

    Last Modified: 18 Apr 2026

    Improper handling of a URL parameter may allow attackers to execute code in a user's browser after login. This can lead to the extraction of sensitive data.

    Published: 15 Jan 2026
    4.3
    Medium

    CVE-2026-22912

    Last Modified: 18 Apr 2026

    Improper validation of a login parameter may allow attackers to redirect users to malicious websites after authentication. This can lead to various risk including stealing credentials from unsuspecting users.

    Published: 15 Jan 2026
    5.3
    Medium

    CVE-2026-22911

    Last Modified: 18 Apr 2026

    Firmware update files may expose password hashes for system accounts, which could allow a remote attacker to recover credentials and gain unauthorized access to the device.

    Published: 15 Jan 2026
    7.5
    High

    CVE-2026-22910

    Last Modified: 18 Apr 2026

    The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized access. This represents a high risk to the integrity of the system.

    Published: 15 Jan 2026
    7.5
    High

    CVE-2026-22909

    Last Modified: 18 Apr 2026

    Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete installed applications, potentially disrupting system operations.

    Published: 15 Jan 2026
    9.1
    Critical

    CVE-2026-22908

    Last Modified: 23 Jan 2026

    Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially compromising its integrity and confidentiality.

    Published: 15 Jan 2026
    Unknown

    CVE-2026-23709

    Last Modified: 16 Jan 2026

    Not used

    Published: 15 Jan 2026
    Unknown

    CVE-2026-23710

    Last Modified: 16 Jan 2026

    Not used

    Published: 15 Jan 2026
    Unknown

    CVE-2026-23711

    Last Modified: 16 Jan 2026

    Not used

    Published: 15 Jan 2026
    Unknown

    CVE-2026-23712

    Last Modified: 16 Jan 2026

    Not used

    Published: 15 Jan 2026
    Unknown

    CVE-2026-23713

    Last Modified: 16 Jan 2026

    Not used

    Published: 15 Jan 2026
    Unknown

    CVE-2026-23714

    Last Modified: 16 Jan 2026

    Not used

    Published: 15 Jan 2026
    9.9
    Critical

    CVE-2026-22907

    Last Modified: 18 Apr 2026

    An attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system data.

    Published: 15 Jan 2026
    3.7
    Low

    CVE-2025-14457

    Last Modified: 22 Apr 2026

    The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ownership check in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.9.2. This makes it possible for unauthenticated attackers to delete arbitrary uploaded files when the "Send attachments as links" setting is enabled.

    Published: 15 Jan 2026
    5.4
    Medium

    CVE-2025-14448

    Last Modified: 21 Apr 2026

    The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Multiple Checkbox and Multiple Select user profile fields in all versions up to, and including, 3.5.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 15 Jan 2026
    3.7
    Low

    CVE-2026-0988

    Last Modified: 24 Apr 2026

    A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this overflow results in an incorrect size being passed to memcpy(), triggering a buffer overflow. This can cause application crashes, leading to a Denial of Service (DoS).

    Published: 15 Jan 2026
    6.1
    Medium

    CVE-2025-67078

    Last Modified: 10 Mar 2026

    Cross site scripting (XSS) vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute arbitrary code via the notify parameter of the file controller used to display errors.

    Published: 15 Jan 2026
    2.9
    Low

    CVE-2026-0992

    Last Modified: 22 Apr 2026

    A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and degrades application availability, resulting in a denial-of-service condition.

    Published: 15 Jan 2026
    3.7
    Low

    CVE-2026-0976

    Last Modified: 18 Apr 2026

    A flaw was found in Keycloak. This improper input validation vulnerability occurs because Keycloak accepts RFC-compliant matrix parameters in URL path segments, while common reverse proxy configurations may ignore or mishandle them. A remote attacker can craft requests to mask path segments, potentially bypassing proxy-level path filtering. This could expose administrative or sensitive endpoints that operators believe are not externally reachable.

    Published: 15 Jan 2026
    7.5
    High

    CVE-2025-70744

    Last Modified: 20 Jan 2026

    Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the cloneType parameter of the sub_65B5C function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

    Published: 15 Jan 2026