CVE Feed

    Dashboard / CVE

    4.8
    Medium

    CVE-2025-14557

    Last Modified: 23 Jan 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Facebook Pixel facebook_pixel allows Stored XSS.This issue affects Facebook Pixel: from 7.X-1.0 through 7.X-1.1.

    Published: 14 Jan 2026
    4.8
    Medium

    CVE-2025-14556

    Last Modified: 23 Jan 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Flag allows Cross-Site Scripting (XSS).This issue affects Flag: from 7.X-3.0 through 7.X-3.9.

    Published: 14 Jan 2026
    Unknown

    CVE-2026-23691

    Last Modified: 10 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 14 Jan 2026
    Unknown

    CVE-2026-23690

    Last Modified: 10 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 14 Jan 2026
    7.2
    High

    CVE-2026-23498

    Last Modified: 18 Apr 2026

    Shopware is an open commerce platform. From 6.7.0.0 to before 6.7.6.1, a regression of CVE-2023-2017 leads to an array and array crafted PHP Closure not checked being against allow list for the map(...) override. This vulnerability is fixed in 6.7.6.1.

    Published: 14 Jan 2026
    7.8
    High

    CVE-2025-33206

    Last Modified: 26 Feb 2026

    NVIDIA NSIGHT Graphics for Linux contains a vulnerability where an attacker could cause command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and denial of service.

    Published: 14 Jan 2026
    4.8
    Medium

    CVE-2025-71166

    Last Modified: 5 Mar 2026

    Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the administrative interface within the Tools Status move message handling. The path parameter is reflected into the HTML output without proper output encoding in include/admin/Tools/Status.php. An authenticated attacker can supply crafted input containing HTML or JavaScript, resulting in arbitrary script execution in the context of an authenticated user's browser session.

    Published: 14 Jan 2026
    4.8
    Medium

    CVE-2025-71165

    Last Modified: 5 Mar 2026

    Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the administrative interface within the Tools Status functionality. The path parameter is reflected into the HTML response without proper output encoding in include/admin/Tools/Status.php. An authenticated attacker can supply crafted input containing HTML or JavaScript, resulting in arbitrary script execution in the context of an authenticated user's browser session.

    Published: 14 Jan 2026
    4.8
    Medium

    CVE-2025-71164

    Last Modified: 5 Mar 2026

    Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the Editing component. The images parameter (submitted as images[] in a POST request) is reflected into an HTML href attribute without proper context-aware output encoding in include/tool/Editing.php. An authenticated attacker with editing privileges can supply a JavaScript pseudo-protocol (e.g., javascript:) to trigger arbitrary JavaScript execution in the context of the victim's browser session.

    Published: 14 Jan 2026
    1.3
    Low

    CVE-2026-23497

    Last Modified: 18 Apr 2026

    Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In 2.44.0 and earlier, there is a stored XSS vulnerability where a specially crafted image filename could execute malicious JavaScript when rendered on course or jobs pages.

    Published: 14 Jan 2026
    8.8
    High

    CVE-2026-23492

    Last Modified: 18 Apr 2026

    Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, an incomplete SQL injection patch in the Admin Search Find API allows an authenticated attacker to perform blind SQL injection. Although CVE-2023-30848 attempted to mitigate SQL injection by removing SQL comments (--) and catching syntax errors, the fix is insufficient. Attackers can still inject SQL payloads that do not rely on comments and infer database information via blind techniques. This vulnerability affects the admin interface and can lead to database information disclosure. This vulnerability is fixed in 12.3.1 and 11.5.14.

    Published: 14 Jan 2026
    7.7
    High

    CVE-2026-23477

    Last Modified: 18 Apr 2026

    Rocket.Chat is an open-source, secure, fully customizable communications platform. In Rocket.Chat versions up to 6.12.0, the API endpoint GET /api/v1/oauth-apps.get is exposed to any authenticated user, regardless of their role or permissions. This endpoint returns an OAuth application, as long as the user knows its ID, including potentially sensitive fields such as client_id and client_secret. This vulnerability is fixed in 6.12.0.

    Published: 14 Jan 2026
    5.9
    Medium

    CVE-2026-22819

    Last Modified: 18 Apr 2026

    Outray openSource ngrok alternative. Prior to 0.1.5, this vulnerability allows a user i.e a free plan user to get more than the desired subdomains due to lack of db transaction lock mechanisms in main/apps/web/src/routes/api/$orgSlug/subdomains/index.ts. This vulnerability is fixed in 0.1.5.

    Published: 14 Jan 2026
    5.6
    Medium

    CVE-2026-22859

    Last Modified: 18 Apr 2026

    FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, the URBDRC client does not perform bounds checking on server‑supplied MSUSB_INTERFACE_DESCRIPTOR values and uses them as indices in libusb_udev_complete_msconfig_setup, causing an out‑of‑bounds read. This vulnerability is fixed in 3.20.1.

    Published: 14 Jan 2026
    5.6
    Medium

    CVE-2026-22858

    Last Modified: 18 Apr 2026

    FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, global-buffer-overflow was observed in FreeRDP's Base64 decoding path. The root cause appears to be implementation-defined char signedness: on Arm/AArch64 builds, plain char is treated as unsigned, so the guard c <= 0 can be optimized into a simple c != 0 check. As a result, non-ASCII bytes (e.g., 0x80-0xFF) may bypass the intended range restriction and be used as an index into a global lookup table, causing out-of-bounds access. This vulnerability is fixed in 3.20.1.

    Published: 14 Jan 2026
    6.8
    Medium

    CVE-2026-22857

    Last Modified: 18 Apr 2026

    FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap use-after-free occurs in irp_thread_func because the IRP is freed by irp->Complete() and then accessed again on the error path. This vulnerability is fixed in 3.20.1.

    Published: 14 Jan 2026
    6.8
    Medium

    CVE-2026-22856

    Last Modified: 18 Apr 2026

    FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race in the serial channel IRP thread tracking allows a heap use‑after‑free when one thread removes an entry from serial->IrpThreads while another reads it. This vulnerability is fixed in 3.20.1.

    Published: 14 Jan 2026
    5.6
    Medium

    CVE-2026-22855

    Last Modified: 18 Apr 2026

    FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap out-of-bounds read occurs in the smartcard SetAttrib path when cbAttrLen does not match the actual NDR buffer length. This vulnerability is fixed in 3.20.1.

    Published: 14 Jan 2026
    6.8
    Medium

    CVE-2026-22854

    Last Modified: 18 Apr 2026

    FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap-buffer-overflow occurs in drive read when a server-controlled read length is used to read file data into an IRP output stream buffer without a hard upper bound, allowing an oversized read to overwrite heap memory. This vulnerability is fixed in 3.20.1.

    Published: 14 Jan 2026
    6.8
    Medium

    CVE-2026-22853

    Last Modified: 18 Apr 2026

    FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, RDPEAR’s NDR array reader does not perform bounds checking on the on‑wire element count and can write past the heap buffer allocated from hints, causing a heap buffer overflow in ndr_read_uint8Array. This vulnerability is fixed in 3.20.1.

    Published: 14 Jan 2026
    6.8
    Medium

    CVE-2026-22852

    Last Modified: 18 Apr 2026

    FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client when processing Audio Input (AUDIN) format lists. audin_process_formats reuses callback->formats_count across multiple MSG_SNDIN_FORMATS PDUs and writes past the newly allocated formats array, causing memory corruption and a crash. This vulnerability is fixed in 3.20.1.

    Published: 14 Jan 2026
    6.9
    Medium

    CVE-2026-22851

    Last Modified: 18 Apr 2026

    FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race condition between the RDPGFX dynamic virtual channel thread and the SDL render thread leads to a heap use-after-free. Specifically, an escaped pointer to sdl->primary (SDL_Surface) is accessed after it has been freed during RDPGFX ResetGraphics handling. This vulnerability is fixed in 3.20.1.

    Published: 14 Jan 2026
    Unknown

    CVE-2026-23677

    Last Modified: 10 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 14 Jan 2026
    Unknown

    CVE-2026-23676

    Last Modified: 10 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 14 Jan 2026
    Unknown

    CVE-2026-23675

    Last Modified: 10 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 14 Jan 2026
    8.7
    High

    CVE-2026-22787

    Last Modified: 18 Apr 2026

    html2pdf.js converts any webpage or element into a printable PDF entirely client-side. Prior to 0.14.0, html2pdf.js contains a cross-site scripting (XSS) vulnerability when given a text source rather than an element. This text is not sufficiently sanitized before being attached to the DOM, allowing malicious scripts to be run on the client browser and risking the confidentiality, integrity, and availability of the page's data. This vulnerability has been fixed in [email protected].

    Published: 14 Jan 2026
    6.3
    Medium

    CVE-2026-22779

    Last Modified: 18 Apr 2026

    BlackSheep is an asynchronous web framework to build event based web applications with Python. Prior to 2.4.6, the HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers.The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. This vulnerability is fixed in 2.4.6.

    Published: 14 Jan 2026
    7.2
    High

    CVE-2026-22708

    Last Modified: 18 Apr 2026

    Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode with Allowlist mode enabled, certain shell built-ins can still be executed without appearing in the allowlist and without requiring user approval. This allows an attacker via indirect or direct prompt injection to poison the shell environment by setting, modifying, or removing environment variables that influence trusted commands. This vulnerability is fixed in 2.3.

    Published: 14 Jan 2026
    6.1
    Medium

    CVE-2026-22694

    Last Modified: 18 Apr 2026

    AliasVault is a privacy-first password manager with built-in email aliasing. AliasVault Android versions 0.24.0 through 0.25.2 contained an issue in how passkey requests from Android apps were validated. Under certain local conditions, a malicious app could attempt to obtain a passkey response for a site it was not authorized to access. The issue involved incomplete validation of calling app identity, origin, and RP ID in the Android credential provider. This issue was fixed in AliasVault Android 0.25.3.

    Published: 14 Jan 2026
    2.3
    Low

    CVE-2026-21889

    Last Modified: 18 Apr 2026

    Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. This vulnerability is fixed in 5.15.2.

    Published: 14 Jan 2026
    7.2
    High

    CVE-2025-37181

    Last Modified: 20 Jan 2026

    Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially leading to unauthorized data access or data manipulation.

    Published: 14 Jan 2026
    5.5
    Medium

    CVE-2025-37185

    Last Modified: 20 Jan 2026

    Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attacks against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface and thereby make unauthorized arbitrary configuration changes to the host.

    Published: 14 Jan 2026
    9.8
    Critical

    CVE-2025-37184

    Last Modified: 3 Mar 2026

    A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-factor authentication requirements. Successful exploitation could allow an attacker to create an admin user account without the necessary multi-factor authentication, thereby compromising the integrity of secured access to the system.

    Published: 14 Jan 2026
    7.2
    High

    CVE-2025-37183

    Last Modified: 20 Jan 2026

    Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially leading to unauthorized data access or data manipulation.

    Published: 14 Jan 2026
    7.2
    High

    CVE-2025-37182

    Last Modified: 20 Jan 2026

    Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially leading to unauthorized data access or data manipulation.

    Published: 14 Jan 2026
    Unknown

    CVE-2026-23591

    Last Modified: 2 Sept 2026

    Withdrawn by requester.

    Published: 14 Jan 2026
    Unknown

    CVE-2026-23590

    Last Modified: 2 Sept 2026

    Withdrawn by requester.

    Published: 14 Jan 2026
    Unknown

    CVE-2026-23586

    Last Modified: 2 Sept 2026

    Withdrawn by requester.

    Published: 14 Jan 2026
    Unknown

    CVE-2026-23585

    Last Modified: 2 Sept 2026

    Withdrawn by requester.

    Published: 14 Jan 2026
    Unknown

    CVE-2026-23584

    Last Modified: 2 Sept 2026

    Withdrawn by requester.

    Published: 14 Jan 2026
    Unknown

    CVE-2026-23583

    Last Modified: 2 Sept 2026

    Withdrawn by requester.

    Published: 14 Jan 2026
    Unknown

    CVE-2026-23589

    Last Modified: 2 Sept 2026

    Withdrawn by requester.

    Published: 14 Jan 2026
    Unknown

    CVE-2026-23588

    Last Modified: 2 Sept 2026

    Withdrawn by requester.

    Published: 14 Jan 2026
    Unknown

    CVE-2026-23587

    Last Modified: 2 Sept 2026

    Withdrawn by requester.

    Published: 14 Jan 2026
    5.1
    Medium

    CVE-2026-22211

    Last Modified: 18 Apr 2026

    TinyOS versions up to and including 2.1.2 contain a global buffer overflow vulnerability in the printfUART formatted output implementation used within the ZigBee / IEEE 802.15.4 networking stack. The implementation formats output into a fixed-size global buffer and concatenates strings for %s format specifiers using strcat() without verifying remaining buffer capacity. When printfUART is invoked with a caller-controlled string longer than the available space, the unbounded sprintf/strcat sequence writes past the end of debugbuf, resulting in global memory corruption. This can cause denial of service, unintended behavior, or information disclosure via corrupted adjacent global state or UART output.

    Published: 14 Jan 2026
    6.3
    Medium

    CVE-2026-22820

    Last Modified: 18 Apr 2026

    Outray openSource ngrok alternative. Prior to 0.1.5, a TOCTOU race condition vulnerability allows a user to exceed the set number of active tunnels in their subscription plan. This vulnerability is fixed in 0.1.5.

    Published: 14 Jan 2026
    Unknown

    CVE-2026-23580

    Last Modified: 15 Jan 2026

    Not used

    Published: 14 Jan 2026
    Unknown

    CVE-2026-23581

    Last Modified: 15 Jan 2026

    Not used

    Published: 14 Jan 2026
    Unknown

    CVE-2026-23582

    Last Modified: 15 Jan 2026

    Not used

    Published: 14 Jan 2026
    Unknown

    CVE-2026-23574

    Last Modified: 15 Jan 2026

    Not used

    Published: 14 Jan 2026