CVE Feed

    Dashboard / CVE

    Unknown

    CVE-2026-22834

    Last Modified: 13 Jan 2026

    Not used

    Published: 12 Jan 2026
    Unknown

    CVE-2026-22835

    Last Modified: 13 Jan 2026

    Not used

    Published: 12 Jan 2026
    Unknown

    CVE-2026-22836

    Last Modified: 13 Jan 2026

    Not used

    Published: 12 Jan 2026
    Unknown

    CVE-2026-22830

    Last Modified: 13 Jan 2026

    Not used

    Published: 12 Jan 2026
    Unknown

    CVE-2026-22831

    Last Modified: 13 Jan 2026

    Not used

    Published: 12 Jan 2026
    Unknown

    CVE-2026-22829

    Last Modified: 13 Jan 2026

    Not used

    Published: 12 Jan 2026
    8.1
    High

    CVE-2025-14279

    Last Modified: 14 Apr 2026

    MLFlow versions up to and including 3.4.0 are vulnerable to DNS rebinding attacks due to a lack of Origin header validation in the MLFlow REST server. This vulnerability allows malicious websites to bypass Same-Origin Policy protections and execute unauthorized calls against REST endpoints. An attacker can query, update, and delete experiments via the affected endpoints, leading to potential data exfiltration, destruction, or manipulation. The issue is resolved in version 3.5.0.

    Published: 12 Jan 2026
    8.7
    High

    CVE-2026-0855

    Last Modified: 18 Apr 2026

    Certain IP Camera models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the device.

    Published: 12 Jan 2026
    4.8
    Medium

    CVE-2025-14579

    Last Modified: 15 Apr 2026

    The Quiz Maker WordPress plugin before 6.7.0.89 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 12 Jan 2026
    8.7
    High

    CVE-2026-0854

    Last Modified: 18 Apr 2026

    Certain DVR/NVR models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the device.

    Published: 12 Jan 2026
    2.3
    Low

    CVE-2025-69276

    Last Modified: 14 Jan 2026

    Deserialization of Untrusted Data vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Object Injection.This issue affects DX NetOps Spectrum: 24.3.13 and earlier.

    Published: 12 Jan 2026
    7.1
    High

    CVE-2025-69275

    Last Modified: 14 Jan 2026

    Dependency on Vulnerable Third-Party Component vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows DOM-Based XSS.This issue affects DX NetOps Spectrum: 24.3.9 and earlier.

    Published: 12 Jan 2026
    2.3
    Low

    CVE-2025-69274

    Last Modified: 14 Jan 2026

    Authorization Bypass Through User-Controlled Key vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Privilege Escalation.This issue affects DX NetOps Spectrum: 24.3.10 and earlier.

    Published: 12 Jan 2026
    8.7
    High

    CVE-2025-69273

    Last Modified: 14 Jan 2026

    Improper Authentication vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Authentication Bypass.This issue affects DX NetOps Spectrum: 24.3.10 and earlier.

    Published: 12 Jan 2026
    5.3
    Medium

    CVE-2025-69272

    Last Modified: 14 Jan 2026

    Cleartext Transmission of Sensitive Information vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sniffing Attacks.This issue affects DX NetOps Spectrum: 21.2.1 and earlier.

    Published: 12 Jan 2026
    2.3
    Low

    CVE-2025-69271

    Last Modified: 14 Jan 2026

    Insufficiently Protected Credentials vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sniffing Attacks.This issue affects DX NetOps Spectrum: 24.3.13 and earlier.

    Published: 12 Jan 2026
    2.3
    Low

    CVE-2025-69270

    Last Modified: 14 Jan 2026

    Information Exposure Through Query Strings in GET Request vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Session Hijacking.This issue affects DX NetOps Spectrum: 24.3.8 and earlier.

    Published: 12 Jan 2026
    7.1
    High

    CVE-2025-69269

    Last Modified: 14 Jan 2026

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows OS Command Injection.This issue affects DX NetOps Spectrum: 23.3.6 and earlier.

    Published: 12 Jan 2026
    5.3
    Medium

    CVE-2025-69268

    Last Modified: 14 Jan 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Reflected XSS.This issue affects DX NetOps Spectrum: 24.3.8 and earlier.

    Published: 12 Jan 2026
    8.8
    High

    CVE-2025-69267

    Last Modified: 14 Jan 2026

    Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Path Traversal.This issue affects DX NetOps Spectrum: 24.3.8 and earlier.

    Published: 12 Jan 2026
    6.9
    Medium

    CVE-2026-0853

    Last Modified: 18 Apr 2026

    Certain NVR models developed by A-Plus Video Technologies has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access the debug page and obtain device status information.

    Published: 12 Jan 2026
    10
    Critical

    CVE-2025-52694

    Last Modified: 26 Jan 2026

    Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability. Users and administrators of affected product versions are advised to update to the latest versions immediately.

    Published: 12 Jan 2026
    5.5
    Medium

    CVE-2026-0852

    Last Modified: 18 Apr 2026

    A security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /Administrator/PHP/AdminUpdateUser.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

    Published: 12 Jan 2026
    6.5
    Medium

    CVE-2025-66689

    Last Modified: 22 Jan 2026

    A path traversal vulnerability exists in Zen MCP Server before 9.8.2 that allows authenticated attackers to read arbitrary files on the system. The vulnerability is caused by flawed logic in the is_dangerous_path() validation function that uses exact string matching against a blacklist of system directories. Attackers can bypass these restrictions by accessing subdirectories of blacklisted paths.

    Published: 12 Jan 2026
    6.5
    Medium

    CVE-2025-65553

    Last Modified: 22 Jan 2026

    D3D Wi-Fi Home Security System ZX-G12 v2.1.17 is susceptible to RF jamming on the 433 MHz alarm sensor channel. An attacker within RF range can transmit continuous interference to block sensor transmissions, resulting in missed alarms and loss of security monitoring. The device lacks jamming detection or mitigations, creating a denial-of-service condition that may lead to undetected intrusions or failure to trigger safety alerts.

    Published: 12 Jan 2026
    9.9
    Critical

    CVE-2025-46066

    Last Modified: 21 Jan 2026

    An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges

    Published: 12 Jan 2026
    9.8
    Critical

    CVE-2025-29329

    Last Modified: 22 Jan 2026

    Buffer Overflow in the ippprint (Internet Printing Protocol) service in Sagemcom F@st 3686 MAGYAR_4.121.0 allows remote attacker to execute arbitrary code by sending a crafted HTTP request.

    Published: 12 Jan 2026
    8.2
    High

    CVE-2023-36331

    Last Modified: 22 Jan 2026

    Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' order details via manipulation of the query parameter userId.

    Published: 12 Jan 2026
    9.1
    Critical

    CVE-2025-51567

    Last Modified: 16 Jan 2026

    A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the rname, rcollage, rnumber, rgender and rpassword parameters in a POST HTTP request.

    Published: 12 Jan 2026
    9.8
    Critical

    CVE-2025-66802

    Last Modified: 9 Feb 2026

    Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE (Remote Code Execution). The application receives a reverse shell (php) into imagem of the user enabling RCE.

    Published: 12 Jan 2026
    5.3
    Medium

    CVE-2025-67813

    Last Modified: 20 Jan 2026

    Quest KACE Desktop Authority through 11.3.1 has Insecure Permissions on the Named Pipes used for inter-process communication

    Published: 12 Jan 2026
    5.4
    Medium

    CVE-2025-66939

    Last Modified: 22 Jan 2026

    Cross Site Scripting vulnerability in 66biolinks by AltumCode v.61.0.1 allows an attacker to execute arbitrary code via a crafted favicon file

    Published: 12 Jan 2026
    5.4
    Medium

    CVE-2021-41074

    Last Modified: 22 Jan 2026

    A CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a crafted HTML document.

    Published: 12 Jan 2026
    9.8
    Critical

    CVE-2025-67147

    Last Modified: 15 Apr 2026

    Multiple SQL Injection vulnerabilities exist in amansuryawanshi Gym-Management-System-PHP 1.0 via the 'name', 'email', and 'comment' parameters in (1) submit_contact.php, the 'username' and 'pass_key' parameters in (2) secure_login.php, and the 'login_id', 'pwfield', and 'login_key' parameters in (3) change_s_pwd.php. An unauthenticated or authenticated attacker can exploit these issues to bypass authentication, execute arbitrary SQL commands, modify database records, delete data, or escalate privileges to administrator level.

    Published: 12 Jan 2026
    8.2
    High

    CVE-2025-46067

    Last Modified: 21 Jan 2026

    An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges and obtain sensitive information via a crafted js file

    Published: 12 Jan 2026
    9.8
    Critical

    CVE-2025-46070

    Last Modified: 21 Jan 2026

    An issue in Automai BotManager v.25.2.0 allows a remote attacker to execute arbitrary code via the BotManager.exe component

    Published: 12 Jan 2026
    9.8
    Critical

    CVE-2025-65552

    Last Modified: 3 Feb 2026

    D3D Wi-Fi Home Security System ZX-G12 v2.1.1 is vulnerable to RF replay attacks on the 433 MHz sensor communication channel. The system does not implement rolling codes, message authentication, or anti-replay protection, allowing an attacker within RF range to record valid alarm/control frames and replay them to trigger false alarms.

    Published: 12 Jan 2026
    9.4
    Critical

    CVE-2025-67146

    Last Modified: 27 Jan 2026

    Multiple SQL Injection vulnerabilities exist in AbhishekMali21 GYM-MANAGEMENT-SYSTEM 1.0 via the 'name' parameter in (1) member_search.php, (2) trainer_search.php, and (3) gym_search.php, and via the 'id' parameter in (4) payment_search.php. An unauthenticated remote attacker can exploit these issues to inject malicious SQL commands, leading to unauthorized data extraction, authentication bypass, or modification of database contents.

    Published: 12 Jan 2026
    10
    Critical

    CVE-2025-63314

    Last Modified: 22 Jan 2026

    A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the user password and execute a full account takeover via a replay attack.

    Published: 12 Jan 2026
    8.8
    High

    CVE-2025-46068

    Last Modified: 21 Jan 2026

    An issue in Automai Director v.25.2.0 allows a remote attacker to execute arbitrary code via the update mechanism

    Published: 12 Jan 2026
    5.5
    Medium

    CVE-2026-0851

    Last Modified: 18 Apr 2026

    A vulnerability was identified in code-projects Online Music Site 1.0. The affected element is an unknown function of the file /Administrator/PHP/AdminAddUser.php. The manipulation of the argument txtusername leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

    Published: 11 Jan 2026
    2
    Low

    CVE-2026-0850

    Last Modified: 18 Apr 2026

    A vulnerability was determined in code-projects Intern Membership Management System 1.0. Impacted is an unknown function of the file /admin/delete_activity.php. Executing a manipulation of the argument activity_id can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

    Published: 11 Jan 2026
    Unknown

    CVE-2022-50974

    Last Modified: 11 Aug 2026

    This CVE ID has been rejected.

    Published: 11 Jan 2026
    8.1
    High

    CVE-2025-68493

    Last Modified: 11 Mar 2026

    Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes the issue.

    Published: 11 Jan 2026
    1.9
    Low

    CVE-2025-15506

    Last Modified: 15 Apr 2026

    A vulnerability was found in AcademySoftwareFoundation OpenColorIO up to 2.5.0. This issue affects the function ConvertToRegularExpression of the file src/OpenColorIO/FileRules.cpp. Performing a manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. The patch is named ebdbb75123c9d5f4643e041314e2bc988a13f20d. To fix this issue, it is recommended to deploy a patch. The fix was added to the 2.5.1 milestone.

    Published: 11 Jan 2026
    2.1
    Low

    CVE-2026-0843

    Last Modified: 18 Apr 2026

    A vulnerability has been found in jiujiujia/victor123/wxw850227 jjjfood and jjjshop_food up to 20260103. This vulnerability affects unknown code of the file /index.php/api/product.category/index. Such manipulation of the argument latitude leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product is distributed under multiple different names. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 11 Jan 2026
    2.1
    Low

    CVE-2026-0842

    Last Modified: 18 Apr 2026

    A flaw has been found in Flycatcher Toys smART Sketcher up to 2.0. This affects an unknown part of the component Bluetooth Low Energy Interface. This manipulation causes missing authentication. The attack can only be done within the local network. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 11 Jan 2026
    7.4
    High

    CVE-2026-0841

    Last Modified: 18 Apr 2026

    A vulnerability was detected in UTT 进取 520W 1.7.7-180627. Affected by this issue is the function strcpy of the file /goform/formPictureUrl. The manipulation of the argument importpictureurl results in buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 11 Jan 2026
    7.4
    High

    CVE-2026-0840

    Last Modified: 18 Apr 2026

    A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. Affected by this vulnerability is the function strcpy of the file /goform/formConfigNoticeConfig. The manipulation of the argument timestart leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 11 Jan 2026
    7.4
    High

    CVE-2026-0839

    Last Modified: 18 Apr 2026

    A weakness has been identified in UTT 进取 520W 1.7.7-180627. Affected is the function strcpy of the file /goform/APSecurity. Executing a manipulation of the argument wepkey1 can lead to buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 11 Jan 2026