CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2025-70656

    Last Modified: 20 Jan 2026

    Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the mac parameter of the sub_65B5C function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

    Published: 15 Jan 2026
    5.5
    Medium

    CVE-2025-70305

    Last Modified: 23 Jan 2026

    A stack overflow in the dmx_saf function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .saf file.

    Published: 15 Jan 2026
    7.5
    High

    CVE-2025-70304

    Last Modified: 23 Jan 2026

    A buffer overflow in the vobsub_get_subpic_duration() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted packet.

    Published: 15 Jan 2026
    9.8
    Critical

    CVE-2025-67079

    Last Modified: 21 Jan 2026

    File upload vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute code through the MSL engine of the Imagick library via crafted PDF file to the file upload and thumbnail functions.

    Published: 15 Jan 2026
    7.5
    High

    CVE-2025-71019

    Last Modified: 20 Jan 2026

    Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the wanSpeed parameter of the sub_65B5C function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

    Published: 15 Jan 2026
    7.5
    High

    CVE-2024-48077

    Last Modified: 3 Apr 2026

    NanoMQ v0.22.7 is vulnerable to Denial of Service (DoS) due to improper resource throttling. A crafted sequence of requests causes the recv-q queue to saturate, leading to the rapid exhaustion of system file descriptors (FDs). This exhaustion triggers a process crash, rendering the broker unable to provide services.

    Published: 15 Jan 2026
    5.9
    Medium

    CVE-2026-0990

    Last Modified: 22 Apr 2026

    A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recursion and call stack exhaustion. This ultimately results in a segmentation fault, causing a Denial of Service (DoS) by crashing affected applications.

    Published: 15 Jan 2026
    3.7
    Low

    CVE-2026-0989

    Last Modified: 22 Apr 2026

    A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk.

    Published: 15 Jan 2026
    6.5
    Medium

    CVE-2025-70299

    Last Modified: 30 Jan 2026

    A heap overflow in the avi_parse_input_file() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted AVI file.

    Published: 15 Jan 2026
    7.3
    High

    CVE-2025-67246

    Last Modified: 20 Apr 2026

    A local information disclosure vulnerability exists in the Ludashi driver before 5.1025 due to a lack of access control in the IOCTL handler. This driver exposes a device interface accessible to a normal user and handles attacker-controlled structures containing the lower 4GB of physical addresses. The handler maps arbitrary physical memory via MmMapIoSpace and copies data back to user mode without verifying the caller's privileges or the target address range. This allows unprivileged users to read arbitrary physical memory, potentially exposing kernel data structures, kernel pointers, security tokens, and other sensitive information. This vulnerability can be further exploited to bypass the Kernel Address Space Layout Rules (KASLR) and achieve local privilege escalation.

    Published: 15 Jan 2026
    5.5
    Medium

    CVE-2025-70302

    Last Modified: 23 Jan 2026

    A heap overflow in the ghi_dmx_declare_opid_bin() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.

    Published: 15 Jan 2026
    8.2
    High

    CVE-2025-67823

    Last Modified: 23 Jan 2026

    A vulnerability in the Multimedia Email component of Mitel MiContact Center Business through 10.2.0.10 and Mitel CX through 1.1.0.1 could allow an unauthenticated attacker to conduct a Cross-Site Scripting (XSS) attack due to insufficient input validation. A successful exploit requires user interaction where the email channel is enabled. This could allow an attacker to execute arbitrary scripts in the victim's browser or desktop client application.

    Published: 15 Jan 2026
    4.9
    Medium

    CVE-2025-67081

    Last Modified: 23 Jan 2026

    An SQL injection vulnerability in Itflow through 25.06 has been identified in the "role_id" parameter when editing a profile. An attacker with admin account can exploit this issue via blind SQL injection, allowing for the extraction of arbitrary data from the database. The vulnerability arises from insufficient sanitizing on integer parameter.

    Published: 15 Jan 2026
    5.5
    Medium

    CVE-2025-70310

    Last Modified: 23 Jan 2026

    A heap overflow in the vorbis_to_intern() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .ogg file.

    Published: 15 Jan 2026
    5.5
    Medium

    CVE-2025-70309

    Last Modified: 23 Jan 2026

    A stack overflow in the pcmreframe_flush_packet function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted WAV file.

    Published: 15 Jan 2026
    7.5
    High

    CVE-2025-70308

    Last Modified: 23 Jan 2026

    An out-of-bounds read in the GSF demuxer filter component of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .gsf file.

    Published: 15 Jan 2026
    8.2
    High

    CVE-2025-70298

    Last Modified: 23 Jan 2026

    GPAC v2.4.0 was discovered to contain an out-of-bounds read in the oggdmx_parse_tags function.

    Published: 15 Jan 2026
    9.8
    Critical

    CVE-2025-70892

    Last Modified: 22 Jan 2026

    Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module. The application fails to properly validate user-supplied input in the username parameter of the add-users.php endpoint.

    Published: 15 Jan 2026
    6.1
    Medium

    CVE-2025-70891

    Last Modified: 22 Jan 2026

    A stored cross-site scripting (XSS) vulnerability exists in Phpgurukul Cyber Cafe Management System v1.0 within the user management module. The application does not properly sanitize or encode user-supplied input submitted via the uadd parameter in the add-users.php endpoint. An authenticated attacker can inject arbitrary JavaScript code that is persistently stored in the database. The malicious payload is triggered when a privileged user clicks the View button on the view-allusers.php page.

    Published: 15 Jan 2026
    6.1
    Medium

    CVE-2025-70890

    Last Modified: 22 Jan 2026

    A stored cross-site scripting (XSS) vulnerability exists in Cyber Cafe Management System v1.0. An authenticated attacker can inject arbitrary JavaScript code into the username parameter via the add-users.php endpoint. The injected payload is stored and executed in the victim s browser when the affected page is accessed.

    Published: 15 Jan 2026
    9.9
    Critical

    CVE-2025-67084

    Last Modified: 22 Jan 2026

    File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which can later be executed remotely, leading to Remote Code Execution (RCE).

    Published: 15 Jan 2026
    5.3
    Medium

    CVE-2025-67083

    Last Modified: 22 Jan 2026

    Directory traversal vulnerability in InvoicePlane through 1.6.3 allows unauthenticated attackers to read files from the server. The ability to read files and the file type depends on the web server and its configuration.

    Published: 15 Jan 2026
    6.5
    Medium

    CVE-2025-67082

    Last Modified: 22 Jan 2026

    An SQL injection vulnerability in InvoicePlane through 1.6.3 has been identified in "maxQuantity" and "minQuantity" parameters when generating a report. An authenticated attacker can exploit this issue via error-based SQL injection, allowing for the extraction of arbitrary data from the database. The vulnerability arises from insufficient sanitizing of single quotes.

    Published: 15 Jan 2026
    6.1
    Medium

    CVE-2025-65368

    Last Modified: 22 Jan 2026

    SparkyFitness v0.15.8.2 is vulnerable to Cross Site Scripting (XSS) via user input and LLM output.

    Published: 15 Jan 2026
    9.4
    Critical

    CVE-2025-67822

    Last Modified: 21 Jan 2026

    A vulnerability in the Provisioning Manager component of Mitel MiVoice MX-ONE 7.3 (7.3.0.0.50) through 7.8 SP1 (7.8.1.0.14) could allow an unauthenticated attacker to conduct an authentication bypass attack due to improper authentication mechanisms. A successful exploit could allow an attacker to gain unauthorized access to user or admin accounts in the system.

    Published: 15 Jan 2026
    8.8
    High

    CVE-2025-67077

    Last Modified: 21 Jan 2026

    File upload vulnerability in Omnispace Agora Project before 25.10 allowing authenticated, or under certain conditions also guest users, via the UploadTmpFile action.

    Published: 15 Jan 2026
    7.5
    High

    CVE-2025-67076

    Last Modified: 21 Jan 2026

    Directory traversal vulnerability in Omnispace Agora Project before 25.10 allowing unauthenticated attackers to read files on the system via the misc controller and the ExternalGetFile action. Only files with an extension can be read.

    Published: 15 Jan 2026
    5.5
    Medium

    CVE-2025-70303

    Last Modified: 23 Jan 2026

    A heap overflow in the uncv_parse_config() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.

    Published: 15 Jan 2026
    6.1
    Medium

    CVE-2025-67025

    Last Modified: 30 Jan 2026

    Cross Site Scripting vulnerability in Anycomment anycomment.io 0.4.4 allows a remote attacker to execute arbitrary code via the Anycomment comment section

    Published: 15 Jan 2026
    7.5
    High

    CVE-2025-70307

    Last Modified: 30 Jan 2026

    A stack overflow in the dump_ttxt_sample function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted packet.

    Published: 15 Jan 2026
    8.8
    High

    CVE-2025-70893

    Last Modified: 22 Jan 2026

    A time-based blind SQL Injection vulnerability exists in PHPGurukul Cyber Cafe Management System v1.0 within the adminprofile.php endpoint. The application fails to properly sanitize user-supplied input provided via the adminname parameter, allowing authenticated attackers to inject arbitrary SQL expressions.

    Published: 15 Jan 2026
    5.4
    Medium

    CVE-2025-65349

    Last Modified: 23 Jan 2026

    A Stored Cross-Site Scripting (XSS) vulnerability in Web management interface in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to execute arbitrary scripts via a crafted payload due to unsanitized repeater AP SSID value when is displayed in any page at /index.htm.

    Published: 15 Jan 2026
    6.2
    Medium

    CVE-2026-0600

    Last Modified: 18 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Sonatype Nexus Repository 3 versions 3.0.0 and later allows authenticated administrators to configure proxy repositories with URLs that can access unintended network destinations, potentially including cloud metadata services and internal network resources. A workaround configuration is available starting in version 3.88.0, but the product remains vulnerable by default.

    Published: 14 Jan 2026
    7.5
    High

    CVE-2025-12166

    Last Modified: 22 Apr 2026

    The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to blind SQL Injection via the `order` and `append_where_sql` parameters in all versions up to, and including, 1.6.9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 14 Jan 2026
    2.4
    Low

    CVE-2025-14058

    Last Modified: 15 Apr 2026

    A potential missing authentication vulnerability was reported in some Lenovo Tablets that could allow an unauthorized user with physical access to modify Control Center settings if the device is locked when the "Allow Control Center access when locked" option is disabled.

    Published: 14 Jan 2026
    7
    High

    CVE-2026-0421

    Last Modified: 18 Apr 2026

    A potential vulnerability was reported in the BIOS of L13 Gen 6, L13 Gen 6 2-in-1, L14 Gen 6, and L16 Gen 2 ThinkPads which could result in Secure Boot being disabled even when configured as “On” in the BIOS setup menu. This issue only affects systems where Secure Boot is set to User Mode.

    Published: 14 Jan 2026
    7.3
    High

    CVE-2025-13455

    Last Modified: 23 Feb 2026

    A vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to bypass ThinkPlus device authentication and enroll an untrusted fingerprint.

    Published: 14 Jan 2026
    6.8
    Medium

    CVE-2025-13454

    Last Modified: 25 Feb 2026

    A potential vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to gain access to sensitive device information.

    Published: 14 Jan 2026
    5.1
    Medium

    CVE-2025-13453

    Last Modified: 25 Feb 2026

    A potential vulnerability was reported in some ThinkPlus USB drives that could allow a user with physical access to read data stored on the drive.

    Published: 14 Jan 2026
    6.8
    Medium

    CVE-2025-13154

    Last Modified: 15 Apr 2026

    An improper link following vulnerability was reported in the SmartPerformanceAddin for Lenovo Vantage that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges.

    Published: 14 Jan 2026
    5.1
    Medium

    CVE-2026-0601

    Last Modified: 18 Apr 2026

    A reflected cross-site scripting vulnerability exists in Nexus Repository 3 that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted request requiring user interaction.

    Published: 14 Jan 2026
    8.4
    High

    CVE-2026-0861

    Last Modified: 29 Apr 2026

    Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption. Note that the attacker must have control over both, the size as well as the alignment arguments of the memalign function to be able to exploit this. The size parameter must be close enough to PTRDIFF_MAX so as to overflow size_t along with the large alignment argument. This limits the malicious inputs for the alignment for memalign to the range [1<<62+ 1, 1<<63] and exactly 1<<63 for posix_memalign and aligned_alloc. Typically the alignment argument passed to such functions is a known constrained quantity (e.g. page size, block size, struct sizes) and is not attacker controlled, because of which this may not be easily exploitable in practice. An application bug could potentially result in the input alignment being too large, e.g. due to a different buffer overflow or integer overflow in the application or its dependent libraries, but that is again an uncommon usage pattern given typical sources of alignments.

    Published: 14 Jan 2026
    8.6
    High

    CVE-2026-23512

    Last Modified: 18 Apr 2026

    SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, there is a Untrusted Search Path vulnerability when Advanced Options setting is trigger. The application executes notepad.exe without specifying an absolute path when using the Advanced Options setting. On Windows, this allows execution of a malicious notepad.exe placed in the application's installation directory, leading to arbitrary code execution.

    Published: 14 Jan 2026
    5.5
    Medium

    CVE-2026-0961

    Last Modified: 18 Apr 2026

    BLF file parser crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service

    Published: 14 Jan 2026
    5.3
    Medium

    CVE-2026-0962

    Last Modified: 16 Apr 2026

    SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service

    Published: 14 Jan 2026
    4.7
    Medium

    CVE-2026-0960

    Last Modified: 18 Apr 2026

    HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service

    Published: 14 Jan 2026
    5.3
    Medium

    CVE-2026-0959

    Last Modified: 18 Apr 2026

    IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service

    Published: 14 Jan 2026
    Unknown

    CVE-2026-23692

    Last Modified: 10 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 14 Jan 2026
    5.9
    Medium

    CVE-2026-22036

    Last Modified: 18 Apr 2026

    Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, the number of links in the decompression chain is unbounded and the default maxHeaderSize allows a malicious server to insert thousands compression steps leading to high CPU usage and excessive memory allocation. This vulnerability is fixed in 7.18.0 and 6.23.0.

    Published: 14 Jan 2026
    7.7
    High

    CVE-2025-11224

    Last Modified: 26 Feb 2026

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated user to execute stored cross-site scripting through improper input validation in the Kubernetes proxy functionality.

    Published: 14 Jan 2026