Latest CVE Feed
-
6.9
MEDIUMCVE-2026-22604
OpenProject is an open-source, web-based project management software. For OpenProject versions from 11.2.1 to before 16.6.2, when sending a POST request to the /account/change_password endpoint with an arbitrary User ID as the password_change_user_id para... Read more
Affected Products : openproject- Published: Jan. 10, 2026
- Modified: Jan. 14, 2026
- Vuln Type: Information Disclosure
-
6.9
MEDIUMCVE-2026-22603
OpenProject is an open-source, web-based project management software. Prior to version 16.6.2, OpenProject’s unauthenticated password-change endpoint (/account/change_password) was not protected by the same brute-force safeguards that apply to the normal ... Read more
Affected Products : openproject- Published: Jan. 10, 2026
- Modified: Jan. 14, 2026
- Vuln Type: Authentication
-
3.5
LOWCVE-2026-22602
OpenProject is an open-source, web-based project management software. Prior to version 16.6.2, a low‑privileged logged-in user can view the full names of other users. Since user IDs are assigned sequentially and predictably (e.g., 1 to 1000), an attacker ... Read more
Affected Products : openproject- Published: Jan. 10, 2026
- Modified: Jan. 14, 2026
- Vuln Type: Information Disclosure
-
8.6
HIGHCVE-2026-22601
OpenProject is an open-source, web-based project management software. For OpenProject version 16.6.1 and below, a registered administrator can execute arbitrary command by configuring sendmail binary path and sending a test email. This issue has been patc... Read more
Affected Products : openproject- Published: Jan. 10, 2026
- Modified: Jan. 14, 2026
- Vuln Type: Injection
-
9.1
CRITICALCVE-2026-22600
OpenProject is an open-source, web-based project management software. A Local File Read (LFR) vulnerability exists in the work package PDF export functionality of OpenProject prior to version 16.6.4. By uploading a specially crafted SVG file (disguised as... Read more
Affected Products : openproject- Published: Jan. 10, 2026
- Modified: Jan. 14, 2026
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2026-0852
A security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /Administrator/PHP/AdminUpdateUser.php. The manipulation of the argument ID results in sql injection. The attack can be exe... Read more
Affected Products : online_music_site- Published: Jan. 12, 2026
- Modified: Jan. 14, 2026
- Vuln Type: Injection
-
9.8
CRITICALCVE-2026-0851
A vulnerability was identified in code-projects Online Music Site 1.0. The affected element is an unknown function of the file /Administrator/PHP/AdminAddUser.php. The manipulation of the argument txtusername leads to sql injection. Remote exploitation of... Read more
Affected Products : online_music_site- Published: Jan. 12, 2026
- Modified: Jan. 14, 2026
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-55462
A CORS misconfiguration in Eramba Community and Enterprise Editions v3.26.0 allows an attacker-controlled Origin header to be reflected in the Access-Control-Allow-Origin response along with Access-Control-Allow-Credentials: true. This permits malicious t... Read more
Affected Products :- Published: Jan. 13, 2026
- Modified: Jan. 14, 2026
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-14242
A flaw was found in vsftpd. This vulnerability allows a denial of service (DoS) via an integer overflow in the ls command parameter parsing, triggered by a remote, authenticated attacker sending a crafted STAT command with a specific byte sequence.... Read more
- Published: Jan. 14, 2026
- Modified: Jan. 14, 2026
-
7.2
HIGHCVE-2026-0850
A vulnerability was determined in code-projects Intern Membership Management System 1.0. Impacted is an unknown function of the file /admin/delete_activity.php. Executing a manipulation of the argument activity_id can lead to sql injection. The attack may... Read more
Affected Products : intern_membership_management_system- Published: Jan. 11, 2026
- Modified: Jan. 14, 2026
- Vuln Type: Injection
-
7.2
HIGHCVE-2025-59922
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.4, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2.0 through 7.2.10, FortiClie... Read more
Affected Products : forticlientems- Published: Jan. 13, 2026
- Modified: Jan. 14, 2026
- Vuln Type: Injection
-
3.8
LOWCVE-2025-67685
A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4, FortiSandbox 4.4 all versions, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an authenticated attacker to pro... Read more
Affected Products : fortisandbox- Published: Jan. 13, 2026
- Modified: Jan. 14, 2026
- Vuln Type: Server-Side Request Forgery
-
6.5
MEDIUMCVE-2025-58693
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 allows a privileged attacker to delete files from the underlying filesystem via craf... Read more
Affected Products : fortivoice- Published: Jan. 13, 2026
- Modified: Jan. 14, 2026
- Vuln Type: Path Traversal
-
10.0
CRITICALCVE-2026-23550
Incorrect Privilege Assignment vulnerability in Modular DS allows Privilege Escalation.This issue affects Modular DS: from n/a through 2.5.1.... Read more
Affected Products :- Published: Jan. 14, 2026
- Modified: Jan. 14, 2026
- Vuln Type: Authorization
-
7.1
HIGHCVE-2025-36192
IBM DS8A00( R10.1) 10.10.106.0 and IBM DS8A00 ( R10.0) 10.1.3.010.2.45.0 and IBM DS8900F ( R9.4) 89.40.83.089.42.18.089.44.5.0 IBM System Storage DS8000 could allow a local user with authorized CCW update permissions to delete or corrupt backups due to mi... Read more
- Published: Dec. 26, 2025
- Modified: Jan. 14, 2026
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2026-21639
A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote code execution (RCE) within the affected product. Affected Products: airMAX AC (Version 8.7.20 and earli... Read more
- Published: Jan. 08, 2026
- Modified: Jan. 14, 2026
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2026-21638
A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote code execution (RCE) within the affected product. Affected Products: UBB-XG (Version 1.2.2 and earlier) UDB... Read more
Affected Products : ubb ubb-xg ubb-xg_firmware udb-pro_firmware udb-pro udb-pro-sector_firmware udb-pro-sector ubb_firmware- Published: Jan. 08, 2026
- Modified: Jan. 14, 2026
- Vuln Type: Memory Corruption
-
9.0
CRITICALCVE-2025-59470
This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.... Read more
Affected Products : veeam_backup_\&_replication- Published: Jan. 08, 2026
- Modified: Jan. 14, 2026
- Vuln Type: Injection
-
9.0
CRITICALCVE-2025-59469
This vulnerability allows a Backup or Tape Operator to write files as root.... Read more
Affected Products : veeam_backup_\&_replication- Published: Jan. 08, 2026
- Modified: Jan. 14, 2026
- Vuln Type: Authorization
-
9.1
CRITICALCVE-2025-59468
This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter.... Read more
Affected Products : veeam_backup_\&_replication- Published: Jan. 08, 2026
- Modified: Jan. 14, 2026
- Vuln Type: Authentication