CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2026-21502

    Last Modified: 18 Apr 2026

    iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to NULL pointer dereference via the XML tag parser. This issue has been patched in version 2.3.1.2.

    Published: 7 Jan 2026
    5.5
    Medium

    CVE-2026-21500

    Last Modified: 18 Apr 2026

    iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to stack overflow in the XML calculator macro expansion. This issue has been patched in version 2.3.1.2.

    Published: 7 Jan 2026
    5.5
    Medium

    CVE-2026-21499

    Last Modified: 18 Apr 2026

    iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to NULL pointer dereference via the XML parser. This issue has been patched in version 2.3.1.2.

    Published: 7 Jan 2026
    5.5
    Medium

    CVE-2026-21498

    Last Modified: 18 Apr 2026

    iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to NULL pointer dereference via the XML calculator parser. This issue has been patched in version 2.3.1.2.

    Published: 7 Jan 2026
    5.5
    Medium

    CVE-2026-21496

    Last Modified: 18 Apr 2026

    iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to NULL pointer dereference via the signature parser. This issue has been patched in version 2.3.1.2.

    Published: 7 Jan 2026
    7.1
    High

    CVE-2025-4677

    Last Modified: 15 Apr 2026

    Insufficient Session Expiration vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.This issue affects WebPro SNMP Card PowerValue: through 1.1.8.K; WebPro SNMP Card PowerValue UL: through 1.1.8.K.

    Published: 7 Jan 2026
    5.5
    Medium

    CVE-2026-21497

    Last Modified: 18 Apr 2026

    iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to NULL pointer dereference via an unknown tag parser. This issue has been patched in version 2.3.1.2.

    Published: 7 Jan 2026
    5.5
    Medium

    CVE-2026-21495

    Last Modified: 18 Apr 2026

    iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to division by zero in the TIFF Image Reader. This issue has been patched in version 2.3.1.2.

    Published: 7 Jan 2026
    6.8
    Medium

    CVE-2026-22537

    Last Modified: 18 Apr 2026

    The lack of hardening of the system allows the user used to manage and maintain the charger to consult different files containing clear-text credentials or valuable information for an attacker.

    Published: 7 Jan 2026
    8.4
    High

    CVE-2025-4676

    Last Modified: 15 Apr 2026

    Incorrect Implementation of Authentication Algorithm vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.This issue affects WebPro SNMP Card PowerValue: through 1.1.8.K; WebPro SNMP Card PowerValue UL: through 1.1.8.K.

    Published: 7 Jan 2026
    6.1
    Medium

    CVE-2026-0618

    Last Modified: 18 Apr 2026

    Cross-site Scripting vulnerability in Devolutions PowerShell Universal.This issue affects Powershell Universal: before 4.5.6, before 5.6.13.

    Published: 7 Jan 2026
    7.1
    High

    CVE-2025-4675

    Last Modified: 15 Apr 2026

    Improper Check for Unusual or Exceptional Conditions vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.This issue affects WebPro SNMP Card PowerValue: through 1.1.8.K; WebPro SNMP Card PowerValue UL: through 1.1.8.K.

    Published: 7 Jan 2026
    8.6
    High

    CVE-2026-22536

    Last Modified: 18 Apr 2026

    The absence of permissions control for the user XXX allows the current configuration in the sudoers file to escalate privileges without any restrictions

    Published: 7 Jan 2026
    8.9
    High

    CVE-2026-22535

    Last Modified: 18 Apr 2026

    An attacker with the ability to interact through the network and with access credentials, could, thanks to the unsecured (unencrypted) MQTT communications protocol, write on the server topics of the board that controls the MQTT communications

    Published: 7 Jan 2026
    4.9
    Medium

    CVE-2026-20029

    Last Modified: 18 Apr 2026

    A vulnerability in the licensing features of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to gain access to sensitive information.  This vulnerability is due to improper parsing of XML that is processed by the web-based management interface of Cisco ISE and Cisco ISE-PIC. An attacker could exploit this vulnerability by uploading a malicious file to the application. A successful exploit could allow the attacker to read arbitrary files from the underlying operating system that could include sensitive data that should otherwise be inaccessible even to administrators. To exploit this vulnerability, the attacker must have valid administrative credentials.

    Published: 7 Jan 2026
    5.3
    Medium

    CVE-2026-20027

    Last Modified: 18 Apr 2026

    Multiple Cisco products are affected by a vulnerability in the processing of DCE/RPC requests that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to leak sensitive information or to restart, resulting in an interruption of packet inspection. This vulnerability is due to an error in buffer handling logic when processing DCE/RPC requests, which can result in a buffer out-of-bounds read. An attacker could exploit this vulnerability by sending a large number of DCE/RPC requests through an established connection that is inspected by Snort 3. A successful exploit could allow the attacker to obtain sensitive information in the Snort 3 data stream.

    Published: 7 Jan 2026
    5.8
    Medium

    CVE-2026-20026

    Last Modified: 18 Apr 2026

    Multiple Cisco products are affected by a vulnerability in the processing of DCE/RPC requests that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to leak sensitive information or to restart, resulting in an interruption of packet inspection. This vulnerability is due to an error in buffer handling logic when processing DCE/RPC requests, which can result in a buffer use-after-free read. An attacker could exploit this vulnerability by sending a large number of DCE/RPC requests through an established connection that is inspected by Snort 3. A successful exploit could allow the attacker to unexpectedly restart the Snort 3 Detection Engine, which could cause a denial of service (DoS).

    Published: 7 Jan 2026
    8.7
    High

    CVE-2026-22544

    Last Modified: 18 Apr 2026

    An attacker with a network connection could detect credentials in clear text.

    Published: 7 Jan 2026
    6.9
    Medium

    CVE-2026-22543

    Last Modified: 18 Apr 2026

    The credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is not considered a strong cipher, an attacker could intercept the web request handling the login and obtain the credentials

    Published: 7 Jan 2026
    9.2
    Critical

    CVE-2026-22542

    Last Modified: 18 Apr 2026

    An attacker with access to the system's internal network can cause a denial of service on the system by making two concurrent connections through the Telnet service.

    Published: 7 Jan 2026
    4.9
    Medium

    CVE-2025-62327

    Last Modified: 29 Jan 2026

    In HCL DevOps Deploy 8.1.2.0 through 8.1.2.3, a user with LLM configuration privileges may be able to recover a credential previously saved for performing authenticated LLM Queries.

    Published: 7 Jan 2026
    8.2
    High

    CVE-2026-22541

    Last Modified: 18 Apr 2026

    The massive sending of ICMP requests causes a denial of service on one of the boards from the EVCharger that allows control the EV interfaces. Since the board must be operating correctly for the charger to also function correctly.

    Published: 7 Jan 2026
    9.2
    Critical

    CVE-2026-22540

    Last Modified: 18 Apr 2026

    The massive sending of ARP requests causes a denial of service on one board of the charger that allows control of the EV interfaces. Since the board must be operating correctly for the charger to also function correctly.

    Published: 7 Jan 2026
    4.9
    Medium

    CVE-2025-49335

    Last Modified: 23 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in minnur External Media external-media allows Server Side Request Forgery.This issue affects External Media: from n/a through <= 1.0.36.

    Published: 7 Jan 2026
    5.1
    Medium

    CVE-2025-15479

    Last Modified: 29 Jan 2026

    Stored cross-site scripting (XSS, CWE-79) in the survey content and administration functionality in Data Illusion Zumbrunn NGSurvey Enterprise Edition 3.6.4 on all supported platforms ( on Windows and Linux servers ) allows authenticated remote users with survey creation or edit privileges to execute arbitrary JavaScript in other users’ browsers, steal session information and perform unauthorized actions on their behalf via crafted survey content that is rendered without proper output encoding.

    Published: 7 Jan 2026
    6.9
    Medium

    CVE-2025-6225

    Last Modified: 15 Apr 2026

    Kieback&Peter Neutrino-GLT product is used for building management. It's web component "SM70 PHWEB" is vulnerable to shell command injection via login form. The injected commands would execute with low privileges. The vulnerability has been fixed in version 9.40.02

    Published: 7 Jan 2026
    9.8
    Critical

    CVE-2025-47552

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This issue affects DZS Video Gallery: from n/a through 12.37.

    Published: 7 Jan 2026
    7.1
    High

    CVE-2025-46494

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themesgrove WidgetKit Pro allows Reflected XSS.This issue affects WidgetKit Pro: from n/a through 1.13.1.

    Published: 7 Jan 2026
    6.5
    Medium

    CVE-2025-46434

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro theplus_elementor_addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Plus Addons for Elementor Pro: from n/a through < 6.3.7.

    Published: 7 Jan 2026
    6.4
    Medium

    CVE-2025-46256

    Last Modified: 28 Apr 2026

    Path Traversal: '.../...//' vulnerability in SigmaPlugin Advanced Database Cleaner PRO allows Path Traversal.This issue affects Advanced Database Cleaner PRO: from n/a through 3.2.10.

    Published: 7 Jan 2026
    9.3
    Critical

    CVE-2025-32303

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla WPCHURCH allows Blind SQL Injection.This issue affects WPCHURCH: from n/a through 2.7.0.

    Published: 7 Jan 2026
    3.2
    Low

    CVE-2026-25211

    Last Modified: 18 Apr 2026

    Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log.

    Published: 7 Jan 2026
    7.1
    High

    CVE-2025-32300

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital zoom studio DZS Video Gallery allows Reflected XSS.This issue affects DZS Video Gallery: from n/a through 12.25.

    Published: 7 Jan 2026
    8.8
    High

    CVE-2025-31643

    Last Modified: 28 Apr 2026

    Incorrect Privilege Assignment vulnerability in Dasinfomedia WPCHURCH allows Privilege Escalation.This issue affects WPCHURCH: from n/a through 2.7.0.

    Published: 7 Jan 2026
    8.1
    High

    CVE-2025-69080

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JanStudio Gecko gecko allows PHP Local File Inclusion.This issue affects Gecko: from n/a through <= 1.9.8.

    Published: 7 Jan 2026
    8.1
    High

    CVE-2025-69081

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Hope charity-is-hope allows PHP Local File Inclusion.This issue affects Hope: from n/a through <= 3.0.0.

    Published: 7 Jan 2026
    7.1
    High

    CVE-2025-69082

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Frenify Arlo arlo allows Reflected XSS.This issue affects Arlo: from n/a through <= 6.0.3.

    Published: 7 Jan 2026
    4.3
    Medium

    CVE-2025-69333

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Crocoblock JetEngine jet-engine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetEngine: from n/a through <= 3.8.1.1.

    Published: 7 Jan 2026
    4.3
    Medium

    CVE-2025-69344

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in themehunk Oneline Lite oneline-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Oneline Lite: from n/a through <= 6.6.

    Published: 7 Jan 2026
    9.1
    Critical

    CVE-2025-68637

    Last Modified: 16 Jan 2026

    The Uniffle HTTP client is configured to trust all SSL certificates and disables hostname verification by default. This insecure configuration exposes all REST API communication between the Uniffle CLI/client and the Uniffle Coordinator service to potential Man-in-the-Middle (MITM) attacks. This issue affects all versions from before 0.10.0. Users are recommended to upgrade to version 0.10.0, which fixes the issue.

    Published: 7 Jan 2026
    5.3
    Medium

    CVE-2025-13722

    Last Modified: 21 Apr 2026

    The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.1.7. This is due to missing capability checks on the `fluentform_ai_create_form` AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary forms via the publicly exposed AI builder.

    Published: 7 Jan 2026
    4.4
    Medium

    CVE-2025-14057

    Last Modified: 20 Apr 2026

    The Multi-column Tag Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 17.0.39 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 7 Jan 2026
    4.3
    Medium

    CVE-2025-14077

    Last Modified: 20 Apr 2026

    The Simcast plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on the settingsPage function. This makes it possible for unauthenticated attackers to modify plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 7 Jan 2026
    6.4
    Medium

    CVE-2025-15058

    Last Modified: 21 Apr 2026

    The Responsive Pricing Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'table_currency' parameter in all versions up to, and including, 5.1.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Jan 2026
    6.4
    Medium

    CVE-2025-14114

    Last Modified: 21 Apr 2026

    The 1180px Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' shortcode attribute in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Jan 2026
    5.3
    Medium

    CVE-2025-14460

    Last Modified: 20 Apr 2026

    The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized order status modification in all versions up to, and including, 3.1.4. This is due to missing authorization checks on the payment callback endpoint handler when processing the 'fail' callback from the payment gateway. This makes it possible for unauthenticated attackers to change any order's status to 'failed' via the publicly accessible WooCommerce API endpoint by providing only the order ID (MerchantReference parameter), which can be easily enumerated as order IDs are sequential integers. This can cause significant business disruption including canceled shipments, inventory issues, and loss of revenue.

    Published: 7 Jan 2026
    6.4
    Medium

    CVE-2025-14122

    Last Modified: 21 Apr 2026

    The AD Sliding FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sliding_faq' shortcode in all versions up to, and including, 2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Jan 2026
    4.4
    Medium

    CVE-2025-13974

    Last Modified: 21 Apr 2026

    The Email Customizer for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email template content in all versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in email templates that will execute when customers view transactional emails. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 7 Jan 2026
    6.4
    Medium

    CVE-2025-14121

    Last Modified: 20 Apr 2026

    The EDD Download Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'edd_download_info_link' shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Jan 2026
    6.4
    Medium

    CVE-2025-14147

    Last Modified: 20 Apr 2026

    The Easy GitHub Gist Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the gist shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Jan 2026