Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2025-29228

    Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter.... Read more

    Affected Products : e5600_firmware e5600
    • Published: Dec. 23, 2025
    • Modified: Jan. 06, 2026
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-29229

    linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus.... Read more

    Affected Products : e5600_firmware e5600
    • Published: Dec. 23, 2025
    • Modified: Jan. 06, 2026
    • Vuln Type: Injection
  • 6.2

    MEDIUM
    CVE-2025-65410

    A stack overflow in the src/main.c component of GNU Unrtf v0.21.10 allows attackers to cause a Denial of Service (DoS) via injecting a crafted input into the filename parameter.... Read more

    Affected Products : unrtf
    • Published: Dec. 23, 2025
    • Modified: Jan. 06, 2026
    • Vuln Type: Denial of Service
  • 4.0

    MEDIUM
    CVE-2025-65713

    Home Assistant Core before v2025.8.0 is vulnerable to Directory Traversal. The Downloader integration does not fully validate file paths during concatenation, leaving a path traversal vulnerability.... Read more

    Affected Products : home-assistant
    • Published: Dec. 23, 2025
    • Modified: Jan. 06, 2026
    • Vuln Type: Path Traversal
  • 9.8

    CRITICAL
    CVE-2025-51511

    Cadmium CMS v.0.4.9 has a background arbitrary file upload vulnerability in /admin/content/filemanager/uploads.... Read more

    Affected Products : cadmium_cms
    • Published: Dec. 23, 2025
    • Modified: Jan. 06, 2026
    • Vuln Type: Misconfiguration
  • 8.4

    HIGH
    CVE-2025-25364

    A command injection vulnerability in the me.connectify.SMJobBlessHelper XPC service of Speedify VPN up to v15.0.0 allows attackers to execute arbitrary commands with root-level privileges.... Read more

    Affected Products : speedify
    • Published: Dec. 23, 2025
    • Modified: Jan. 06, 2026
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-65354

    Improper input handling in /Grocery/search_products_itname.php inPuneethReddyHC event-management 1.0 permits SQL injection via the sitem_name POST parameter. Crafted payloads can alter query logic and disclose database contents. Exploitation may result in... Read more

    Affected Products : event_management
    • Published: Dec. 23, 2025
    • Modified: Jan. 06, 2026
    • Vuln Type: Injection
  • 0.0

    NA
    CVE-2025-69364

    Missing Authorization vulnerability in Cloudways Breeze breeze allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Breeze: from n/a through <= 2.2.21.... Read more

    Affected Products :
    • Published: Jan. 06, 2026
    • Modified: Jan. 06, 2026
    • Vuln Type: Authorization
  • 0.0

    NA
    CVE-2025-69363

    Missing Authorization vulnerability in CyberChimps Responsive Addons for Elementor responsive-addons-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Responsive Addons for Elementor: from n/a through... Read more

    Affected Products : responsive_addons_for_elementor
    • Published: Jan. 06, 2026
    • Modified: Jan. 06, 2026
    • Vuln Type: Authorization
  • 0.0

    NA
    CVE-2025-69361

    Missing Authorization vulnerability in PublishPress Post Expirator post-expirator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Expirator: from n/a through <= 4.9.3.... Read more

    Affected Products :
    • Published: Jan. 06, 2026
    • Modified: Jan. 06, 2026
    • Vuln Type: Authorization
  • 0.0

    NA
    CVE-2025-69359

    Missing Authorization vulnerability in WPFunnels Creator LMS creatorlms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Creator LMS: from n/a through <= 1.1.12.... Read more

    Affected Products :
    • Published: Jan. 06, 2026
    • Modified: Jan. 06, 2026
    • Vuln Type: Authorization
  • 0.0

    NA
    CVE-2025-69356

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor allows PHP Local File Inclusion.This issue affects TheGem ... Read more

    Affected Products :
    • Published: Jan. 06, 2026
    • Modified: Jan. 06, 2026
    • Vuln Type: Path Traversal
  • 0.0

    NA
    CVE-2025-69355

    Missing Authorization vulnerability in Tickera Tickera tickera-event-ticketing-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tickera: from n/a through <= 3.5.6.4.... Read more

    Affected Products : tickera
    • Published: Jan. 06, 2026
    • Modified: Jan. 06, 2026
    • Vuln Type: Authorization
  • 7.5

    HIGH
    CVE-2025-69342

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in VanKarWai Calafate calafate allows PHP Local File Inclusion.This issue affects Calafate: from n/a through <= 1.7.7.... Read more

    Affected Products :
    • Published: Jan. 06, 2026
    • Modified: Jan. 06, 2026
    • Vuln Type: Injection
  • 5.4

    MEDIUM
    CVE-2025-69341

    Missing Authorization vulnerability in BuddhaThemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WeDesignTech Ultimate Booking Addon: fro... Read more

    Affected Products :
    • Published: Jan. 06, 2026
    • Modified: Jan. 06, 2026
    • Vuln Type: Authorization
  • 4.3

    MEDIUM
    CVE-2025-69336

    Missing Authorization vulnerability in bdthemes Ultimate Store Kit Elementor Addons ultimate-store-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Store Kit Elementor Addons: from n/a through <= 2.9.... Read more

    Affected Products : ultimate_store_kit
    • Published: Jan. 06, 2026
    • Modified: Jan. 06, 2026
    • Vuln Type: Authorization
  • 0.0

    NA
    CVE-2025-69335

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Team Showcase team-showcase allows Stored XSS.This issue affects Team Showcase: from n/a through <= 2.9.... Read more

    Affected Products : team_showcase
    • Published: Jan. 06, 2026
    • Modified: Jan. 06, 2026
    • Vuln Type: Cross-Site Scripting
  • 6.5

    MEDIUM
    CVE-2025-69334

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Wishlist for WooCommerce wish-list-for-woocommerce allows Stored XSS.This issue affects Wishlist for WooCommerce: from n/a through <= 3.3.0.... Read more

    Affected Products :
    • Published: Jan. 06, 2026
    • Modified: Jan. 06, 2026
    • Vuln Type: Cross-Site Scripting
  • 4.3

    MEDIUM
    CVE-2025-69331

    Missing Authorization vulnerability in Jeroen Schmit Theater for WordPress theatre allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Theater for WordPress: from n/a through <= 0.19.... Read more

    Affected Products : theater_for_wordpress
    • Published: Jan. 06, 2026
    • Modified: Jan. 06, 2026
    • Vuln Type: Authorization
  • 4.3

    MEDIUM
    CVE-2025-69327

    Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Car Rental Manager: from n/a through <= 1.0.9.... Read more

    Affected Products :
    • Published: Jan. 06, 2026
    • Modified: Jan. 06, 2026
    • Vuln Type: Authorization
Showing 20 of 5138 Results