CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2025-47369

    Last Modified: 27 Jan 2026

    Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.

    Published: 6 Jan 2026
    7.8
    High

    CVE-2025-47356

    Last Modified: 27 Jan 2026

    Memory Corruption when multiple threads concurrently access and modify shared resources.

    Published: 6 Jan 2026
    7.8
    High

    CVE-2025-47348

    Last Modified: 28 Jan 2026

    Memory corruption while processing identity credential operations in the trusted application.

    Published: 6 Jan 2026
    7.8
    High

    CVE-2025-47346

    Last Modified: 27 Jan 2026

    Memory corruption while processing a secure logging command in the trusted application.

    Published: 6 Jan 2026
    8.4
    High

    CVE-2025-47345

    Last Modified: 27 Jan 2026

    Cryptographic issue may occur while encrypting license data.

    Published: 6 Jan 2026
    6.7
    Medium

    CVE-2025-47344

    Last Modified: 27 Jan 2026

    Memory corruption while handling sensor utility operations.

    Published: 6 Jan 2026
    7.8
    High

    CVE-2025-47343

    Last Modified: 12 Jan 2026

    Memory corruption while processing a video session to set video parameters.

    Published: 6 Jan 2026
    7.8
    High

    CVE-2025-47339

    Last Modified: 27 Jan 2026

    Memory corruption while deinitializing a HDCP session.

    Published: 6 Jan 2026
    6.7
    Medium

    CVE-2025-47337

    Last Modified: 27 Jan 2026

    Memory corruption while accessing a synchronization object during concurrent operations.

    Published: 6 Jan 2026
    6.7
    Medium

    CVE-2025-47336

    Last Modified: 27 Jan 2026

    Memory corruption while performing sensor register read operations.

    Published: 6 Jan 2026
    6.7
    Medium

    CVE-2025-47335

    Last Modified: 27 Jan 2026

    Memory corruption while parsing clock configuration data for a specific hardware type.

    Published: 6 Jan 2026
    6.7
    Medium

    CVE-2025-47334

    Last Modified: 27 Jan 2026

    Memory corruption while processing shared command buffer packet between camera userspace and kernel.

    Published: 6 Jan 2026
    6.6
    Medium

    CVE-2025-47333

    Last Modified: 28 Jan 2026

    Memory corruption while handling buffer mapping operations in the cryptographic driver.

    Published: 6 Jan 2026
    6.7
    Medium

    CVE-2025-47332

    Last Modified: 28 Jan 2026

    Memory corruption while processing a config call from userspace.

    Published: 6 Jan 2026
    6.1
    Medium

    CVE-2025-47331

    Last Modified: 28 Jan 2026

    Information disclosure while processing a firmware event.

    Published: 6 Jan 2026
    5.5
    Medium

    CVE-2025-47330

    Last Modified: 28 Jan 2026

    Transient DOS while parsing video packets received from the video firmware.

    Published: 6 Jan 2026
    1.9
    Low

    CVE-2026-0642

    Last Modified: 18 Apr 2026

    A vulnerability was detected in projectworlds House Rental and Property Listing 1.0. This issue affects some unknown processing of the file /app/complaint.php. The manipulation of the argument Name results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used.

    Published: 6 Jan 2026
    3.7
    Low

    CVE-2025-11235

    Last Modified: 3 Feb 2026

    Unverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules).This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.3, from 2023.0.0 before 2023.0.8, from 2022.1.0 before 2022.1.11, from 2022.0.0 before 2022.0.10.

    Published: 6 Jan 2026
    7.3
    High

    CVE-2025-15472

    Last Modified: 23 Feb 2026

    A flaw has been found in TRENDnet TEW-811DRU 1.0.2.0. This affects the function setDeviceURL  of the file uapply.cgi of the component httpd . This manipulation of the argument DeviceURL causes os command injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 6 Jan 2026
    5.4
    Medium

    CVE-2025-14625

    Last Modified: 28 Jan 2026

    Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard on Windows (Nios II Command Shell modules), Altera Quartus Prime Lite on Windows (Nios II Command Shell modules) allows Search Order Hijacking.This issue affects Quartus Prime Standard: from 19.1 through 24.1; Quartus Prime Lite: from 19.1 through 24.1.

    Published: 6 Jan 2026
    5.4
    Medium

    CVE-2025-14614

    Last Modified: 12 Jan 2026

    Insecure Temporary File vulnerability in Altera Quartus Prime Standard  Installer (SFX) on Windows, Altera Quartus Prime Lite  Installer (SFX) on Windows allows Explore for Predictable Temporary File Names.This issue affects Quartus Prime Standard: from 23.1 through 24.1; Quartus Prime Lite: from 23.1 through 24.1.

    Published: 6 Jan 2026
    8.9
    High

    CVE-2025-15471

    Last Modified: 18 Mar 2026

    A vulnerability was detected in TRENDnet TEW-713RE 1.02. The impacted element is an unknown function of the file /goformX/formFSrvX. The manipulation of the argument SZCMD results in os command injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor confirms: "The product in question TEW-731RE for CVE-2025-15471 has been discontinued and end of life since October 23, 2020. We no longer provide support for this product, so we are not able to confirm the vulnerabilities. We will make an announcement on the website product support page and notify customers who registered their products with us." This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 6 Jan 2026
    5.4
    Medium

    CVE-2025-14599

    Last Modified: 12 Jan 2026

    Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard Installer (SFX) on Windows, Altera Quartus Prime Lite  Installer (SFX) on Windows allows Search Order Hijacking.This issue affects Quartus Prime Standard: from 23.1 through 24.1; Quartus Prime Lite: from 23.1 through 24.1.

    Published: 6 Jan 2026
    5.4
    Medium

    CVE-2025-14612

    Last Modified: 12 Jan 2026

    Insecure Temporary File vulnerability in Altera Quartus Prime Pro  Installer (SFX) on Windows allows : Use of Predictable File Names.This issue affects Quartus Prime Pro: from 24.1 through 25.1.1.

    Published: 6 Jan 2026
    5.4
    Medium

    CVE-2025-14605

    Last Modified: 12 Jan 2026

    Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro on Windows (System Console modules) allows Search Order Hijacking.This issue affects Quartus Prime Pro: from 17.0 through 25.1.1.

    Published: 6 Jan 2026
    7.1
    High

    CVE-2025-31642

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dasinfomedia WPCHURCH allows Reflected XSS.This issue affects WPCHURCH: from n/a through 2.7.0.

    Published: 6 Jan 2026
    5.3
    Medium

    CVE-2025-31051

    Last Modified: 28 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EngoTheme Plant - Gardening & Houseplants WordPress Theme allows Retrieve Embedded Sensitive Data.This issue affects Plant - Gardening & Houseplants WordPress Theme: from n/a through 1.0.0.

    Published: 6 Jan 2026
    5.4
    Medium

    CVE-2025-14596

    Last Modified: 12 Jan 2026

    Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro Installer (SFX) on Windows allows Search Order Hijacking.This issue affects Quartus Prime Pro: from 24.1 through 24.3.1.

    Published: 6 Jan 2026
    9.9
    Critical

    CVE-2025-30996

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Sidepane WordPress Theme, Themify Themify Newsy, Themify Themify Folo, Themify Themify Edmin, Themify Bloggie, Themify Photobox, Themify Wigi, Themify Rezo, Themify Slide allows Upload a Web Shell to a Web Server.This issue affects Themify Sidepane WordPress Theme: from n/a through 1.9.8; Themify Newsy: from n/a through 1.9.9; Themify Folo: from n/a through 1.9.6; Themify Edmin: from n/a through 2.0.0; Bloggie: from n/a through 2.0.8; Photobox: from n/a through 2.0.1; Wigi: from n/a through 2.0.1; Rezo: from n/a through 1.9.7; Slide: from n/a through 1.7.5.

    Published: 6 Jan 2026
    8.4
    High

    CVE-2025-13744

    Last Modified: 30 Jan 2026

    An Improper Neutralization of Input During Web Page Generation vulnerability was identified in GitHub Enterprise Server that allowed attacker controlled HTML to be rendered by the Filter component (search) across GitHub that could be used to exfiltrate sensitive information. An attacker would require permissions to create or modify the names of milestones, issues, pull requests, or similar entities that are rendered in the vulnerable filter/search components. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.20 and was fixed in versions 3.19.1, and 3.18.2, 3.17.8, 3.16.11, 3.15.15, and 3.14.20. This vulnerability was reported via the GitHub Bug Bounty program.

    Published: 6 Jan 2026
    7.1
    High

    CVE-2025-30631

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA-Team Woocommerce Sales Funnel Builder, AA-Team Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer) allows Reflected XSS.This issue affects Woocommerce Sales Funnel Builder: from n/a through 1.1; Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer): from n/a through 1.2.

    Published: 6 Jan 2026
    8.8
    High

    CVE-2025-29004

    Last Modified: 28 Apr 2026

    Incorrect Privilege Assignment vulnerability in AA-Team Premium Age Verification / Restriction for WordPress, AA-Team Responsive Coming Soon Landing Page / Holding Page for WordPress allows Privilege Escalation.This issue affects Premium Age Verification / Restriction for WordPress: from n/a through 3.0.2; Responsive Coming Soon Landing Page / Holding Page for WordPress: from n/a through 3.0.

    Published: 6 Jan 2026
    5.5
    Medium

    CVE-2026-21492

    Last Modified: 18 Apr 2026

    iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a NULL pointer member call vulnerability. This vulnerability affects users of the iccDEV library who process ICC color profiles. Version 2.3.1.2 contains a patch. No known workarounds are available.

    Published: 6 Jan 2026
    5.3
    Medium

    CVE-2025-7048

    Last Modified: 15 Apr 2026

    On affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can cause the MACsec process to terminate unexpectedly. Continuous receipt of these packets with certain MACsec configurations can cause longer term disruption of dataplane traffic.

    Published: 6 Jan 2026
    6.1
    Medium

    CVE-2026-21491

    Last Modified: 18 Apr 2026

    iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. A vulnerability present in versions prior to 2.3.1.2 affects users of the iccDEV library who process ICC color profiles. It results in unicode buffer overflow in `CIccTagTextDescription`. Version 2.3.1.2 contains a patch. No known workarounds are available.

    Published: 6 Jan 2026
    6.1
    Medium

    CVE-2026-21490

    Last Modified: 18 Apr 2026

    iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. A vulnerability present in versions prior to 2.3.1.2 affects users of the iccDEV library who process ICC color profiles. It results in heap buffer overflow in `CIccTagLut16::Validate()`. Version 2.3.1.2 contains a patch. No known workarounds are available.

    Published: 6 Jan 2026
    2.1
    Low

    CVE-2026-0641

    Last Modified: 18 Apr 2026

    A security vulnerability has been detected in TOTOLINK WA300 5.2cu.7112_B20190227. This vulnerability affects the function sub_401510 of the file cstecgi.cgi. The manipulation of the argument UPLOAD_FILENAME leads to command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

    Published: 6 Jan 2026
    6.1
    Medium

    CVE-2026-21494

    Last Modified: 18 Apr 2026

    iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. A vulnerability present in versions prior to 2.3.1.2 affects users of the iccDEV library who process ICC color profiles. It results in heap buffer overflow in `CIccTagLut8::Validate()`. Version 2.3.1.2 contains a patch. No known workarounds are available.

    Published: 6 Jan 2026
    5.1
    Medium

    CVE-2025-15382

    Last Modified: 12 Jan 2026

    A heap buffer over-read vulnerability exists in the wolfSSH_CleanPath() function in wolfSSH. An authenticated remote attacker can trigger the issue via crafted SCP path input containing '/./' sequences, resulting in a heap over read by 1 byte.

    Published: 6 Jan 2026
    8.1
    High

    CVE-2025-32304

    Last Modified: 28 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mojoomla WPCHURCH allows PHP Local File Inclusion.This issue affects WPCHURCH: from n/a through 2.7.0.

    Published: 6 Jan 2026
    9.4
    Critical

    CVE-2025-14942

    Last Modified: 12 Jan 2026

    wolfSSH’s key exchange state machine can be manipulated to leak the client’s password in the clear, trick the client to send a bogus signature, or trick the client into skipping user authentication. This affects client applications with wolfSSH version 1.4.21 and earlier. Users of wolfSSH must update or apply the fix patch and it’s recommended to update credentials used. This fix is also recommended for wolfSSH server applications. While there aren’t any specific attacks on server applications, the same defect is present. Thanks to Aina Toky Rasoamanana of Valeo and Olivier Levillain of Telecom SudParis for the report.

    Published: 6 Jan 2026
    9.8
    Critical

    CVE-2025-39477

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Sfwebservice InWave Jobs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects InWave Jobs: from n/a through 3.5.8.

    Published: 6 Jan 2026
    6.5
    Medium

    CVE-2024-31088

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPShop.Ru AdsPlace'r – Ad Manager, Inserter, AdSense Ads allows DOM-Based XSS.This issue affects AdsPlace'r – Ad Manager, Inserter, AdSense Ads: from n/a through 1.1.5.

    Published: 6 Jan 2026
    7.1
    High

    CVE-2024-30547

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Shazdeh Header Image Slider header-image-slider allows DOM-Based XSS.This issue affects Header Image Slider: from n/a through 0.3.

    Published: 6 Jan 2026
    8.8
    High

    CVE-2025-47553

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This issue affects DZS Video Gallery: from n/a through 12.25.

    Published: 6 Jan 2026
    8.1
    High

    CVE-2025-69083

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Frappé frappe allows PHP Local File Inclusion.This issue affects Frappé: from n/a through <= 1.8.

    Published: 6 Jan 2026
    5.3
    Medium

    CVE-2025-69364

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in Cloudways Breeze breeze allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Breeze: from n/a through <= 2.2.21.

    Published: 6 Jan 2026
    6.5
    Medium

    CVE-2025-69363

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in CyberChimps Responsive Addons for Elementor responsive-addons-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Responsive Addons for Elementor: from n/a through <= 2.0.8.

    Published: 6 Jan 2026
    5.9
    Medium

    CVE-2025-69362

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH UiChemy uichemy allows Stored XSS.This issue affects UiChemy: from n/a through <= 4.4.2.

    Published: 6 Jan 2026
    4.3
    Medium

    CVE-2025-69361

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in PublishPress Post Expirator post-expirator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Expirator: from n/a through <= 4.9.3.

    Published: 6 Jan 2026