CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2025-69360

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for WPBakery) thegem-elements allows DOM-Based XSS.This issue affects TheGem Theme Elements (for WPBakery): from n/a through <= 5.11.0.

    Published: 6 Jan 2026
    5.3
    Medium

    CVE-2025-69359

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in WPFunnels Creator LMS creatorlms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Creator LMS: from n/a through <= 1.1.12.

    Published: 6 Jan 2026
    6.5
    Medium

    CVE-2025-69357

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor allows Stored XSS.This issue affects TheGem Theme Elements (for Elementor): from n/a through <= 5.11.0.

    Published: 6 Jan 2026
    7.5
    High

    CVE-2025-69356

    Last Modified: 15 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor allows PHP Local File Inclusion.This issue affects TheGem Theme Elements (for Elementor): from n/a through <= 5.11.0.

    Published: 6 Jan 2026
    4.3
    Medium

    CVE-2025-69355

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in Tickera Tickera tickera-event-ticketing-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tickera: from n/a through <= 3.5.6.4.

    Published: 6 Jan 2026
    4.3
    Medium

    CVE-2025-69354

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in BBR Plugins Better Business Reviews better-business-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Better Business Reviews: from n/a through <= 0.1.1.

    Published: 6 Jan 2026
    4.3
    Medium

    CVE-2025-69353

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Proxy & VPN Blocker Proxy & VPN Blocker proxy-vpn-blocker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Proxy & VPN Blocker: from n/a through <= 3.5.3.

    Published: 6 Jan 2026
    5.4
    Medium

    CVE-2025-69352

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in StellarWP The Events Calendar the-events-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar: from n/a through <= 6.15.12.2.

    Published: 6 Jan 2026
    8.5
    High

    CVE-2025-69351

    Last Modified: 24 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Ninja Tables ninja-tables allows Blind SQL Injection.This issue affects Ninja Tables: from n/a through <= 5.2.4.

    Published: 6 Jan 2026
    5.9
    Medium

    CVE-2025-69350

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Accordion accordions-wp allows Stored XSS.This issue affects Accordion: from n/a through <= 3.0.3.

    Published: 6 Jan 2026
    5.4
    Medium

    CVE-2025-69349

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in Fahad Mahmood RSS Feed Widget rss-feed-widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RSS Feed Widget: from n/a through <= 3.0.2.

    Published: 6 Jan 2026
    4.3
    Medium

    CVE-2025-69348

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in CoolHappy The Events Calendar Countdown Addon countdown-for-the-events-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar Countdown Addon: from n/a through <= 1.4.15.

    Published: 6 Jan 2026
    4.3
    Medium

    CVE-2025-69346

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in WPCenter AffiliateX affiliatex allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AffiliateX: from n/a through <= 1.3.9.3.

    Published: 6 Jan 2026
    4.3
    Medium

    CVE-2025-69345

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in BoldGrid Post and Page Builder by BoldGrid post-and-page-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post and Page Builder by BoldGrid: from n/a through <= 1.27.9.

    Published: 6 Jan 2026
    7.5
    High

    CVE-2025-69342

    Last Modified: 15 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in VanKarWai Calafate calafate allows PHP Local File Inclusion.This issue affects Calafate: from n/a through <= 1.7.7.

    Published: 6 Jan 2026
    5.4
    Medium

    CVE-2025-69341

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in BuddhaThemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WeDesignTech Ultimate Booking Addon: from n/a through <= 1.0.3.

    Published: 6 Jan 2026
    4.3
    Medium

    CVE-2025-69336

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in bdthemes Ultimate Store Kit Elementor Addons ultimate-store-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Store Kit Elementor Addons: from n/a through <= 2.9.4.

    Published: 6 Jan 2026
    6.5
    Medium

    CVE-2025-69335

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Team Showcase team-showcase allows Stored XSS.This issue affects Team Showcase: from n/a through <= 2.9.

    Published: 6 Jan 2026
    6.5
    Medium

    CVE-2025-69334

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Wishlist for WooCommerce wish-list-for-woocommerce allows Stored XSS.This issue affects Wishlist for WooCommerce: from n/a through <= 3.3.0.

    Published: 6 Jan 2026
    4.3
    Medium

    CVE-2025-69331

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Jeroen Schmit Theater for WordPress theatre allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Theater for WordPress: from n/a through <= 0.19.

    Published: 6 Jan 2026
    4.3
    Medium

    CVE-2025-69327

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Car Rental Manager: from n/a through <= 1.0.9.

    Published: 6 Jan 2026
    7.1
    High

    CVE-2025-69084

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gt3themes Photo Gallery gt3-photo-video-gallery allows Reflected XSS.This issue affects Photo Gallery: from n/a through <= 2.7.7.26.

    Published: 6 Jan 2026
    7.1
    High

    CVE-2025-69085

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins JobBank jobbank allows Reflected XSS.This issue affects JobBank: from n/a through <= 1.2.2.

    Published: 6 Jan 2026
    8.1
    High

    CVE-2025-69086

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes Issabella issabella allows PHP Local File Inclusion.This issue affects Issabella: from n/a through <= 1.1.2.

    Published: 6 Jan 2026
    7.6
    High

    CVE-2025-36589

    Last Modified: 22 Jan 2026

    Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to data and resources outside of the intended sphere of control.

    Published: 6 Jan 2026
    5.9
    Medium

    CVE-2025-63082

    Last Modified: 30 Jan 2026

    Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags.

    Published: 6 Jan 2026
    5.9
    Medium

    CVE-2025-63083

    Last Modified: 30 Jan 2026

    Lack of output escaping leads to a XSS vector in the pagebreak plugin.

    Published: 6 Jan 2026
    8.6
    High

    CVE-2020-36917

    Last Modified: 15 Apr 2026

    iDS6 DSSPro Digital Signage System 6.2 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept authentication credentials through cleartext cookie transmission. Attackers can exploit the autoSave feature to capture user passwords during man-in-the-middle attacks on HTTP communications.

    Published: 6 Jan 2026
    8.6
    High

    CVE-2020-36914

    Last Modified: 15 Apr 2026

    QiHang Media Web Digital Signage 3.0.9 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept user authentication credentials through cleartext cookie transmission. Attackers can perform man-in-the-middle attacks to capture and potentially misuse stored authentication credentials transmitted in an insecure manner.

    Published: 6 Jan 2026
    8.7
    High

    CVE-2020-36925

    Last Modified: 15 Apr 2026

    Arteco Web Client DVR/NVR contains a session hijacking vulnerability with insufficient session ID complexity that allows remote attackers to bypass authentication. Attackers can brute force session IDs within a specific numeric range to obtain valid sessions and access live camera streams without authorization.

    Published: 6 Jan 2026
    5.3
    Medium

    CVE-2020-36924

    Last Modified: 26 Jan 2026

    Sony BRAVIA Digital Signage 1.7.8 contains a remote file inclusion vulnerability that allows attackers to inject arbitrary client-side scripts through the content material URL parameter. Attackers can exploit this vulnerability to hijack user sessions, execute cross-site scripting code, and modify display content by manipulating the input material type.

    Published: 6 Jan 2026
    6.9
    Medium

    CVE-2020-36923

    Last Modified: 22 Jan 2026

    Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization controls. Attackers can access hidden system resources like '/#/content-creation' by manipulating client-side access restrictions.

    Published: 6 Jan 2026
    6.9
    Medium

    CVE-2020-36922

    Last Modified: 22 Jan 2026

    Sony BRAVIA Digital Signage 1.7.8 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive system details through API endpoints. Attackers can retrieve network interface information, server configurations, and system metadata by sending requests to the exposed system API.

    Published: 6 Jan 2026
    6.9
    Medium

    CVE-2020-36921

    Last Modified: 15 Apr 2026

    RED-V Super Digital Signage System 5.1.1 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive webserver log files. Attackers can visit multiple endpoints to retrieve system resources and debug log information without authentication.

    Published: 6 Jan 2026
    8.7
    High

    CVE-2020-36920

    Last Modified: 15 Apr 2026

    iDS6 DSSPro Digital Signage System 6.2 contains an improper access control vulnerability that allows authenticated users to elevate privileges through console JavaScript functions. Attackers can create users, modify roles and permissions, and potentially achieve full application takeover by exploiting insecure direct object references.

    Published: 6 Jan 2026
    5.1
    Medium

    CVE-2020-36918

    Last Modified: 15 Apr 2026

    iDS6 DSSPro Digital Signage System 6.2 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without request validation. Attackers can craft malicious web pages to trick logged-in administrators into adding unauthorized users by exploiting the lack of CSRF protections.

    Published: 6 Jan 2026
    8.5
    High

    CVE-2020-36916

    Last Modified: 15 Apr 2026

    TDM Digital Signage PC Player 4.1.0.4 contains an elevation of privileges vulnerability that allows authenticated users to modify executable files. Attackers can leverage the 'Modify' permissions for authenticated users to replace executable files with malicious binaries and gain elevated system access.

    Published: 6 Jan 2026
    8.7
    High

    CVE-2020-36915

    Last Modified: 15 Apr 2026

    Adtec Digital SignEdje Digital Signage Player v2.08.28 contains multiple hardcoded default credentials that allow unauthenticated remote access to web, telnet, and SSH interfaces. Attackers can exploit these credentials to gain root-level access and execute system commands across multiple Adtec Digital product versions.

    Published: 6 Jan 2026
    8.5
    High

    CVE-2020-36913

    Last Modified: 15 Apr 2026

    All-Dynamics Software enlogic:show 2.0.2 contains a session fixation vulnerability that allows attackers to set a predefined PHP session identifier during the login process. Attackers can forge HTTP GET requests to welcome.php with a manipulated session token to bypass authentication and potentially execute cross-site request forgery attacks.

    Published: 6 Jan 2026
    5.1
    Medium

    CVE-2020-36912

    Last Modified: 15 Apr 2026

    Plexus anblick Digital Signage Management 3.1.13 contains an open redirect vulnerability in the 'PantallaLogin' script that allows attackers to manipulate the 'pagina' GET parameter. Attackers can craft malicious links that redirect users to arbitrary websites by exploiting improper input validation in the parameter.

    Published: 6 Jan 2026
    8.7
    High

    CVE-2020-36910

    Last Modified: 15 Jul 2026

    Cayin Signage Media Player 3.0 contains an authenticated remote command injection vulnerability in system.cgi and wizard_system.cgi pages. Attackers can exploit the 'NTP_Server_IP' parameter with default credentials to execute arbitrary shell commands as root.

    Published: 6 Jan 2026
    8.7
    High

    CVE-2020-36909

    Last Modified: 15 Jul 2026

    SnapGear Management Console SG560 3.1.5 contains a file manipulation vulnerability that allows authenticated users to read, write, and delete files using the edit_config_files CGI script. Attackers can manipulate POST request parameters in /cgi-bin/cgix/edit_config_files to access and modify files outside the intended /etc/config/ directory.

    Published: 6 Jan 2026
    5.1
    Medium

    CVE-2020-36908

    Last Modified: 15 Jul 2026

    SnapGear Management Console SG560 version 3.1.5 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft a malicious web page that automatically submits a form to create a new super user account with full administrative privileges when a logged-in user visits the page.

    Published: 6 Jan 2026
    8.7
    High

    CVE-2020-36907

    Last Modified: 15 Apr 2026

    Aerohive HiveOS contains a denial of service vulnerability in the NetConfig UI that allows unauthenticated attackers to render the web interface unusable. Attackers can send a crafted HTTP request to the action.php5 script with specific parameters to trigger a 5-minute service disruption.

    Published: 6 Jan 2026
    5.3
    Medium

    CVE-2020-36906

    Last Modified: 15 Apr 2026

    P5 FNIP-8x16A FNIP-4xSH 1.0.20 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to add new admin users, change passwords, and modify system configurations by tricking authenticated users into loading a specially crafted form.

    Published: 6 Jan 2026
    5.1
    Medium

    CVE-2020-36905

    Last Modified: 15 Apr 2026

    FIBARO System Home Center 5.021 contains a remote file inclusion vulnerability in the undocumented proxy API that allows attackers to include arbitrary client-side scripts. Attackers can exploit the 'url' GET parameter to inject malicious JavaScript and potentially hijack user sessions or manipulate page content.

    Published: 6 Jan 2026
    7.4
    High

    CVE-2026-0640

    Last Modified: 18 Apr 2026

    A weakness has been identified in Tenda AC23 16.03.07.52. This affects the function sscanf of the file /goform/PowerSaveSet. Executing a manipulation of the argument Time can lead to buffer overflow. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.

    Published: 6 Jan 2026
    8.5
    High

    CVE-2025-14979

    Last Modified: 9 Apr 2026

    AirVPN Eddie on MacOS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root.This issue affects Eddie: 2.24.6.

    Published: 6 Jan 2026
    Unknown

    CVE-2026-22162

    Last Modified: 7 Jan 2026

    Not used

    Published: 6 Jan 2026
    Unknown

    CVE-2026-22160

    Last Modified: 7 Jan 2026

    Not used

    Published: 6 Jan 2026