Latest CVE Feed
-
9.8
CRITICALCVE-2025-55125
This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file.... Read more
Affected Products : veeam_backup_\&_replication- Published: Jan. 08, 2026
- Modified: Jan. 12, 2026
- Vuln Type: Misconfiguration
-
4.9
MEDIUMCVE-2026-22242
CoreShop is a Pimcore enhanced eCommerce solution. Prior to version 4.1.8, a blind SQL injection vulnerability exists in the application that allows an authenticated administrator-level user to extract database contents using boolean-based or time-based t... Read more
Affected Products : coreshop- Published: Jan. 08, 2026
- Modified: Jan. 12, 2026
- Vuln Type: Injection
-
7.8
HIGHCVE-2026-21505
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV has undefined behavior due to an invalid enum value. This issue has been patched ... Read more
Affected Products : iccdev- Published: Jan. 07, 2026
- Modified: Jan. 12, 2026
- Vuln Type: Memory Corruption
-
0.0
NACVE-2025-46070
An issue in Automai BotManager v.25.2.0 allows a remote attacker to execute arbitrary code via the BotManager.exe component... Read more
Affected Products :- Published: Jan. 12, 2026
- Modified: Jan. 12, 2026
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2026-0581
A vulnerability was determined in Tenda AC1206 15.03.06.23. Affected by this issue is the function formBehaviorManager of the file /goform/BehaviorManager of the component httpd. Executing a manipulation of the argument modulename/option/data/switch can l... Read more
- Published: Jan. 05, 2026
- Modified: Jan. 12, 2026
- Vuln Type: Injection
-
0.0
NACVE-2025-46068
An issue in Automai Director v.25.2.0 allows a remote attacker to execute arbitrary code via the update mechanism... Read more
Affected Products :- Published: Jan. 12, 2026
- Modified: Jan. 12, 2026
- Vuln Type: Supply Chain
-
0.0
NACVE-2025-46067
An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges and obtain sensitive information via a crafted js file... Read more
Affected Products :- Published: Jan. 12, 2026
- Modified: Jan. 12, 2026
- Vuln Type: Information Disclosure
-
8.2
HIGHCVE-2025-71063
Errands before 46.2.10 does not verify TLS certificates for CalDAV servers.... Read more
Affected Products :- Published: Jan. 12, 2026
- Modified: Jan. 12, 2026
- Vuln Type: Misconfiguration
-
0.0
NACVE-2025-67813
Quest KACE Desktop Authority through 11.3.1 has Insecure Permissions on the Named Pipes used for inter-process communication... Read more
Affected Products :- Published: Jan. 12, 2026
- Modified: Jan. 12, 2026
- Vuln Type: Misconfiguration
-
0.0
NACVE-2025-66939
Cross Site Scripting vulnerability in 66biolinks by AltumCode v.61.0.1 allows an attacker to execute arbitrary code via a crafted favicon file... Read more
Affected Products :- Published: Jan. 12, 2026
- Modified: Jan. 12, 2026
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2026-0607
A flaw has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PHP/AdminViewSongs.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remote... Read more
Affected Products : online_music_site- Published: Jan. 06, 2026
- Modified: Jan. 12, 2026
- Vuln Type: Injection
-
0.0
NACVE-2025-46066
An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges... Read more
Affected Products :- Published: Jan. 12, 2026
- Modified: Jan. 12, 2026
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2026-0606
A vulnerability was detected in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /FrontEnd/Albums.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate t... Read more
Affected Products : online_music_site- Published: Jan. 05, 2026
- Modified: Jan. 12, 2026
- Vuln Type: Injection
-
9.8
CRITICALCVE-2026-0605
A security vulnerability has been detected in code-projects Online Music Site 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. Such manipulation of the argument username/password leads to sql injection. The attack ma... Read more
Affected Products : online_music_site- Published: Jan. 05, 2026
- Modified: Jan. 12, 2026
- Vuln Type: Injection
-
7.8
HIGHCVE-2025-47343
Memory corruption while processing a video session to set video parameters.... Read more
Affected Products : wcd9380_firmware wcd9385_firmware qcm6490_firmware wcd9370_firmware wcd9375_firmware fastconnect_6900_firmware fastconnect_7800_firmware fastconnect_6700_firmware qca0000_firmware wsa8840_firmware +40 more products- Published: Jan. 07, 2026
- Modified: Jan. 12, 2026
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-67268
gpsd before commit dc966aa contains a heap-based out-of-bounds write vulnerability in the drivers/driver_nmea2000.c file. The hnd_129540 function, which handles NMEA2000 PGN 129540 (GNSS Satellites in View) packets, fails to validate the user-supplied sat... Read more
Affected Products : gpsd- Published: Jan. 02, 2026
- Modified: Jan. 12, 2026
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-15432
A vulnerability has been found in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3. This vulnerability affects the function downloadShowFile of the file /file/downloadShowFile.action of the component com.yeqifu.sys.controller.FileController... Read more
- Published: Jan. 02, 2026
- Modified: Jan. 12, 2026
- Vuln Type: Path Traversal
-
5.3
MEDIUMCVE-2024-55374
REDCap 14.3.13 allows an attacker to enumerate usernames due to an observable discrepancy between login attempts.... Read more
Affected Products : redcap- Published: Jan. 02, 2026
- Modified: Jan. 12, 2026
- Vuln Type: Authentication
-
6.3
MEDIUMCVE-2025-68161
The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguratio... Read more
Affected Products : log4j- Published: Dec. 18, 2025
- Modified: Jan. 12, 2026
- Vuln Type: Misconfiguration
-
6.7
MEDIUMCVE-2025-14596
Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro Installer (SFX) on Windows allows Search Order Hijacking.This issue affects Quartus Prime Pro: from 24.1 through 24.3.1.... Read more
- Published: Jan. 07, 2026
- Modified: Jan. 12, 2026
- Vuln Type: Path Traversal