CVE-2025-7195 2026-01-04 00:34:29 UTC | Operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd | MEDIUM 5.2 |
CVE-2025-3660 2026-01-03 23:33:05 UTC | Petlibro Smart Pet Feeder Platform through 1.7.31 Broken Access Control via API endpoint | MEDIUM 6.9 |
CVE-2025-3653 2026-01-03 23:33:04 UTC | Petlibro Smart Pet Feeder through 1.7.31 Platform Improper Access Control via API endpoint | MEDIUM 6.9 |
CVE-2025-3654 2026-01-03 23:33:04 UTC | Petlibro Smart Pet Feeder Platform through 1.7.31 Information Disclosure via API endpoint | MEDIUM 6.9 |
CVE-2025-3646 2026-01-03 23:33:03 UTC | Petlibro Smart Pet Feeder Platform through 1.7.31 Authorization Bypass via Device Share API | MEDIUM 6.9 |
CVE-2025-3652 2026-01-03 23:33:03 UTC | Petlibro Smart Pet Feeder Platform through 1.7.31 Audio Information Disclosure via API endpoint | MEDIUM 6.9 |
CVE-2025-15115 2026-01-03 23:33:02 UTC | Petlibro Smart Pet Feeder Platform through 1.7.31 Authentication Bypass via API endpoint | MEDIUM 6.9 |
CVE-2025-34171 2026-01-03 21:18:51 UTC | CasaOS <= 0.4.15 Unauthenticated File and Debug Data Exposure | MEDIUM 6.9 |
CVE-2025-34449 2026-01-03 20:47:18 UTC | Genymobile/scrcpy <= 3.3.3 Global Buffer Overflow | MEDIUM 6.9 |
CVE-2023-53973 2026-01-03 20:46:28 UTC | Zillya Total Security 3.0.2367.0 Local Privilege Escalation via Quarantine Module | HIGH 8.5 |
CVE-2023-6717 2026-01-03 12:05:05 UTC | Keycloak: xss via assertion consumer service url in saml post-binding flow | MEDIUM 6.0 |
CVE-2024-9355 2026-01-03 11:37:35 UTC | Golang-fips: golang fips zeroed buffer | MEDIUM 6.5 |
CVE-2024-3727 2026-01-03 11:36:20 UTC | Containers/image: digest type does not guarantee valid type | HIGH 8.3 |
CVE-2024-1249 2026-01-03 11:16:41 UTC | Keycloak: org.keycloak.protocol.oidc: unvalidated cross-origin messages in checkloginiframe leads to ddos | HIGH 7.4 |
CVE-2026-21644 2026-01-03 03:55:09 UTC | Not used | |
CVE-2026-21645 2026-01-03 03:55:09 UTC | Not used | |
CVE-2026-21646 2026-01-03 03:55:08 UTC | Not used | |
CVE-2026-21647 2026-01-03 03:55:08 UTC | Not used | |
CVE-2026-21648 2026-01-03 03:55:07 UTC | Not used | |
CVE-2026-21649 2026-01-03 03:55:07 UTC | Not used | |
CVE-2026-21650 2026-01-03 03:55:06 UTC | Not used | |
CVE-2026-21651 2026-01-03 03:55:06 UTC | Not used | |
CVE-2026-21652 2026-01-03 03:55:05 UTC | Not used | |
CVE-2026-21484 2026-01-03 01:21:39 UTC | AnythingLLM Vulnerable to Username Enumeration w/ Password Recovery | MEDIUM 5.3 |
CVE-2025-64124 2026-01-03 00:28:25 UTC | Nuvation Energy Multi-Stack Controller OS Command Injection | HIGH 8.7 |
CVE-2025-64123 2026-01-03 00:25:05 UTC | Nuvation Energy Multi-Stack Controller Proxy service allows arbitrary BMS access | HIGH 7.9 |
CVE-2025-64125 2026-01-03 00:21:20 UTC | Nuvation Energy nCloud Client-to-Client Communication | CRITICAL 9.4 |
CVE-2025-69031 2026-01-02 22:11:34 UTC | WordPress Arcane theme <= 3.6.6 - Broken Access Control vulnerability | MEDIUM 5.3 |
CVE-2025-69030 2026-01-02 22:01:58 UTC | WordPress Backpack Traveler theme <= 2.10.3 - Insecure Direct Object References (IDOR) vulnerability | MEDIUM 5.4 |
CVE-2025-69029 2026-01-02 21:59:12 UTC | WordPress Struktur theme <= 2.5.1 - Insecure Direct Object References (IDOR) vulnerability | MEDIUM 5.4 |
CVE-2024-27480 2026-01-02 21:58:18 UTC | givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload. | CRITICAL 9.8 |
CVE-2024-25182 2026-01-02 21:57:10 UTC | givanz VvvebJs 1.7.2 suffers from a File Upload vulnerability via save.php. | CRITICAL 9.8 |
CVE-2025-69028 2026-01-02 21:55:36 UTC | WordPress weForms plugin <= 1.6.25 - Broken Access Control vulnerability | MEDIUM 5.3 |
CVE-2025-69027 2026-01-02 21:42:44 UTC | WordPress Product Delivery Date for WooCommerce – Lite plugin <= 3.2.0 - Broken Access Control vulnerability | MEDIUM 5.4 |
CVE-2025-64122 2026-01-02 21:39:27 UTC | Nuvation Energy Multi-Stack Controller Private Key Stored on Device | HIGH 7.2 |
CVE-2025-64121 2026-01-02 21:36:25 UTC | Nuvation Energy Multi-Stack Controller Authentication Bypass | CRITICAL 10.0 |
CVE-2025-64120 2026-01-02 21:33:23 UTC | Nuvation Energy Multi-Stack Controller OS Command Injection | CRITICAL 9.4 |
CVE-2026-21447 2026-01-02 21:30:39 UTC | Bagisto has IDOR in Customer Order Reorder Functionality | HIGH 7.1 |
CVE-2026-21448 2026-01-02 21:29:34 UTC | Bagisto has Normal & Blind SSTI from low-privilege user when ordering product | HIGH 8.9 |
CVE-2026-21449 2026-01-02 21:27:39 UTC | Bagisto has SSTI via first and last name from low-privilege user (not admin) | HIGH 7.4 |
CVE-2025-64119 2026-01-02 21:26:57 UTC | Nuvation Energy BMS Client-side Authentication | CRITICAL 9.3 |
CVE-2026-21451 2026-01-02 21:25:52 UTC | Bagisto has HTML Filter Bypass that Enables Stored XSS | MEDIUM 5.2 |
CVE-2025-69026 2026-01-02 21:25:33 UTC | WordPress PopupKit plugin <= 2.1.5 - Sensitive Data Exposure vulnerability | MEDIUM 4.3 |
CVE-2026-21450 2026-01-02 21:24:43 UTC | Bagisto has SSTI in parameter that can lead to RCE | HIGH 7.3 |
CVE-2026-21452 2026-01-02 21:22:02 UTC | MessagePack-Java Vulnerable to Remote Denial of Service via Malicious .msgpack Model File Triggering Unbounded EXT Payload Allocation | HIGH 7.5 |
CVE-2022-50801 2026-01-02 21:21:48 UTC | JM-DATA ONU JF511-TV 1.0.67 Authenticated Stored Cross-Site Scripting (XSS) Vulnerability | MEDIUM 5.1 |
CVE-2026-21483 2026-01-02 21:18:58 UTC | listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover | MEDIUM 5.4 |
CVE-2025-14072 2026-01-02 21:12:38 UTC | Ninja Forms < 3.13.3 - Unauthenticated Token Generation and Submission Disclosure | MEDIUM 5.3 |
CVE-2025-13456 2026-01-02 21:11:51 UTC | Shopbuilder < 3.2.2 - Reflected XSS | MEDIUM 6.1 |
CVE-2025-13153 2026-01-02 21:11:05 UTC | Logo Slider < 4.9.0 - Contributor+ Stored XSS | MEDIUM 6.1 |
CVE-2025-12685 2026-01-02 21:09:51 UTC | WPBookit <= 1.0.7 - Customer Deletion via CSRF | MEDIUM 6.5 |
CVE-2025-69025 2026-01-02 21:09:01 UTC | WordPress Poptics: AI-Powered Popup Builder for Lead Generation, Conversions, Exit-Intent, Email Opt-ins & WooCommerce Sales plugin <= 1.0.20 - Sensitive Data Exposure vulnerability | MEDIUM 4.3 |
CVE-2026-0568 2026-01-02 21:08:04 UTC | code-projects Online Music Site ViewSongs.php sql injection | MEDIUM 6.9 |
CVE-2026-0567 2026-01-02 21:07:05 UTC | code-projects Content Management System pages.php sql injection | MEDIUM 6.9 |
CVE-2026-21429 2026-01-02 21:05:56 UTC | Emlog has Broken Access Control (BAC) | LOW 2.0 |
CVE-2025-15439 2026-01-02 21:05:16 UTC | Daptin Aggregate API resource_aggregate.go goqu.L sql injection | MEDIUM 5.3 |
CVE-2025-69417 2026-01-02 21:04:30 UTC | In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve share tokens (intended for unrelated access) via a shared_servers endpoint. | MEDIUM 5.0 |
CVE-2025-69416 2026-01-02 21:03:42 UTC | In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve other tokens (intended for unrelated access) via clients.plex.tv/devices.xml. | MEDIUM 5.0 |
CVE-2025-69415 2026-01-02 21:02:50 UTC | In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly aligned with whether the device is currently associated with an account. | HIGH 7.1 |
CVE-2025-69414 2026-01-02 21:01:45 UTC | Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient access token. | HIGH 8.5 |
CVE-2026-0566 2026-01-02 21:00:56 UTC | code-projects Content Management System edit_posts.php unrestricted upload | MEDIUM 5.1 |
CVE-2025-15431 2026-01-02 21:00:12 UTC | UTT 进取 512W formFtpServerDirConfig strcpy buffer overflow | HIGH 8.7 |
CVE-2025-15430 2026-01-02 20:59:15 UTC | UTT 进取 512W formFtpServerShareDirSelcet strcpy buffer overflow | HIGH 8.7 |
CVE-2025-15429 2026-01-02 20:58:32 UTC | UTT 进取 512W formConfigCliForEngineerOnly strcpy buffer overflow | HIGH 8.7 |
CVE-2021-47725 2026-01-02 20:57:55 UTC | STVS ProVision 5.9.10 Authenticated Reflected Cross-Site Scripting via Files Parameter | MEDIUM 4.8 |
CVE-2025-69024 2026-01-02 20:49:59 UTC | WordPress BizPrint plugin <= 4.6.7 - Broken Access Control vulnerability | MEDIUM 6.5 |
CVE-2025-69023 2026-01-02 20:47:03 UTC | WordPress Discussion Board plugin <= 2.5.7 - Broken Access Control vulnerability | MEDIUM 4.3 |
CVE-2025-68972 2026-01-02 20:44:27 UTC | In GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an "invalid armor" message is printed during verification). This is related to use of \f as a marker to denote truncation of a long plaintext line. | MEDIUM 5.9 |
CVE-2025-68973 2026-01-02 20:43:58 UTC | In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.) | HIGH 7.8 |
CVE-2021-47740 2026-01-02 20:42:42 UTC | KZTech JT3500V 4G LTE CPE 2.0.1 Insufficient Session Expiration Vulnerability | MEDIUM 6.9 |
CVE-2021-47743 2026-01-02 20:42:10 UTC | COMMAX Biometric Access Control System 1.0.0 Reflected XSS via Cookie Parameters | MEDIUM 5.1 |
CVE-2025-69022 2026-01-02 20:35:51 UTC | WordPress HR Management Lite plugin <= 3.5 - Broken Access Control vulnerability | MEDIUM 5.4 |
CVE-2025-69021 2026-01-02 20:22:35 UTC | WordPress Popup box plugin <= 6.0.7 - Cross Site Request Forgery (CSRF) vulnerability | MEDIUM 5.4 |
CVE-2020-36903 2026-01-02 20:17:19 UTC | Selea CarPlateServer 4.0.1.6 Local Privilege Escalation via Unquoted Service Path | HIGH 8.5 |
CVE-2020-36904 2026-01-02 20:16:15 UTC | Selea CarPlateServer 4.0.1.6 Remote Program Execution via Configuration Endpoint | CRITICAL 9.3 |
CVE-2021-47726 2026-01-02 20:08:08 UTC | NuCom 11N Wireless Router 5.07.90 Privilege Escalation via Configuration Backup | HIGH 8.7 |
CVE-2021-47741 2026-01-02 20:07:00 UTC | ZBL EPON ONU Broadband Router V100R001 Privilege Escalation via Configuration Endpoint | HIGH 8.7 |
CVE-2021-47742 2026-01-02 20:05:26 UTC | Epic Games Psyonix Rocket League <=1.95 Elevation of Privileges via Insecure Permissions | HIGH 8.5 |
CVE-2026-0571 2026-01-02 20:02:06 UTC | yeqifu warehouse AppFileUtils.java createResponseEntity path traversal | MEDIUM 5.3 |
CVE-2022-50787 2026-01-02 19:58:05 UTC | SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Stored Cross-Site Scripting | MEDIUM 5.3 |
CVE-2022-50696 2026-01-02 19:56:13 UTC | SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Hardcoded Credentials Authentication Bypass | CRITICAL 9.3 |
CVE-2022-50695 2026-01-02 19:54:48 UTC | SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x ICMP Flood Attack via Network Commands | HIGH 8.7 |
CVE-2025-55683 2026-01-02 19:53:23 UTC | Windows Kernel Information Disclosure Vulnerability | MEDIUM 5.5 |
CVE-2025-59184 2026-01-02 19:53:23 UTC | Storage Spaces Direct Information Disclosure Vulnerability | MEDIUM 5.5 |
CVE-2025-59501 2026-01-02 19:53:22 UTC | Microsoft Configuration Manager Spoofing Vulnerability | MEDIUM 4.8 |
CVE-2025-60711 2026-01-02 19:53:22 UTC | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | MEDIUM 6.3 |
CVE-2025-59500 2026-01-02 19:53:21 UTC | Azure Notification Service Elevation of Privilege Vulnerability | HIGH 7.7 |
CVE-2025-59503 2026-01-02 19:53:21 UTC | Azure Compute Resource Provider Elevation of Privilege Vulnerability | CRITICAL 10.0 |
CVE-2025-59273 2026-01-02 19:53:20 UTC | Azure Event Grid System Elevation of Privilege Vulnerability | HIGH 7.3 |
CVE-2025-59286 2026-01-02 19:53:19 UTC | Copilot Information Disclosure Vulnerability | CRITICAL 9.3 |
CVE-2025-55321 2026-01-02 19:53:18 UTC | Azure Monitor Log Analytics Spoofing Vulnerability | CRITICAL 9.3 |
CVE-2025-59272 2026-01-02 19:53:18 UTC | Copilot Information Disclosure Vulnerability | CRITICAL 9.3 |
CVE-2025-59271 2026-01-02 19:53:17 UTC | Redis Enterprise Elevation of Privilege Vulnerability | HIGH 8.7 |
CVE-2025-59247 2026-01-02 19:53:16 UTC | Azure PlayFab Elevation of Privilege Vulnerability | HIGH 8.8 |
CVE-2025-59252 2026-01-02 19:53:16 UTC | M365 Copilot Information Disclosure Vulnerability | CRITICAL 9.3 |
CVE-2025-59218 2026-01-02 19:53:15 UTC | Azure Entra ID Elevation of Privilege Vulnerability | CRITICAL 9.6 |
CVE-2025-59246 2026-01-02 19:53:15 UTC | Azure Entra ID Elevation of Privilege Vulnerability | CRITICAL 9.8 |
CVE-2025-59497 2026-01-02 19:53:14 UTC | Microsoft Defender for Linux Denial of Service Vulnerability | HIGH 7.0 |
CVE-2025-59287 2026-01-02 19:53:13 UTC | Windows Server Update Service (WSUS) Remote Code Execution Vulnerability | CRITICAL 9.8 |
CVE-2025-59289 2026-01-02 19:53:13 UTC | Windows Bluetooth Service Elevation of Privilege Vulnerability | HIGH 7.0 |