Latest CVE Feed
-
7.5
HIGHCVE-2025-66735
youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The getRoleForm function in SysRoleController.java does not perform permission checks, which may allow non-root users to directly access root roles.... Read more
Affected Products : youlai-boot- Published: Dec. 22, 2025
- Modified: Jan. 06, 2026
- Vuln Type: Authorization
-
7.1
HIGHCVE-2025-66736
youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The importUsers function in SysUserController.java does not perform a permission check on the current user's identity, which may allow regular users to import user data into the database, resu... Read more
Affected Products : youlai-boot- Published: Dec. 22, 2025
- Modified: Jan. 06, 2026
- Vuln Type: Authorization
-
4.8
MEDIUMCVE-2025-15416
A vulnerability was found in xnx3 wangmarket up to 6.4. This affects an unknown function of the file /siteVar/save.do of the component Add Global Variable Handler. The manipulation of the argument Remark/Variable Value results in cross site scripting. The... Read more
Affected Products : wangmarket- Published: Jan. 01, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-65865
An integer overflow in eProsima Fast-DDS v3.3 allows attackers to cause a Denial of Service (DoS) via a crafted input.... Read more
Affected Products : fast_dds- Published: Dec. 23, 2025
- Modified: Jan. 06, 2026
- Vuln Type: Denial of Service
-
6.6
MEDIUMCVE-2025-65855
The OTA firmware update mechanism in Netun Solutions HelpFlash IoT (firmware v18_178_221102_ASCII_PRO_1R5_50) uses hard-coded WiFi credentials identical across all devices and does not authenticate update servers or validate firmware signatures. An attack... Read more
- Published: Dec. 17, 2025
- Modified: Jan. 06, 2026
- Vuln Type: Misconfiguration
-
5.5
MEDIUMCVE-2025-15418
A security flaw has been discovered in Open5GS up to 2.7.6. Affected by this vulnerability is the function ogs_gtp2_parse_bearer_qos in the library lib/gtp/v2/types.c of the component Bearer QoS IE Length Handler. Performing manipulation results in denial... Read more
Affected Products : open5gs- Published: Jan. 02, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2025-15419
A weakness has been identified in Open5GS up to 2.7.6. Affected by this issue is the function sgwc_s5c_handle_create_session_response of the file src/sgwc/s5c-handler.c of the component GTPv2-C Flow Handler. Executing a manipulation can lead to denial of ... Read more
Affected Products : open5gs- Published: Jan. 02, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Denial of Service
-
9.1
CRITICAL- Published: Dec. 12, 2025
- Modified: Jan. 06, 2026
- Vuln Type: Authorization
-
8.1
HIGHCVE-2025-47411
A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows them to swap the username of an existing user with that of an administrator. This vulnerability allows an ... Read more
Affected Products : streampipes- Published: Jan. 01, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-48768
Release of Invalid Pointer or Reference vulnerability was discovered in fs/inode/fs_inoderemove code of the Apache NuttX RTOS that allowed root filesystem inode removal leading to a debug assert trigger (that is disabled by default), NULL pointer derefere... Read more
Affected Products : nuttx- Published: Jan. 01, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Denial of Service
-
8.1
HIGHCVE-2025-48769
Use After Free vulnerability was discovered in fs/vfs/fs_rename code of the Apache NuttX RTOS, that due recursive implementation and single buffer use by two different pointer variables allowed arbitrary user provided size buffer reallocation and write to... Read more
Affected Products : nuttx- Published: Jan. 01, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-48721
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed th... Read more
- Published: Jan. 02, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Memory Corruption
-
4.9
MEDIUMCVE-2025-59380
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We ha... Read more
- Published: Jan. 02, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Path Traversal
-
4.9
MEDIUMCVE-2025-59381
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We ha... Read more
- Published: Jan. 02, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2025-62852
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed th... Read more
- Published: Jan. 02, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-9110
An exposure of sensitive system information to an unauthorized control sphere vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to read application data. We have alre... Read more
- Published: Jan. 02, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2026-0565
A weakness has been identified in code-projects Content Management System 1.0. This issue affects some unknown processing of the file /admin/delete.php. Executing manipulation of the argument del can lead to sql injection. The attack can be executed remot... Read more
Affected Products : content_management_system- Published: Jan. 02, 2026
- Modified: Jan. 05, 2026
- Vuln Type: Injection
-
5.5
MEDIUMCVE-2025-15432
A vulnerability has been found in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3. This vulnerability affects the function downloadShowFile of the file /file/downloadShowFile.action of the component com.yeqifu.sys.controller.FileController... Read more
Affected Products : carrental- Published: Jan. 02, 2026
- Modified: Jan. 05, 2026
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-15425
A vulnerability was determined in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /worksheet/del_user.jsp of the component HTTP GET Parameter Handler. Executing manipulation of the argument ID can lead to sql injection. The attack... Read more
Affected Products : ksoa- Published: Jan. 02, 2026
- Modified: Jan. 05, 2026
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-15424
A vulnerability was found in Yonyou KSOA 9.0. The affected element is an unknown function of the file /worksheet/agent_worksdel.jsp of the component HTTP GET Parameter Handler. Performing manipulation of the argument ID results in sql injection. Remote ex... Read more
Affected Products : ksoa- Published: Jan. 02, 2026
- Modified: Jan. 05, 2026
- Vuln Type: Injection