CVE / JVNDB Latest 100

IDDescriptionSeverity
CVE-2025-7195
2026-01-04 00:34:29 UTC

Operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd

MEDIUM
5.2
CVE-2025-3660
2026-01-03 23:33:05 UTC

Petlibro Smart Pet Feeder Platform through 1.7.31 Broken Access Control via API endpoint

MEDIUM
6.9
CVE-2025-3653
2026-01-03 23:33:04 UTC

Petlibro Smart Pet Feeder through 1.7.31 Platform Improper Access Control via API endpoint

MEDIUM
6.9
CVE-2025-3654
2026-01-03 23:33:04 UTC

Petlibro Smart Pet Feeder Platform through 1.7.31 Information Disclosure via API endpoint

MEDIUM
6.9
CVE-2025-3646
2026-01-03 23:33:03 UTC

Petlibro Smart Pet Feeder Platform through 1.7.31 Authorization Bypass via Device Share API

MEDIUM
6.9
CVE-2025-3652
2026-01-03 23:33:03 UTC

Petlibro Smart Pet Feeder Platform through 1.7.31 Audio Information Disclosure via API endpoint

MEDIUM
6.9
CVE-2025-15115
2026-01-03 23:33:02 UTC

Petlibro Smart Pet Feeder Platform through 1.7.31 Authentication Bypass via API endpoint

MEDIUM
6.9
CVE-2025-34171
2026-01-03 21:18:51 UTC

CasaOS <= 0.4.15 Unauthenticated File and Debug Data Exposure

MEDIUM
6.9
CVE-2025-34449
2026-01-03 20:47:18 UTC

Genymobile/scrcpy <= 3.3.3 Global Buffer Overflow

MEDIUM
6.9
CVE-2023-53973
2026-01-03 20:46:28 UTC

Zillya Total Security 3.0.2367.0 Local Privilege Escalation via Quarantine Module

HIGH
8.5
CVE-2023-6717
2026-01-03 12:05:05 UTC

Keycloak: xss via assertion consumer service url in saml post-binding flow

MEDIUM
6.0
CVE-2024-9355
2026-01-03 11:37:35 UTC

Golang-fips: golang fips zeroed buffer

MEDIUM
6.5
CVE-2024-3727
2026-01-03 11:36:20 UTC

Containers/image: digest type does not guarantee valid type

HIGH
8.3
CVE-2024-1249
2026-01-03 11:16:41 UTC

Keycloak: org.keycloak.protocol.oidc: unvalidated cross-origin messages in checkloginiframe leads to ddos

HIGH
7.4
CVE-2026-21644
2026-01-03 03:55:09 UTC

Not used

CVE-2026-21645
2026-01-03 03:55:09 UTC

Not used

CVE-2026-21646
2026-01-03 03:55:08 UTC

Not used

CVE-2026-21647
2026-01-03 03:55:08 UTC

Not used

CVE-2026-21648
2026-01-03 03:55:07 UTC

Not used

CVE-2026-21649
2026-01-03 03:55:07 UTC

Not used

CVE-2026-21650
2026-01-03 03:55:06 UTC

Not used

CVE-2026-21651
2026-01-03 03:55:06 UTC

Not used

CVE-2026-21652
2026-01-03 03:55:05 UTC

Not used

CVE-2026-21484
2026-01-03 01:21:39 UTC

AnythingLLM Vulnerable to Username Enumeration w/ Password Recovery

MEDIUM
5.3
CVE-2025-64124
2026-01-03 00:28:25 UTC

Nuvation Energy Multi-Stack Controller OS Command Injection

HIGH
8.7
CVE-2025-64123
2026-01-03 00:25:05 UTC

Nuvation Energy Multi-Stack Controller Proxy service allows arbitrary BMS access

HIGH
7.9
CVE-2025-64125
2026-01-03 00:21:20 UTC

Nuvation Energy nCloud Client-to-Client Communication

CRITICAL
9.4
CVE-2025-69031
2026-01-02 22:11:34 UTC

WordPress Arcane theme <= 3.6.6 - Broken Access Control vulnerability

MEDIUM
5.3
CVE-2025-69030
2026-01-02 22:01:58 UTC

WordPress Backpack Traveler theme <= 2.10.3 - Insecure Direct Object References (IDOR) vulnerability

MEDIUM
5.4
CVE-2025-69029
2026-01-02 21:59:12 UTC

WordPress Struktur theme <= 2.5.1 - Insecure Direct Object References (IDOR) vulnerability

MEDIUM
5.4
CVE-2024-27480
2026-01-02 21:58:18 UTC

givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload.

CRITICAL
9.8
CVE-2024-25182
2026-01-02 21:57:10 UTC

givanz VvvebJs 1.7.2 suffers from a File Upload vulnerability via save.php.

CRITICAL
9.8
CVE-2025-69028
2026-01-02 21:55:36 UTC

WordPress weForms plugin <= 1.6.25 - Broken Access Control vulnerability

MEDIUM
5.3
CVE-2025-69027
2026-01-02 21:42:44 UTC

WordPress Product Delivery Date for WooCommerce – Lite plugin <= 3.2.0 - Broken Access Control vulnerability

MEDIUM
5.4
CVE-2025-64122
2026-01-02 21:39:27 UTC

Nuvation Energy Multi-Stack Controller Private Key Stored on Device

HIGH
7.2
CVE-2025-64121
2026-01-02 21:36:25 UTC

Nuvation Energy Multi-Stack Controller Authentication Bypass

CRITICAL
10.0
CVE-2025-64120
2026-01-02 21:33:23 UTC

Nuvation Energy Multi-Stack Controller OS Command Injection

CRITICAL
9.4
CVE-2026-21447
2026-01-02 21:30:39 UTC

Bagisto has IDOR in Customer Order Reorder Functionality

HIGH
7.1
CVE-2026-21448
2026-01-02 21:29:34 UTC

Bagisto has Normal & Blind SSTI from low-privilege user when ordering product

HIGH
8.9
CVE-2026-21449
2026-01-02 21:27:39 UTC

Bagisto has SSTI via first and last name from low-privilege user (not admin)

HIGH
7.4
CVE-2025-64119
2026-01-02 21:26:57 UTC

Nuvation Energy BMS Client-side Authentication

CRITICAL
9.3
CVE-2026-21451
2026-01-02 21:25:52 UTC

Bagisto has HTML Filter Bypass that Enables Stored XSS

MEDIUM
5.2
CVE-2025-69026
2026-01-02 21:25:33 UTC

WordPress PopupKit plugin <= 2.1.5 - Sensitive Data Exposure vulnerability

MEDIUM
4.3
CVE-2026-21450
2026-01-02 21:24:43 UTC

Bagisto has SSTI in parameter that can lead to RCE

HIGH
7.3
CVE-2026-21452
2026-01-02 21:22:02 UTC

MessagePack-Java Vulnerable to Remote Denial of Service via Malicious .msgpack Model File Triggering Unbounded EXT Payload Allocation

HIGH
7.5
CVE-2022-50801
2026-01-02 21:21:48 UTC

JM-DATA ONU JF511-TV 1.0.67 Authenticated Stored Cross-Site Scripting (XSS) Vulnerability

MEDIUM
5.1
CVE-2026-21483
2026-01-02 21:18:58 UTC

listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover

MEDIUM
5.4
CVE-2025-14072
2026-01-02 21:12:38 UTC

Ninja Forms < 3.13.3 - Unauthenticated Token Generation and Submission Disclosure

MEDIUM
5.3
CVE-2025-13456
2026-01-02 21:11:51 UTC

Shopbuilder < 3.2.2 - Reflected XSS

MEDIUM
6.1
CVE-2025-13153
2026-01-02 21:11:05 UTC

Logo Slider < 4.9.0 - Contributor+ Stored XSS

MEDIUM
6.1
CVE-2025-12685
2026-01-02 21:09:51 UTC

WPBookit <= 1.0.7 - Customer Deletion via CSRF

MEDIUM
6.5
CVE-2025-69025
2026-01-02 21:09:01 UTC

WordPress Poptics: AI-Powered Popup Builder for Lead Generation, Conversions, Exit-Intent, Email Opt-ins & WooCommerce Sales plugin <= 1.0.20 - Sensitive Data Exposure vulnerability

MEDIUM
4.3
CVE-2026-0568
2026-01-02 21:08:04 UTC

code-projects Online Music Site ViewSongs.php sql injection

MEDIUM
6.9
CVE-2026-0567
2026-01-02 21:07:05 UTC

code-projects Content Management System pages.php sql injection

MEDIUM
6.9
CVE-2026-21429
2026-01-02 21:05:56 UTC

Emlog has Broken Access Control (BAC)

LOW
2.0
CVE-2025-15439
2026-01-02 21:05:16 UTC

Daptin Aggregate API resource_aggregate.go goqu.L sql injection

MEDIUM
5.3
CVE-2025-69417
2026-01-02 21:04:30 UTC

In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve share tokens (intended for unrelated access) via a shared_servers endpoint.

MEDIUM
5.0
CVE-2025-69416
2026-01-02 21:03:42 UTC

In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve other tokens (intended for unrelated access) via clients.plex.tv/devices.xml.

MEDIUM
5.0
CVE-2025-69415
2026-01-02 21:02:50 UTC

In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly aligned with whether the device is currently associated with an account.

HIGH
7.1
CVE-2025-69414
2026-01-02 21:01:45 UTC

Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient access token.

HIGH
8.5
CVE-2026-0566
2026-01-02 21:00:56 UTC

code-projects Content Management System edit_posts.php unrestricted upload

MEDIUM
5.1
CVE-2025-15431
2026-01-02 21:00:12 UTC

UTT 进取 512W formFtpServerDirConfig strcpy buffer overflow

HIGH
8.7
CVE-2025-15430
2026-01-02 20:59:15 UTC

UTT 进取 512W formFtpServerShareDirSelcet strcpy buffer overflow

HIGH
8.7
CVE-2025-15429
2026-01-02 20:58:32 UTC

UTT 进取 512W formConfigCliForEngineerOnly strcpy buffer overflow

HIGH
8.7
CVE-2021-47725
2026-01-02 20:57:55 UTC

STVS ProVision 5.9.10 Authenticated Reflected Cross-Site Scripting via Files Parameter

MEDIUM
4.8
CVE-2025-69024
2026-01-02 20:49:59 UTC

WordPress BizPrint plugin <= 4.6.7 - Broken Access Control vulnerability

MEDIUM
6.5
CVE-2025-69023
2026-01-02 20:47:03 UTC

WordPress Discussion Board plugin <= 2.5.7 - Broken Access Control vulnerability

MEDIUM
4.3
CVE-2025-68972
2026-01-02 20:44:27 UTC

In GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an "invalid armor" message is printed during verification). This is related to use of \f as a marker to denote truncation of a long plaintext line.

MEDIUM
5.9
CVE-2025-68973
2026-01-02 20:43:58 UTC

In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.)

HIGH
7.8
CVE-2021-47740
2026-01-02 20:42:42 UTC

KZTech JT3500V 4G LTE CPE 2.0.1 Insufficient Session Expiration Vulnerability

MEDIUM
6.9
CVE-2021-47743
2026-01-02 20:42:10 UTC

COMMAX Biometric Access Control System 1.0.0 Reflected XSS via Cookie Parameters

MEDIUM
5.1
CVE-2025-69022
2026-01-02 20:35:51 UTC

WordPress HR Management Lite plugin <= 3.5 - Broken Access Control vulnerability

MEDIUM
5.4
CVE-2025-69021
2026-01-02 20:22:35 UTC

WordPress Popup box plugin <= 6.0.7 - Cross Site Request Forgery (CSRF) vulnerability

MEDIUM
5.4
CVE-2020-36903
2026-01-02 20:17:19 UTC

Selea CarPlateServer 4.0.1.6 Local Privilege Escalation via Unquoted Service Path

HIGH
8.5
CVE-2020-36904
2026-01-02 20:16:15 UTC

Selea CarPlateServer 4.0.1.6 Remote Program Execution via Configuration Endpoint

CRITICAL
9.3
CVE-2021-47726
2026-01-02 20:08:08 UTC

NuCom 11N Wireless Router 5.07.90 Privilege Escalation via Configuration Backup

HIGH
8.7
CVE-2021-47741
2026-01-02 20:07:00 UTC

ZBL EPON ONU Broadband Router V100R001 Privilege Escalation via Configuration Endpoint

HIGH
8.7
CVE-2021-47742
2026-01-02 20:05:26 UTC

Epic Games Psyonix Rocket League <=1.95 Elevation of Privileges via Insecure Permissions

HIGH
8.5
CVE-2026-0571
2026-01-02 20:02:06 UTC

yeqifu warehouse AppFileUtils.java createResponseEntity path traversal

MEDIUM
5.3
CVE-2022-50787
2026-01-02 19:58:05 UTC

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Stored Cross-Site Scripting

MEDIUM
5.3
CVE-2022-50696
2026-01-02 19:56:13 UTC

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Hardcoded Credentials Authentication Bypass

CRITICAL
9.3
CVE-2022-50695
2026-01-02 19:54:48 UTC

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x ICMP Flood Attack via Network Commands

HIGH
8.7
CVE-2025-55683
2026-01-02 19:53:23 UTC

Windows Kernel Information Disclosure Vulnerability

MEDIUM
5.5
CVE-2025-59184
2026-01-02 19:53:23 UTC

Storage Spaces Direct Information Disclosure Vulnerability

MEDIUM
5.5
CVE-2025-59501
2026-01-02 19:53:22 UTC

Microsoft Configuration Manager Spoofing Vulnerability

MEDIUM
4.8
CVE-2025-60711
2026-01-02 19:53:22 UTC

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

MEDIUM
6.3
CVE-2025-59500
2026-01-02 19:53:21 UTC

Azure Notification Service Elevation of Privilege Vulnerability

HIGH
7.7
CVE-2025-59503
2026-01-02 19:53:21 UTC

Azure Compute Resource Provider Elevation of Privilege Vulnerability

CRITICAL
10.0
CVE-2025-59273
2026-01-02 19:53:20 UTC

Azure Event Grid System Elevation of Privilege Vulnerability

HIGH
7.3
CVE-2025-59286
2026-01-02 19:53:19 UTC

Copilot Information Disclosure Vulnerability

CRITICAL
9.3
CVE-2025-55321
2026-01-02 19:53:18 UTC

Azure Monitor Log Analytics Spoofing Vulnerability

CRITICAL
9.3
CVE-2025-59272
2026-01-02 19:53:18 UTC

Copilot Information Disclosure Vulnerability

CRITICAL
9.3
CVE-2025-59271
2026-01-02 19:53:17 UTC

Redis Enterprise Elevation of Privilege Vulnerability

HIGH
8.7
CVE-2025-59247
2026-01-02 19:53:16 UTC

Azure PlayFab Elevation of Privilege Vulnerability

HIGH
8.8
CVE-2025-59252
2026-01-02 19:53:16 UTC

M365 Copilot Information Disclosure Vulnerability

CRITICAL
9.3
CVE-2025-59218
2026-01-02 19:53:15 UTC

Azure Entra ID Elevation of Privilege Vulnerability

CRITICAL
9.6
CVE-2025-59246
2026-01-02 19:53:15 UTC

Azure Entra ID Elevation of Privilege Vulnerability

CRITICAL
9.8
CVE-2025-59497
2026-01-02 19:53:14 UTC

Microsoft Defender for Linux Denial of Service Vulnerability

HIGH
7.0
CVE-2025-59287
2026-01-02 19:53:13 UTC

Windows Server Update Service (WSUS) Remote Code Execution Vulnerability

CRITICAL
9.8
CVE-2025-59289
2026-01-02 19:53:13 UTC

Windows Bluetooth Service Elevation of Privilege Vulnerability

HIGH
7.0