CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2025-67281

    Last Modified: 22 Jan 2026

    In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple SQL injection vulnerabilities exists which allow a low privileged and administrative user to access the database and its content.

    Published: 9 Jan 2026
    6.5
    Medium

    CVE-2025-67004

    Last Modified: 23 Jan 2026

    ** Disputed ** An Information Disclosure vulnerability in CouchCMS 2.4 allow an Admin user to read arbitrary files via traversing directories back after back. It can Disclosure the source code or any other confidential information if weaponize accordingly. NOTE: A community member states that this is not a CouchCMS vulnerability and that if /\<file> is accessible it is a web-server configuration issue.

    Published: 9 Jan 2026
    5.4
    Medium

    CVE-2025-67280

    Last Modified: 22 Jan 2026

    In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Hibernate Query Language injection vulnerabilities exist which allow a low privileged user to extract passwords of other users and access sensitive data of another user.

    Published: 9 Jan 2026
    7.5
    High

    CVE-2025-66744

    Last Modified: 15 Apr 2026

    In Yonyou YonBIP v3 and before, the LoginWithV8 interface in the series data application service system is vulnerable to path traversal, allowing unauthorized access to sensitive information within the system

    Published: 9 Jan 2026
    2.3
    Low

    CVE-2026-22714

    Last Modified: 18 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Monaco Skin allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Monaco Skin: 1.45, 1.44, 1.43, 1.39.

    Published: 8 Jan 2026
    2.3
    Low

    CVE-2026-22710

    Last Modified: 18 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Wikibase Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Wikibase Extension: 1.45, 1.44, 1.43, 1.39.

    Published: 8 Jan 2026
    2.1
    Low

    CVE-2026-0733

    Last Modified: 18 Apr 2026

    A vulnerability was determined in PHPGurukul Online Course Registration System up to 3.1. This impacts an unknown function of the file /onlinecourse/admin/manage-students.php. This manipulation of the argument id/cid causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

    Published: 8 Jan 2026
    2.1
    Low

    CVE-2026-0732

    Last Modified: 18 Apr 2026

    A vulnerability was found in D-Link DI-8200G 17.12.20A1. This affects an unknown function of the file /upgrade_filter.asp. The manipulation of the argument path results in command injection. The attack may be performed from remote. The exploit has been made public and could be used.

    Published: 8 Jan 2026
    5.5
    Medium

    CVE-2026-0731

    Last Modified: 18 Apr 2026

    A vulnerability has been found in TOTOLINK WA1200 5.9c.2914. The impacted element is an unknown function of the file cstecgi.cgi of the component HTTP Request Handler. The manipulation leads to null pointer dereference. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Jan 2026
    1.9
    Low

    CVE-2026-0730

    Last Modified: 18 Apr 2026

    A flaw has been found in PHPGurukul Staff Leave Management System 1.0. The affected element is the function ADD_STAFF/UPDATE_STAFF of the file /staffleave/slms/slms/adminviews.py of the component SVG File Handler. Executing a manipulation of the argument profile_pic can lead to cross site scripting. The attack can be executed remotely. The exploit has been published and may be used.

    Published: 8 Jan 2026
    2
    Low

    CVE-2026-0729

    Last Modified: 18 Apr 2026

    A vulnerability was detected in code-projects Intern Membership Management System 1.0. Impacted is an unknown function of the file /intern/admin/add_activity.php. Performing a manipulation of the argument Title results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.

    Published: 8 Jan 2026
    7.2
    High

    CVE-2025-14436

    Last Modified: 22 Apr 2026

    The Brevo for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user_connection_id’ parameter in all versions up to, and including, 4.0.49 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 8 Jan 2026
    5.6
    Medium

    CVE-2025-14505

    Last Modified: 15 Apr 2026

    The ECDSA implementation of the Elliptic package generates incorrect signatures if an interim value of 'k' (as computed based on step 3.2 of RFC 6979 https://datatracker.ietf.org/doc/html/rfc6979 ) has leading zeros and is susceptible to cryptanalysis, which can lead to secret key exposure. This happens, because the byte-length of 'k' is incorrectly computed, resulting in its getting truncated during the computation. Legitimate transactions or communications will be broken as a result. Furthermore, due to the nature of the fault, attackers could–under certain conditions–derive the secret key, if they could get their hands on both a faulty signature generated by a vulnerable version of Elliptic and a correct signature for the same inputs. This issue affects all known versions of Elliptic (at the time of writing, versions less than or equal to 6.6.1).

    Published: 8 Jan 2026
    7.5
    High

    CVE-2025-15464

    Last Modified: 12 Feb 2026

    Exported Activity allows external applications to gain application context and directly launch Gmail with inbox access, bypassing security controls.

    Published: 8 Jan 2026
    6.5
    Medium

    CVE-2026-22588

    Last Modified: 18 Apr 2026

    Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Authenticated Insecure Direct Object Reference (IDOR) vulnerability was identified that allows an authenticated user to retrieve other users’ address information by modifying an existing order. By editing an order they legitimately own and manipulating address identifiers in the request, the backend server accepts and processes references to addresses belonging to other users, subsequently associating those addresses with the attacker’s order and returning them in the response. This issue has been patched in versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5.

    Published: 8 Jan 2026
    2
    Low

    CVE-2026-0728

    Last Modified: 18 Apr 2026

    A security vulnerability has been detected in code-projects Intern Membership Management System 1.0. This issue affects some unknown processing of the file /intern/admin/delete_admin.php. Such manipulation of the argument admin_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.

    Published: 8 Jan 2026
    3.3
    Low

    CVE-2026-0747

    Last Modified: 18 Apr 2026

    Exposure of sensitive information in the TeamViewer entry dashboard component in Devolutions Remote Desktop Manager 2025.3.24.0 through 2025.3.28.0 on Windows allows an external observer to view a password on screen via a defective masking feature, for example during physical observation or screen sharing.

    Published: 8 Jan 2026
    Unknown

    CVE-2026-22658

    Last Modified: 10 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 8 Jan 2026
    Unknown

    CVE-2026-22657

    Last Modified: 10 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 8 Jan 2026
    Unknown

    CVE-2026-22656

    Last Modified: 10 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 8 Jan 2026
    Unknown

    CVE-2026-22655

    Last Modified: 10 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 8 Jan 2026
    Unknown

    CVE-2026-22654

    Last Modified: 10 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 8 Jan 2026
    Unknown

    CVE-2026-22653

    Last Modified: 10 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 8 Jan 2026
    Unknown

    CVE-2026-22652

    Last Modified: 10 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 8 Jan 2026
    Unknown

    CVE-2026-22651

    Last Modified: 10 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 8 Jan 2026
    5.4
    Medium

    CVE-2026-22253

    Last Modified: 18 Apr 2026

    Soft Serve is a self-hostable Git server for the command line. Prior to version 0.11.2, an authorization bypass in the LFS lock deletion endpoint allows any authenticated user with repository write access to delete locks owned by other users by setting the force flag. The vulnerable code path processes force deletions before retrieving user context, bypassing ownership validation entirely. This issue has been patched in version 0.11.2.

    Published: 8 Jan 2026
    6.3
    Medium

    CVE-2026-21860

    Last Modified: 18 Apr 2026

    Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.5, Werkzeug's safe_join function allows path segments with Windows device names that have file extensions or trailing spaces. On Windows, there are special device names such as CON, AUX, etc that are implicitly present and readable in every directory. Windows still accepts them with any file extension, such as CON.txt, or trailing spaces such as CON. This issue has been patched in version 3.1.5.

    Published: 8 Jan 2026
    8.8
    High

    CVE-2026-22257

    Last Modified: 18 Apr 2026

    Salvo is a Rust web backend framework. Prior to version 0.88.1, the function list_html generates a file view of a folder without sanitizing the files or folders names, this may potentially lead to XSS in cases where a website allow the access to public files using this feature and anyone can upload a file. This issue has been patched in version 0.88.1.

    Published: 8 Jan 2026
    8.8
    High

    CVE-2026-22256

    Last Modified: 18 Apr 2026

    Salvo is a Rust web backend framework. Prior to version 0.88.1, the function list_html generate an file view of a folder which include a render of the current path, in which its inserted in the HTML without proper sanitation, this leads to reflected XSS using the fact that request path is decoded and normalized in the matching stage but not is inserted raw in the html view (current.path), the only constraint here is for the root path (eg. /files in the PoC example) to have a sub directory (e.g common ones styles/scripts/etc…) so that the matching return the list HTML page instead of the Not Found page. This issue has been patched in version 0.88.1.

    Published: 8 Jan 2026
    5.8
    Medium

    CVE-2026-21896

    Last Modified: 18 Apr 2026

    Kirby is an open-source content management system. From versions 5.0.0 to 5.2.1, Kirby is missing permission checks in the content changes API. This vulnerability affects all Kirby sites where user permissions are configured to prevent specific role(s) from performing write actions, specifically by disabling the update permission with the intent to prevent modifications to site content. This vulnerability does not affect those who have not altered the deviated from default user permissions. This issue has been patched in version 5.2.2.

    Published: 8 Jan 2026
    5.7
    Medium

    CVE-2025-68158

    Last Modified: 30 Mar 2026

    Authlib is a Python library which builds OAuth and OpenID Connect servers. In versions 1.0.0 through 1.6.5, cache-backed state/request-token storage is not tied to the initiating user session, so CSRF is possible for any attacker that has a valid state (easily obtainable via an attacker-initiated authentication flow). When a cache is supplied to the OAuth client registry, FrameworkIntegration.set_state_data writes the entire state blob under _state_{app}_{state}, and get_state_data ignores the caller’s session altogether. This issue has been patched in version 1.6.6.

    Published: 8 Jan 2026
    8.7
    High

    CVE-2026-22235

    Last Modified: 18 Apr 2026

    OPEXUS eComplaint before version 9.0.45.0 allows an attacker to visit the the 'DocumentOpen.aspx' endpoint, iterate through predictable values of 'chargeNumber', and download any uploaded files.

    Published: 8 Jan 2026
    9.3
    Critical

    CVE-2026-22234

    Last Modified: 18 Apr 2026

    OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predictable values of 'formid', and download or delete all user-uploaded files, or upload new files.

    Published: 8 Jan 2026
    4.8
    Medium

    CVE-2026-22233

    Last Modified: 18 Apr 2026

    OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript as a comment in the "Estimated Staff Hours" field. The JavaScript is executed whenever another user visits the Project Cost tab. Fixed in OPEXUS eCASE Audit 11.14.2.0.

    Published: 8 Jan 2026
    4.8
    Medium

    CVE-2026-22232

    Last Modified: 18 Apr 2026

    OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript in the "A or SIC Number" field within the Project Setup functionality. The JavaScript is executed whenever another user views the project. Fixed in OPEXUS eCASE Audit 11.14.2.0.

    Published: 8 Jan 2026
    4.8
    Medium

    CVE-2026-22231

    Last Modified: 18 Apr 2026

    OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript as a comment within the Document Check Out functionality. The JavaScript is executed whenever another user views the Action History Log. Fixed in OPEXUS eCASE Platform 11.14.1.0.

    Published: 8 Jan 2026
    7.2
    High

    CVE-2026-22230

    Last Modified: 18 Apr 2026

    OPEXUS eCASE Audit allows an authenticated attacker to modify client-side JavaScript or craft HTTP requests to access functions or buttons that have been disabled or blocked by an administrator. Fixed in eCASE Platform 11.14.1.0.

    Published: 8 Jan 2026
    4.8
    Medium

    CVE-2026-22587

    Last Modified: 18 Apr 2026

    Ideagen DevonWay contains a stored cross site scripting vulnerability. A remote, authenticated attacker could craft a payload in the 'Reports' page that executes when another user views the report. Fixed in 2.62.4 and 2.62 LTS.

    Published: 8 Jan 2026
    5.3
    Medium

    CVE-2026-22486

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Re Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Re Gallery: from n/a through 1.18.9.

    Published: 8 Jan 2026
    4.3
    Medium

    CVE-2026-22487

    Last Modified: 25 Apr 2026

    Missing Authorization vulnerability in baqend Speed Kit baqend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Speed Kit: from n/a through <= 2.0.2.

    Published: 8 Jan 2026
    5.3
    Medium

    CVE-2026-22488

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in IdeaBox Creations Dashboard Welcome for Beaver Builder dashboard-welcome-for-beaver-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dashboard Welcome for Beaver Builder: from n/a through <= 1.0.8.

    Published: 8 Jan 2026
    4.3
    Medium

    CVE-2026-22489

    Last Modified: 23 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in Wptexture Image Slider Slideshow image-slider-slideshow allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Slider Slideshow: from n/a through <= 1.8.

    Published: 8 Jan 2026
    5.4
    Medium

    CVE-2026-22490

    Last Modified: 25 Apr 2026

    Missing Authorization vulnerability in niklaslindemann Bulk Landing Page Creator for WordPress LPagery lpagery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bulk Landing Page Creator for WordPress LPagery: from n/a through <= 2.4.9.

    Published: 8 Jan 2026
    4.3
    Medium

    CVE-2026-22492

    Last Modified: 25 Apr 2026

    Missing Authorization vulnerability in Nawawi Jamili Docket Cache docket-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Docket Cache: from n/a through <= 24.07.04.

    Published: 8 Jan 2026
    5.4
    Medium

    CVE-2026-22517

    Last Modified: 25 Apr 2026

    Missing Authorization vulnerability in Passionate Brains GA4WP: Google Analytics for WordPress ga-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GA4WP: Google Analytics for WordPress: from n/a through <= 2.10.0.

    Published: 8 Jan 2026
    6.1
    Medium

    CVE-2026-0671

    Last Modified: 18 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki - UploadWizard extension allows Cross-Site Scripting (XSS).This issue affects MediaWiki - UploadWizard extension: 1.45, 1.44, 1.43, 1.39.

    Published: 8 Jan 2026
    6.5
    Medium

    CVE-2026-22518

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pencilwp X Addons for Elementor x-addons-elementor allows DOM-Based XSS.This issue affects X Addons for Elementor: from n/a through <= 1.0.23.

    Published: 8 Jan 2026
    6.5
    Medium

    CVE-2026-22519

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddyDev MediaPress mediapress allows Stored XSS.This issue affects MediaPress: from n/a through <= 1.6.2.

    Published: 8 Jan 2026
    7.5
    High

    CVE-2026-22521

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in G5Theme Handmade Framework handmade-framework allows PHP Local File Inclusion.This issue affects Handmade Framework: from n/a through <= 3.9.

    Published: 8 Jan 2026
    9
    Critical

    CVE-2025-59468

    Last Modified: 26 Feb 2026

    This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter.

    Published: 8 Jan 2026