CVE Feed

    Dashboard / CVE

    8.6
    High

    CVE-2021-47735

    Last Modified: 5 Mar 2026

    CMSimple 5.4 contains an authenticated remote code execution vulnerability that allows logged-in attackers to inject malicious PHP code into template files. Attackers can exploit the template editing functionality by crafting a reverse shell payload and saving it through the template editing endpoint with a valid CSRF token.

    Published: 23 Dec 2025
    8.6
    High

    CVE-2021-47734

    Last Modified: 17 Mar 2026

    CMSimple 5.4 contains an authenticated local file inclusion vulnerability that allows remote attackers to manipulate PHP session files and execute arbitrary code. Attackers can leverage the vulnerability by changing the functions file path and uploading malicious PHP code through session file upload mechanisms.

    Published: 23 Dec 2025
    5.1
    Medium

    CVE-2021-47732

    Last Modified: 7 Apr 2026

    CMSimple 5.2 contains a stored cross-site scripting vulnerability in the Filebrowser External input field that allows attackers to inject malicious JavaScript. Attackers can place unfiltered JavaScript code that executes when users click on Page or Files tabs, enabling persistent script injection.

    Published: 23 Dec 2025
    5.1
    Medium

    CVE-2021-47722

    Last Modified: 15 Apr 2026

    Zucchetti Axess CLOKI Access Control 1.64 contains a cross-site request forgery vulnerability that allows attackers to manipulate access control settings without user interaction. Attackers can craft malicious web pages with hidden forms to disable or modify access control parameters by tricking authenticated users into loading the page.

    Published: 23 Dec 2025
    8.7
    High

    CVE-2021-47721

    Last Modified: 5 Mar 2026

    Orangescrum 1.8.0 contains a privilege escalation vulnerability that allows authenticated users to take over other project-assigned accounts by manipulating session cookies. Attackers can extract the victim's unique ID from the page source and replace their own session cookie to gain unauthorized access to another user's account.

    Published: 23 Dec 2025
    8.7
    High

    CVE-2021-47720

    Last Modified: 7 Apr 2026

    Orangescrum 1.8.0 contains an authenticated SQL injection vulnerability that allows authorized users to manipulate database queries through multiple vulnerable parameters. Attackers can inject malicious SQL code into parameters like old_project_id, project_id, uuid, and uniqid to potentially extract or modify database information.

    Published: 23 Dec 2025
    9.8
    Critical

    CVE-2025-33222

    Last Modified: 15 Jan 2026

    NVIDIA Isaac Launchable contains a vulnerability where an attacker could exploit a hard-coded credential issue. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, and data tampering.

    Published: 23 Dec 2025
    9.8
    Critical

    CVE-2025-33223

    Last Modified: 15 Jan 2026

    NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure and data tampering.

    Published: 23 Dec 2025
    9.8
    Critical

    CVE-2025-33224

    Last Modified: 15 Jan 2026

    NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure and data tampering.

    Published: 23 Dec 2025
    Unknown

    CVE-2025-68693

    Last Modified: 24 Dec 2025

    Not used

    Published: 23 Dec 2025
    Unknown

    CVE-2025-68694

    Last Modified: 24 Dec 2025

    Not used

    Published: 23 Dec 2025
    Unknown

    CVE-2025-68695

    Last Modified: 24 Dec 2025

    Not used

    Published: 23 Dec 2025
    Unknown

    CVE-2025-68691

    Last Modified: 24 Dec 2025

    Not used

    Published: 23 Dec 2025
    Unknown

    CVE-2025-68692

    Last Modified: 24 Dec 2025

    Not used

    Published: 23 Dec 2025
    Unknown

    CVE-2025-68687

    Last Modified: 24 Dec 2025

    Not used

    Published: 23 Dec 2025
    Unknown

    CVE-2025-68688

    Last Modified: 24 Dec 2025

    Not used

    Published: 23 Dec 2025
    Unknown

    CVE-2025-68689

    Last Modified: 24 Dec 2025

    Not used

    Published: 23 Dec 2025
    Unknown

    CVE-2025-68690

    Last Modified: 24 Dec 2025

    Not used

    Published: 23 Dec 2025
    7.5
    High

    CVE-2024-9684

    Last Modified: 15 Apr 2026

    FreyrSCADA/IEC-60870-5-104 server v21.06.008 allows remote attackers to cause a denial of service by sending specific message sequences.

    Published: 23 Dec 2025
    7.3
    High

    CVE-2025-13183

    Last Modified: 4 Jun 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hotech Software Inc. Otello allows Stored XSS. This issue affects Otello: from 2.4.0 before 2.4.4.

    Published: 23 Dec 2025
    7.5
    High

    CVE-2024-24844

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in IdeaBox Creations PowerPack Pro for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PowerPack Pro for Elementor: from n/a through 2.10.6.

    Published: 23 Dec 2025
    5.3
    Medium

    CVE-2023-52210

    Last Modified: 15 Apr 2026

    Vulnerability in Tyche softwares Product Delivery Date for WooCommerce – Lite.This issue affects Product Delivery Date for WooCommerce – Lite: from n/a through 2.7.0.

    Published: 23 Dec 2025
    7.5
    High

    CVE-2025-68546

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Nika nika allows PHP Local File Inclusion.This issue affects Nika: from n/a through <= 1.2.14.

    Published: 23 Dec 2025
    7.5
    High

    CVE-2025-68544

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Diza diza allows PHP Local File Inclusion.This issue affects Diza: from n/a through <= 1.3.15.

    Published: 23 Dec 2025
    6.5
    Medium

    CVE-2025-68548

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebCodingPlace Responsive Posts Carousel Pro responsive-posts-carousel-pro allows Stored XSS.This issue affects Responsive Posts Carousel Pro: from n/a through <= 15.2.

    Published: 23 Dec 2025
    7.6
    High

    CVE-2025-68550

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme WPBulky wpbulky-wp-bulk-edit-post-types allows Blind SQL Injection.This issue affects WPBulky: from n/a through <= 1.1.13.

    Published: 23 Dec 2025
    6.5
    Medium

    CVE-2025-68551

    Last Modified: 23 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vikas Ratudi VPSUForm v-form allows Retrieve Embedded Sensitive Data.This issue affects VPSUForm: from n/a through <= 3.2.24.

    Published: 23 Dec 2025
    5.3
    Medium

    CVE-2025-68556

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HAPPY: from n/a through <= 1.0.9.

    Published: 23 Dec 2025
    4.3
    Medium

    CVE-2025-68557

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Vikas Ratudi Chakra test chakra-test allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chakra test: from n/a through <= 1.0.1.

    Published: 23 Dec 2025
    6.5
    Medium

    CVE-2025-68559

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor.This issue affects TheGem Theme Elements (for Elementor): from n/a through <= 5.10.5.1.

    Published: 23 Dec 2025
    7.5
    High

    CVE-2025-68560

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor.This issue affects TheGem Theme Elements (for Elementor): from n/a through <= 5.10.5.1.

    Published: 23 Dec 2025
    7.6
    High

    CVE-2025-68561

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia AutomatorWP automatorwp allows SQL Injection.This issue affects AutomatorWP: from n/a through <= 5.2.4.

    Published: 23 Dec 2025
    8.8
    High

    CVE-2025-59886

    Last Modified: 18 Feb 2026

    Improper input validation at one of the endpoints of Eaton xComfort ECI's web interface, could lead into an attacker with network access to the device executing privileged user commands. As cybersecurity standards continue to evolve and to meet our requirements today, Eaton has decided to discontinue the product. Upon retirement or end of support, there will be no new security updates, non-security updates, or paid assisted support options, or online technical content updates.

    Published: 23 Dec 2025
    6.4
    Medium

    CVE-2025-14635

    Last Modified: 22 Apr 2026

    The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_page_custom_js' parameter in all versions up to, and including, 3.20.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page, despite the intended role restriction of Custom JS to Administrators.

    Published: 23 Dec 2025
    6.4
    Medium

    CVE-2025-14000

    Last Modified: 22 Apr 2026

    The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'register_form' and 'restrict' shortcodes in all versions up to, and including, 3.2.15 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 23 Dec 2025
    9.8
    Critical

    CVE-2025-14388

    Last Modified: 20 Apr 2026

    The PhastPress plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read via null byte injection in all versions up to, and including, 3.7. This is due to a discrepancy between the extension validation in `getExtensionForURL()` which operates on URL-decoded paths, and `appendNormalized()` which strips everything after a null byte before constructing the filesystem path. This makes it possible for unauthenticated attackers to read arbitrary files from the webroot, including wp-config.php, by appending a double URL-encoded null byte (%2500) followed by an allowed extension (.txt) to the file path.

    Published: 23 Dec 2025
    8.1
    High

    CVE-2025-12934

    Last Modified: 21 Apr 2026

    The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'duplicate_wpml_layout' function in all versions up to, and including, 2.9.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary posts with the content of other existing posts, potentially exposing private and password-protected content and deleting any content that is not saved in revisions or backups. Posts must have been created with Beaver Builder to be copied or updated.

    Published: 23 Dec 2025
    4.3
    Medium

    CVE-2025-14163

    Last Modified: 21 Apr 2026

    The Premium Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.11.53. This is due to missing nonce validation in the 'insert_inner_template' function. This makes it possible for unauthenticated attackers to create arbitrary Elementor templates via a forged request granted they can trick a site administrator or other user with the edit_posts capability into performing an action such as clicking on a link.

    Published: 23 Dec 2025
    6.4
    Medium

    CVE-2025-14548

    Last Modified: 15 Apr 2026

    The Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'event_desc' parameter in all versions up to, and including, 1.3.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page, granted they can convince an administrator to enable lower privilege users to manage calendar events via the plugin settings.

    Published: 23 Dec 2025
    5.3
    Medium

    CVE-2025-14155

    Last Modified: 22 Apr 2026

    The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_template_content' function in all versions up to, and including, 4.11.53. This makes it possible for unauthenticated attackers to view the content of private, draft, and pending templates.

    Published: 23 Dec 2025
    5.5
    Medium

    CVE-2025-15034

    Last Modified: 24 Dec 2025

    A security flaw has been discovered in itsourcecode Student Management System 1.0. This affects an unknown part of the file /record.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be exploited.

    Published: 23 Dec 2025
    6.3
    Medium

    CVE-2025-67743

    Last Modified: 29 Dec 2025

    Local Deep Research is an AI-powered research assistant for deep, iterative research. In versions from 1.3.0 to before 1.3.9, the download service (download_service.py) makes HTTP requests using raw requests.get() without utilizing the application's SSRF protection (safe_requests.py). This can allow attackers to access internal services and attempt to reach cloud provider metadata endpoints (AWS/GCP/Azure), as well as perform internal network reconnaissance, by submitting malicious URLs through the API, depending on the deployment and surrounding controls. This issue has been patched in version 1.3.9.

    Published: 23 Dec 2025
    7.8
    High

    CVE-2025-68340

    Last Modified: 30 Jul 2026

    In the Linux kernel, the following vulnerability has been resolved: team: Move team device type change at the end of team_port_add Attempting to add a port device that is already up will expectedly fail, but not before modifying the team device header_ops. In the case of the syzbot reproducer the gre0 device is already in state UP when it attempts to add it as a port device of team0, this fails but before that header_ops->create of team0 is changed from eth_header to ipgre_header in the call to team_dev_type_check_change. Later when we end up in ipgre_header() struct ip_tunnel* points to nonsense as the private data of the device still holds a struct team. Example sequence of iproute2 commands to reproduce the hang/BUG(): ip link add dev team0 type team ip link add dev gre0 type gre ip link set dev gre0 up ip link set dev gre0 master team0 ip link set dev team0 up ping -I team0 1.1.1.1 Move team_dev_type_check_change down where all other checks have passed as it changes the dev type with no way to restore it in case one of the checks that follow it fail. Also make sure to preserve the origial mtu assignment: - If port_dev is not the same type as dev, dev takes mtu from port_dev - If port_dev is the same type as dev, port_dev takes mtu from dev This is done by adding a conditional before the call to dev_set_mtu to prevent it from assigning port_dev->mtu = dev->mtu and instead letting team_dev_type_check_change assign dev->mtu = port_dev->mtu. The conditional is needed because the patch moves the call to team_dev_type_check_change past dev_set_mtu. Testing: - team device driver in-tree selftests - Add/remove various devices as slaves of team device - syzbot

    Published: 23 Dec 2025
    9.8
    Critical

    CVE-2025-68341

    Last Modified: 30 Jul 2026

    In the Linux kernel, the following vulnerability has been resolved: veth: reduce XDP no_direct return section to fix race As explain in commit fa349e396e48 ("veth: Fix race with AF_XDP exposing old or uninitialized descriptors") for veth there is a chance after napi_complete_done() that another CPU can manage start another NAPI instance running veth_pool(). For NAPI this is correctly handled as the napi_schedule_prep() check will prevent multiple instances from getting scheduled, but for the remaining code in veth_pool() this can run concurrent with the newly started NAPI instance. The problem/race is that xdp_clear_return_frame_no_direct() isn't designed to be nested. Prior to commit 401cb7dae813 ("net: Reference bpf_redirect_info via task_struct on PREEMPT_RT.") the temporary BPF net context bpf_redirect_info was stored per CPU, where this wasn't an issue. Since this commit the BPF context is stored in 'current' task_struct. When running veth in threaded-NAPI mode, then the kthread becomes the storage area. Now a race exists between two concurrent veth_pool() function calls one exiting NAPI and one running new NAPI, both using the same BPF net context. Race is when another CPU gets within the xdp_set_return_frame_no_direct() section before exiting veth_pool() calls the clear-function xdp_clear_return_frame_no_direct().

    Published: 23 Dec 2025
    10
    Critical

    CVE-2024-57521

    Last Modified: 6 Jan 2026

    SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the createTable function in SqlUtil.java.

    Published: 23 Dec 2025
    6.5
    Medium

    CVE-2025-45493

    Last Modified: 5 Jan 2026

    Netgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the iface parameter in the action_bandwidth function.

    Published: 23 Dec 2025
    9.8
    Critical

    CVE-2025-65354

    Last Modified: 6 Jan 2026

    Improper input handling in /Grocery/search_products_itname.php inPuneethReddyHC event-management 1.0 permits SQL injection via the sitem_name POST parameter. Crafted payloads can alter query logic and disclose database contents. Exploitation may result in sensitive data disclosure and backend compromise.

    Published: 23 Dec 2025
    6.2
    Medium

    CVE-2025-65410

    Last Modified: 6 Jan 2026

    A stack overflow in the src/main.c component of GNU Unrtf v0.21.10 allows attackers to cause a Denial of Service (DoS) via injecting a crafted input into the filename parameter.

    Published: 23 Dec 2025
    9.8
    Critical

    CVE-2025-51511

    Last Modified: 6 Jan 2026

    Cadmium CMS v.0.4.9 has a background arbitrary file upload vulnerability in /admin/content/filemanager/uploads.

    Published: 23 Dec 2025
    9.8
    Critical

    CVE-2025-29229

    Last Modified: 6 Jan 2026

    linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus.

    Published: 23 Dec 2025