CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2025-11837

    Last Modified: 22 Jan 2026

    An improper control of generation of code vulnerability has been reported to affect Malware Remover. The remote attackers can then exploit the vulnerability to bypass protection mechanism. We have already fixed the vulnerability in the following version: Malware Remover 6.6.8.20251023 and later

    Published: 2 Jan 2026
    4.3
    Medium

    CVE-2025-69284

    Last Modified: 25 Feb 2026

    Plane is an an open-source project management tool. In plane.io, a guest user doesn't have a permission to access https[:]//app[.]plane[.]so/[:]slug/settings. Prior to Plane version 1.2.0, a problem occurs when the `/api/workspaces/:slug/members/` is accessible by guest and able to list of users on a specific workspace that they joined. Since the `display_name` in the response is actually the handler of the email, a malicious guest can still identify admin users' email addresses. Version 1.2.0 fixes this issue.

    Published: 2 Jan 2026
    1.2
    Low

    CVE-2025-62852

    Last Modified: 6 Jan 2026

    A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: QTS 5.2.8.3332 build 20251128 and later

    Published: 2 Jan 2026
    8.1
    High

    CVE-2025-59387

    Last Modified: 15 Apr 2026

    An SQL injection vulnerability has been reported to affect MARS (Multi-Application Recovery Service). The remote attackers can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: MARS (Multi-Application Recovery Service) 1.2.1.1686 and later

    Published: 2 Jan 2026
    8.1
    High

    CVE-2025-59384

    Last Modified: 22 Jan 2026

    A path traversal vulnerability has been reported to affect Qfiling. The remote attackers can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qfiling 3.13.1 and later

    Published: 2 Jan 2026
    6.9
    Medium

    CVE-2025-59381

    Last Modified: 9 Jun 2026

    A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: QTS 5.2.8.3332 build 20251128 and later QuTS hero h5.2.8.3321 build 20251117 and later QuTS hero h5.3.2.3354 build 20251225 and later

    Published: 2 Jan 2026
    4.6
    Medium

    CVE-2025-59380

    Last Modified: 6 Jan 2026

    A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: QTS 5.2.8.3332 build 20251128 and later QuTS hero h5.2.8.3321 build 20251117 and later

    Published: 2 Jan 2026
    1.2
    Low

    CVE-2025-53597

    Last Modified: 5 Jan 2026

    A buffer overflow vulnerability has been reported to affect License Center. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: License Center 2.0.36 and later

    Published: 2 Jan 2026
    4.4
    Medium

    CVE-2025-53594

    Last Modified: 15 Apr 2026

    A path traversal vulnerability has been reported to affect several product versions. If a local attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: Qfinder Pro Mac 7.13.0 and later Qsync for Mac 5.1.5 and later QVPN Device Client for Mac 2.2.8 and later

    Published: 2 Jan 2026
    1.3
    Low

    CVE-2025-52871

    Last Modified: 5 Jan 2026

    An out-of-bounds read vulnerability has been reported to affect License Center. If a remote attacker gains a user account, they can then exploit the vulnerability to obtain secret data. We have already fixed the vulnerability in the following version: License Center 2.0.36 and later

    Published: 2 Jan 2026
    1.2
    Low

    CVE-2025-48721

    Last Modified: 6 Jan 2026

    A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: QTS 5.2.8.3332 build 20251128 and later

    Published: 2 Jan 2026
    2.7
    Low

    CVE-2025-9110

    Last Modified: 6 Jan 2026

    An exposure of sensitive system information to an unauthorized control sphere vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to read application data. We have already fixed the vulnerability in the following versions: QTS 5.2.8.3332 build 20251128 and later QuTS hero h5.2.8.3321 build 20251117 and later QuTS hero h5.3.1.3250 build 20250912 and later

    Published: 2 Jan 2026
    4.6
    Medium

    CVE-2025-57705

    Last Modified: 5 Jan 2026

    An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.1.3250 build 20250912 and later

    Published: 2 Jan 2026
    4.6
    Medium

    CVE-2025-54166

    Last Modified: 5 Jan 2026

    An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.1.3250 build 20250912 and later

    Published: 2 Jan 2026
    4.6
    Medium

    CVE-2025-54165

    Last Modified: 5 Jan 2026

    An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.1.3250 build 20250912 and later

    Published: 2 Jan 2026
    4.6
    Medium

    CVE-2025-54164

    Last Modified: 5 Jan 2026

    An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.1.3250 build 20250912 and later

    Published: 2 Jan 2026
    1.2
    Low

    CVE-2025-53596

    Last Modified: 5 Jan 2026

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.1.3250 build 20250912 and later

    Published: 2 Jan 2026
    1.2
    Low

    CVE-2025-53593

    Last Modified: 5 Jan 2026

    A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.1.3250 build 20250912 and later

    Published: 2 Jan 2026
    1.3
    Low

    CVE-2025-53592

    Last Modified: 5 Jan 2026

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.1.3250 build 20250912 and later

    Published: 2 Jan 2026
    1.2
    Low

    CVE-2025-53591

    Last Modified: 5 Jan 2026

    A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data or modify memory. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.1.3250 build 20250912 and later

    Published: 2 Jan 2026
    1.2
    Low

    CVE-2025-53590

    Last Modified: 5 Jan 2026

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250913 and later

    Published: 2 Jan 2026
    1.2
    Low

    CVE-2025-53589

    Last Modified: 5 Jan 2026

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.1.3250 build 20250912 and later

    Published: 2 Jan 2026
    1.2
    Low

    CVE-2025-53414

    Last Modified: 5 Jan 2026

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.1.3250 build 20250912 and later

    Published: 2 Jan 2026
    1.2
    Low

    CVE-2025-53405

    Last Modified: 5 Jan 2026

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.1.3250 build 20250912 and later

    Published: 2 Jan 2026
    1.3
    Low

    CVE-2025-52872

    Last Modified: 5 Jan 2026

    A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.0.3192 build 20250716 and later

    Published: 2 Jan 2026
    1.3
    Low

    CVE-2025-52864

    Last Modified: 5 Jan 2026

    A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.0.3192 build 20250716 and later

    Published: 2 Jan 2026
    1.3
    Low

    CVE-2025-52863

    Last Modified: 5 Jan 2026

    A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.0.3192 build 20250716 and later

    Published: 2 Jan 2026
    1.2
    Low

    CVE-2025-52431

    Last Modified: 5 Jan 2026

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.1.3250 build 20250912 and later

    Published: 2 Jan 2026
    1.2
    Low

    CVE-2025-52430

    Last Modified: 5 Jan 2026

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.1.3250 build 20250912 and later

    Published: 2 Jan 2026
    1.2
    Low

    CVE-2025-52426

    Last Modified: 5 Jan 2026

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.1.3250 build 20250912 and later

    Published: 2 Jan 2026
    4.9
    Medium

    CVE-2025-47208

    Last Modified: 5 Jan 2026

    An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and later QuTS hero h5.2.6.3195 build 20250715 and later

    Published: 2 Jan 2026
    1.3
    Low

    CVE-2025-44013

    Last Modified: 5 Jan 2026

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and later QuTS hero h5.2.6.3195 build 20250715 and later

    Published: 2 Jan 2026
    2.2
    Low

    CVE-2025-62857

    Last Modified: 5 Jan 2026

    A cross-site scripting (XSS) vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following version: QuMagie 2.8.1 and later

    Published: 2 Jan 2026
    2
    Low

    CVE-2025-15438

    Last Modified: 27 Feb 2026

    A vulnerability was determined in PluXml up to 5.8.22. Affected is the function FileCookieJar::__destruct of the file core/admin/medias.php of the component Media Management Module. Executing a manipulation of the argument File can lead to deserialization. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was informed early about this issue and announced that "[w]e fix this issue in the next version 5.8.23". A patch for it is ready.

    Published: 2 Jan 2026
    5.5
    Medium

    CVE-2026-0565

    Last Modified: 18 Apr 2026

    A weakness has been identified in code-projects Content Management System 1.0. This issue affects some unknown processing of the file /admin/delete.php. Executing a manipulation of the argument del can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.

    Published: 2 Jan 2026
    2.1
    Low

    CVE-2026-0547

    Last Modified: 18 Apr 2026

    A vulnerability was found in PHPGurukul Online Course Registration up to 3.1. This issue affects some unknown processing of the file /admin/edit-student-profile.php of the component Student Registration Page. The manipulation of the argument photo results in unrestricted upload. The attack may be launched remotely. The exploit has been made public and could be used.

    Published: 2 Jan 2026
    5.5
    Medium

    CVE-2026-0546

    Last Modified: 18 Apr 2026

    A vulnerability was determined in code-projects Content Management System 1.0. This impacts an unknown function of the file search.php. This manipulation of the argument Value causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

    Published: 2 Jan 2026
    Unknown

    CVE-2026-21645

    Last Modified: 3 Jan 2026

    Not used

    Published: 2 Jan 2026
    Unknown

    CVE-2026-21646

    Last Modified: 3 Jan 2026

    Not used

    Published: 2 Jan 2026
    Unknown

    CVE-2026-21647

    Last Modified: 3 Jan 2026

    Not used

    Published: 2 Jan 2026
    Unknown

    CVE-2026-21648

    Last Modified: 3 Jan 2026

    Not used

    Published: 2 Jan 2026
    Unknown

    CVE-2026-21649

    Last Modified: 3 Jan 2026

    Not used

    Published: 2 Jan 2026
    Unknown

    CVE-2026-21650

    Last Modified: 3 Jan 2026

    Not used

    Published: 2 Jan 2026
    Unknown

    CVE-2026-21651

    Last Modified: 3 Jan 2026

    Not used

    Published: 2 Jan 2026
    Unknown

    CVE-2026-21652

    Last Modified: 3 Jan 2026

    Not used

    Published: 2 Jan 2026
    Unknown

    CVE-2026-21644

    Last Modified: 3 Jan 2026

    Not used

    Published: 2 Jan 2026
    2
    Low

    CVE-2025-15437

    Last Modified: 27 Feb 2026

    A vulnerability was found in LigeroSmart up to 6.1.24. This affects an unknown part of the component Environment Variable Handler. Performing a manipulation of the argument REQUEST_URI results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be used. Upgrading to version 6.1.26 and 6.3 is able to mitigate this issue. The patch is named 264ac5b2be5b3c673ebd8cb862e673f5d300d9a7. The affected component should be upgraded.

    Published: 2 Jan 2026
    5.5
    Medium

    CVE-2025-15436

    Last Modified: 23 Feb 2026

    A vulnerability has been found in Yonyou KSOA 9.0. Affected by this issue is some unknown functionality of the file /worksheet/work_edit.jsp. Such manipulation of the argument Report leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 2 Jan 2026
    5.5
    Medium

    CVE-2025-15435

    Last Modified: 23 Feb 2026

    A flaw has been found in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /worksheet/work_update.jsp. This manipulation of the argument Report causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 2 Jan 2026
    5.5
    Medium

    CVE-2025-15434

    Last Modified: 23 Feb 2026

    A vulnerability was detected in Yonyou KSOA 9.0. Affected is an unknown function of the file /kp/PrintZPYG.jsp. The manipulation of the argument zpjhid results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 2 Jan 2026