CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2025-13753

    Last Modified: 20 Apr 2026

    The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to unauthorized modification of data due to an incorrect authorization check on the save_table() function in all versions up to, and including, 2.0.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create new wptb-table posts.

    Published: 9 Jan 2026
    4.3
    Medium

    CVE-2025-13935

    Last Modified: 22 Apr 2026

    The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course completion in all versions up to, and including, 3.9.2. This is due to missing enrollment verification in the 'mark_course_complete' function. This makes it possible for authenticated attackers, with subscriber level access and above, to mark any course as completed.

    Published: 9 Jan 2026
    4.3
    Medium

    CVE-2025-13934

    Last Modified: 22 Apr 2026

    The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course enrollment in all versions up to, and including, 3.9.3. This is due to a missing capability check and purchasability validation in the `course_enrollment()` AJAX handler. This makes it possible for authenticated attackers, with subscriber level access and above, to enroll themselves in any course without going through the proper purchase flow.

    Published: 9 Jan 2026
    9.1
    Critical

    CVE-2025-14741

    Last Modified: 22 Apr 2026

    The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to missing authorization to unauthorized data modification and deletion due to a missing capability check on the 'delete_object' function in all versions up to, and including, 3.28.25. This makes it possible for unauthenticated attackers to delete arbitrary posts, pages, products, taxonomy terms, and user accounts.

    Published: 9 Jan 2026
    4.3
    Medium

    CVE-2025-13628

    Last Modified: 21 Apr 2026

    The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification and deletion of data due to a missing capability check on the 'bulk_action_handler' and 'coupon_permanent_delete' functions in all versions up to, and including, 3.9.3. This makes it possible for authenticated attackers, with subscriber level access and above, to delete, activate, deactivate, or trash arbitrary coupons.

    Published: 9 Jan 2026
    7.2
    High

    CVE-2025-14937

    Last Modified: 22 Apr 2026

    The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'acff' parameter in the 'frontend_admin/forms/update_field' AJAX action in all versions up to, and including, 3.28.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 9 Jan 2026
    5.3
    Medium

    CVE-2025-14146

    Last Modified: 22 Apr 2026

    The Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 10.14.10 via the `WPBC_FLEXTIMELINE_NAV` AJAX action. This is due to the nonce verification being conditionally disabled by default (`booking_is_nonce_at_front_end` option is `'Off'` by default). When the `booking_is_show_popover_in_timeline_front_end` option is enabled (which is the default in demo installations and can be enabled by administrators), it is possible for unauthenticated attackers to extract sensitive booking data including customer names, email addresses, phone numbers, and booking details.

    Published: 9 Jan 2026
    8.2
    High

    CVE-2026-21409

    Last Modified: 18 Apr 2026

    Improper authorization vulnerability exists in RICOH Streamline NX 3.5.1 to 24R3. If a man-in-the-middle attack is conducted on the communication between the affected product and its user, and some crafted request is processed by the product, the user's registration information and/or OIDC (OpenID Connect) tokens may be retrieved.

    Published: 9 Jan 2026
    10
    Critical

    CVE-2025-70974

    Last Modified: 15 Apr 2026

    Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain public methods of that class. Depending on the behavior of those methods, there may be JNDI injection with an attacker-supplied payload located elsewhere in that JSON document. This was exploited in the wild in 2023 through 2025. NOTE: this issue exists because of an incomplete fix for CVE-2017-18349. Also, a later bypass is covered by CVE-2022-25845.

    Published: 9 Jan 2026
    5.3
    Medium

    CVE-2025-14574

    Last Modified: 20 Apr 2026

    The weDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.15 via the `/wp-json/wp/v2/docs/settings` REST API endpoint. This makes it possible for unauthenticated attackers to extract sensitive data including third party services API keys.

    Published: 9 Jan 2026
    6.4
    Medium

    CVE-2025-14893

    Last Modified: 20 Apr 2026

    The IndieWeb plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Telephone' parameter in all versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 9 Jan 2026
    7.2
    High

    CVE-2025-15055

    Last Modified: 21 Apr 2026

    The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' and 'resource' parameters in all versions up to, and including, 5.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator accesses the Recent Custom Events report.

    Published: 9 Jan 2026
    7.2
    High

    CVE-2025-15057

    Last Modified: 21 Apr 2026

    The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fh` (fingerprint) parameter in all versions up to, and including, 5.3.3. This is due to insufficient input sanitization and output escaping on the fingerprint value stored in the database. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator views the Real-time Access Log report.

    Published: 9 Jan 2026
    5.4
    Medium

    CVE-2025-14718

    Last Modified: 21 Apr 2026

    The Schedule Post Changes With PublishPress Future plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.9.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Contributor-level access and above, to create, update, delete, and publish malicious workflows that may automatically delete any post upon publication or update, including posts created by administrators.

    Published: 9 Jan 2026
    5.3
    Medium

    CVE-2025-14720

    Last Modified: 21 Apr 2026

    The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on multiple AJAX actions in all versions up to, and including, 1.2.38. This makes it possible for unauthenticated attackers to mark payments as refunded, trigger sending of queued notifications (emails/SMS/WhatsApp), and access debug information among other things.

    Published: 9 Jan 2026
    6.4
    Medium

    CVE-2026-0563

    Last Modified: 16 Apr 2026

    The WP Google Street View (with 360° virtual tour) & Google maps + Local SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpgsv_map' shortcode in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 9 Jan 2026
    5.3
    Medium

    CVE-2025-14782

    Last Modified: 15 Apr 2026

    The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.49.1 via the 'listen_for_csv_export' function. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with access to the Forminator dashboard, to export sensitive form submission data including personally identifiable information.

    Published: 9 Jan 2026
    6.5
    Medium

    CVE-2025-14980

    Last Modified: 22 Apr 2026

    The BetterDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.3 via the scripts() function. This makes it possible for authenticated attackers, with contributor-level access and above, to extract sensitive data including the OpenAI API key stored in plugin settings.

    Published: 9 Jan 2026
    6.4
    Medium

    CVE-2025-15019

    Last Modified: 22 Apr 2026

    The BIALTY - Bulk Image Alt Text (Alt tag, Alt Attribute) with Yoast SEO + WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bialty_cs_alt' post meta in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever an administrator accesses the post editor.

    Published: 9 Jan 2026
    9.8
    Critical

    CVE-2025-14736

    Last Modified: 22 Apr 2026

    The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.28.29. This is due to insufficient validation of user-supplied role values in the 'validate_value', 'pre_update_value', and 'get_fields_display' functions. This makes it possible for unauthenticated attackers to register as administrators and gain complete control of the site, granted they can access a user registration form containing a Role field.

    Published: 9 Jan 2026
    5.1
    Medium

    CVE-2026-20976

    Last Modified: 18 Apr 2026

    Improper input validation in Galaxy Store prior to version 4.6.02 allows local attacker to execute arbitrary script.

    Published: 9 Jan 2026
    2.1
    Low

    CVE-2026-20975

    Last Modified: 18 Apr 2026

    Improper handling of insufficient permission in Samsung Cloud prior to version 5.6.11 allows local attackers to access specific files in arbitrary path.

    Published: 9 Jan 2026
    5.2
    Medium

    CVE-2026-20974

    Last Modified: 18 Apr 2026

    Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 allows physical attackers to bypass Carrier Relock.

    Published: 9 Jan 2026
    5.3
    Medium

    CVE-2026-20973

    Last Modified: 18 Apr 2026

    Out-of-bounds read in libimagecodec.quram.so prior to SMR Jan-2026 Release 1 allows remote attacker to access out-of-bounds memory.

    Published: 9 Jan 2026
    4.8
    Medium

    CVE-2026-20972

    Last Modified: 18 Apr 2026

    Improper Export of Android Application Components in UwbTest prior to SMR Jan-2026 Release 1 allows local attackers to enable UWB.

    Published: 9 Jan 2026
    7.3
    High

    CVE-2026-20971

    Last Modified: 18 Apr 2026

    Use After Free in PROCA driver prior to SMR Jan-2026 Release 1 allows local attackers to potentially execute arbitrary code.

    Published: 9 Jan 2026
    6.8
    Medium

    CVE-2026-20970

    Last Modified: 18 Apr 2026

    Improper access control in SLocation prior to SMR Jan-2026 Release 1 allows local attackers to execute the privileged APIs.

    Published: 9 Jan 2026
    2.3
    Low

    CVE-2026-20969

    Last Modified: 18 Apr 2026

    Improper input validation in SecSettings prior to SMR Jan-2026 Release 1 allows local attacker to access file with system privilege. User interaction is required for triggering this vulnerability.

    Published: 9 Jan 2026
    6.7
    Medium

    CVE-2026-20968

    Last Modified: 18 Apr 2026

    Use after free in DualDAR prior to SMR Jan-2026 Release 1 allows local privileged attackers to execute arbitrary code.

    Published: 9 Jan 2026
    6.8
    Medium

    CVE-2025-14803

    Last Modified: 15 Apr 2026

    The NEX-Forms WordPress plugin before 9.1.8 does not sanitise and escape some of its settings. The NEX-Forms WordPress plugin before 9.1.8 can be configured in such a way that could allow subscribers to perform Stored Cross-Site Scripting.

    Published: 9 Jan 2026
    4.3
    Medium

    CVE-2025-13749

    Last Modified: 22 Apr 2026

    The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.0. This is due to missing nonce validation on the "wbcr_upm_change_flag" function. This makes it possible for unauthenticated attackers to disable plugin/theme update notifications via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 9 Jan 2026
    5.3
    Medium

    CVE-2025-14886

    Last Modified: 22 Apr 2026

    The Japanized for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `order` REST API endpoint in all versions up to, and including, 2.7.17. This makes it possible for unauthenticated attackers to mark any WooCommerce order as processed/completed.

    Published: 9 Jan 2026
    4.3
    Medium

    CVE-2025-66315

    Last Modified: 12 Mar 2026

    There is a configuration defect vulnerability in the version server of ZTE MF258K Pro products. Due to improper directory permission settings, an attacker can execute write permissions in a specific directory.

    Published: 9 Jan 2026
    6.4
    Medium

    CVE-2025-14525

    Last Modified: 15 Apr 2026

    A flaw was found in kubevirt. A user within a virtual machine (VM), if the guest agent is active, can exploit this by causing the agent to report an excessive number of network interfaces. This action can overwhelm the system's ability to store VM configuration updates, effectively blocking changes to the Virtual Machine Instance (VMI). This allows the VM user to restrict the VM administrator's ability to manage the VM, leading to a denial of service for administrative operations.

    Published: 9 Jan 2026
    2.3
    Low

    CVE-2026-22712

    Last Modified: 18 Apr 2026

    Improper Encoding or Escaping of Output due to magic word replacement in ParserAfterTidy vulnerability in The Wikimedia Foundation Mediawiki - ApprovedRevs Extension allows Input Data Manipulation.This issue affects Mediawiki - ApprovedRevs Extension: 1.45, 1.44, 1.43, 1.39.

    Published: 9 Jan 2026
    2.3
    Low

    CVE-2026-22713

    Last Modified: 18 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - GrowthExperiments Extension: 1.45, 1.44, 1.43, 1.39.

    Published: 9 Jan 2026
    6.5
    Medium

    CVE-2025-66715

    Last Modified: 22 Jan 2026

    A DLL hijacking vulnerability in Axtion ODISSAAS ODIS v1.8.4 allows attackers to execute arbitrary code via a crafted DLL file.

    Published: 9 Jan 2026
    6.5
    Medium

    CVE-2025-60538

    Last Modified: 22 Jan 2026

    A lack of rate limiting in the login page of shiori v1.7.4 and below allows attackers to bypass authentication via a brute force attack.

    Published: 9 Jan 2026
    7.5
    High

    CVE-2025-56225

    Last Modified: 23 Jan 2026

    fluidsynth-2.4.6 and earlier versions is vulnerable to Null pointer dereference in fluid_synth_monopoly.c, that can be triggered when loading an invalid midi file.

    Published: 9 Jan 2026
    8.2
    High

    CVE-2025-67070

    Last Modified: 15 Apr 2026

    A vulnerability exists in Intelbras CFTV IP NVD 9032 R Ftd V2.800.00IB00C.0.T, which allows an unauthenticated attacker to bypass the multi-factor authentication (MFA) mechanism during the password recovery process. This results in the ability to change the admin password and gain full access to the administrative panel.

    Published: 9 Jan 2026
    6.5
    Medium

    CVE-2025-51626

    Last Modified: 22 Jan 2026

    SQL injection vulnerability in pss.sale.com 1.0 via the id parameter to the userfiles/php/cancel_order.php endpoint.

    Published: 9 Jan 2026
    6.5
    Medium

    CVE-2025-67811

    Last Modified: 10 Feb 2026

    Area9 Rhapsode 1.47.3 allows SQL Injection via multiple API endpoints accessible to authenticated users. Insufficient input validation allows remote attackers to inject arbitrary SQL commands, resulting in unauthorized database access and potential compromise of sensitive data. Fixed in v.1.47.4 and beyond.

    Published: 9 Jan 2026
    6.5
    Medium

    CVE-2025-67810

    Last Modified: 10 Feb 2026

    In Area9 Rhapsode 1.47.3, an authenticated attacker can exploit the operation, url, and filename parameters via POST request to read arbitrary files from the server filesystem. Fixed in 1.47.4 (#7254) and further versions.

    Published: 9 Jan 2026
    9.8
    Critical

    CVE-2025-70161

    Last Modified: 22 Jan 2026

    EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the system() function without proper sanitization. An attacker can exploit this by injecting malicious commands into the pppUserName field, allowing arbitrary code execution.

    Published: 9 Jan 2026
    7.5
    High

    CVE-2025-67133

    Last Modified: 20 Apr 2026

    An issue in Hero Motocorp Vida V1 Pro 2.0.7 allows a local attacker to cause a denial of service via the BLE component

    Published: 9 Jan 2026
    5.3
    Medium

    CVE-2025-67279

    Last Modified: 22 Jan 2026

    An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges via the application stores password hashes in MD5 format

    Published: 9 Jan 2026
    6.5
    Medium

    CVE-2025-67278

    Last Modified: 22 Jan 2026

    An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges via a crafted HTTP request

    Published: 9 Jan 2026
    9.8
    Critical

    CVE-2025-69542

    Last Modified: 10 Feb 2026

    A Command Injection Vulnerability has been discovered in the DHCP daemon service of D-Link DIR895LA1 v102b07. The vulnerability exists in the lease renewal processing logic where the DHCP hostname parameter is directly concatenated into a system command without proper sanitization. When a DHCP client renews an existing lease with a malicious hostname, arbitrary commands can be executed with root privileges.

    Published: 9 Jan 2026
    5.4
    Medium

    CVE-2025-67282

    Last Modified: 22 Jan 2026

    In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Authorization Bypass vulnerabilities exists which allow a low privileged user to download password hashes of other user, access work items of other user, modify restricted content in workflows, modify the applications logo and manipulate the profile of other user.

    Published: 9 Jan 2026
    6.5
    Medium

    CVE-2026-0665

    Last Modified: 18 Apr 2026

    An off-by-one error was found in QEMU's KVM Xen guest support. A malicious guest could use this flaw to trigger out-of-bounds heap accesses in the QEMU process via the emulated Xen physdev hypercall interface, leading to a denial of service or potential memory corruption.

    Published: 9 Jan 2026