Latest CVE Feed
-
8.5
HIGHCVE-2026-22244
OpenMetadata is a unified metadata platform. Versions prior to 1.11.4 are vulnerable to remote code execution via Server-Side Template Injection (SSTI) in FreeMarker email templates. An attacker must have administrative privileges to exploit the vulnerabi... Read more
Affected Products : openmetadata- Published: Jan. 08, 2026
- Modified: Jan. 15, 2026
- Vuln Type: Injection
-
9.8
CRITICALCVE-2026-22043
RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 through 1.0.0-alpha.78, a flawed `deny_only` short-circuit in RustFS IAM allows a restricted service account or STS credential to self-issue an unrestricted service ac... Read more
Affected Products : rustfs- Published: Jan. 08, 2026
- Modified: Jan. 15, 2026
- Vuln Type: Authorization
-
8.8
HIGHCVE-2026-22042
RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.79, he `ImportIam` admin API validates permissions using `ExportIAMAction` instead of `ImportIAMAction`, allowing a principal with export-only IAM permissions to per... Read more
Affected Products : rustfs- Published: Jan. 08, 2026
- Modified: Jan. 15, 2026
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-15263
A weakness has been identified in BiggiDroid Simple PHP CMS 1.0. Affected is an unknown function of the file /admin/login.php of the component Admin Login. Executing manipulation of the argument Username can lead to sql injection. The attack can be execut... Read more
Affected Products : simple_php_cms- Published: Dec. 30, 2025
- Modified: Jan. 15, 2026
- Vuln Type: Injection
-
7.2
HIGHCVE-2025-15262
A security flaw has been discovered in BiggiDroid Simple PHP CMS 1.0. This impacts an unknown function of the file /admin/edit.php of the component Site Logo Handler. Performing manipulation of the argument image results in unrestricted upload. Remote exp... Read more
Affected Products : simple_php_cms- Published: Dec. 30, 2025
- Modified: Jan. 15, 2026
- Vuln Type: Misconfiguration
-
7.8
HIGHCVE-2026-20922
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_23h2 +8 more products- Published: Jan. 13, 2026
- Modified: Jan. 15, 2026
-
7.5
HIGHCVE-2026-22245
Mastodon is a free, open-source social network server based on ActivityPub. By nature, Mastodon performs a lot of outbound requests to user-provided domains. Mastodon, however, has some protection mechanism to disallow requests to local IP addresses (unle... Read more
Affected Products : mastodon- Published: Jan. 08, 2026
- Modified: Jan. 15, 2026
- Vuln Type: Server-Side Request Forgery
-
9.8
CRITICALCVE-2025-15458
A vulnerability was determined in bg5sbk MiniCMS up to 1.8. This affects an unknown function of the file /mc-admin/post-edit.php of the component Article Handler. Executing a manipulation can lead to improper authentication. It is possible to launch the a... Read more
Affected Products : minicms- Published: Jan. 05, 2026
- Modified: Jan. 15, 2026
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-11543
Improper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may create and run unauthorized firmware.... Read more
Affected Products : np-p502h_firmware np-p502h np-p502w_firmware np-p502w np-p452h_firmware np-p452h np-p452w_firmware np-p452w np-p502hg_firmware np-p502hg +42 more products- Published: Dec. 22, 2025
- Modified: Jan. 15, 2026
- Vuln Type: Misconfiguration
-
9.1
CRITICALCVE-2025-11540
Path Traversal vulnerability in Sharp Display Solutions projectors allows a attacker may access and read any files within the projector.... Read more
Affected Products : np-p502h_firmware np-p502h np-p502w_firmware np-p502w np-p452h_firmware np-p452h np-p452w_firmware np-p452w np-p502hg_firmware np-p502hg +42 more products- Published: Dec. 22, 2025
- Modified: Jan. 15, 2026
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-11541
Stack-based Buffer Overflow vulnerability in Sharp Display Solutions projectors allows a attacker may execute arbitrary commands and programs.... Read more
Affected Products : np-p502h_firmware np-p502h np-p502w_firmware np-p502w np-p452h_firmware np-p452h np-p452w_firmware np-p452w np-p502hg_firmware np-p502hg +42 more products- Published: Dec. 22, 2025
- Modified: Jan. 15, 2026
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-11542
Stack-based Buffer Overflow vulnerability in Sharp Display Solutions projectors allows a attacker may execute arbitrary commands and programs.... Read more
Affected Products : np-p502h_firmware np-p502h np-p502w_firmware np-p502w np-p452h_firmware np-p452h np-p452w_firmware np-p452w np-p502hg_firmware np-p502hg +42 more products- Published: Dec. 22, 2025
- Modified: Jan. 15, 2026
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-15457
A vulnerability was found in bg5sbk MiniCMS up to 1.8. The impacted element is an unknown function of the file /minicms/mc-admin/post.php of the component Trash File Restore Handler. Performing a manipulation results in improper authentication. It is poss... Read more
Affected Products : minicms- Published: Jan. 05, 2026
- Modified: Jan. 15, 2026
- Vuln Type: Authentication
-
7.7
HIGHCVE-2025-62004
BullWall Server Intrusion Protection (SIP) services are initialized after login services during system startup. A local, authenticated attacker can log in after boot and before SIP MFA is running. The SIP services do not retroactively enforce MFA or disco... Read more
Affected Products : server_intrusion_protection- Published: Dec. 18, 2025
- Modified: Jan. 15, 2026
- Vuln Type: Authentication
-
7.7
HIGHCVE-2025-62003
BullWall Server Intrusion Protection has a noticeable configuration-dependent delay before the MFA check for RDP connections. A remote, authenticated attacker can potentially bypass detection during this delay. Versions 4.6.0.0, 4.6.0.6, 4.6.0.7, and 4.6.... Read more
Affected Products : server_intrusion_protection- Published: Dec. 18, 2025
- Modified: Jan. 15, 2026
- Vuln Type: Authentication
-
8.1
HIGHCVE-2025-62002
BullWall Ransomware Containment considers the number of files modified to trigger detection. An authenticated attacker could encrypt a single (possibly large) file without triggering detection if thresholds are configured to require multiple file changes.... Read more
Affected Products : ransomware_containment- Published: Dec. 18, 2025
- Modified: Jan. 15, 2026
- Vuln Type: Denial of Service
-
8.8
HIGHCVE-2025-62001
BullWall Ransomware Containment supports configurable file and directory exclusions such as '$RECYCLE.BIN' to balance monitoring scope and performance. Certain exclusion patterns could allow an authenticated attacker to rename directories in a way that av... Read more
Affected Products : ransomware_containment- Published: Dec. 18, 2025
- Modified: Jan. 15, 2026
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-12049
Missing Authentication for Critical Function vulnerability in Sharp Display Solutions Media Player MP-01 All Verisons allows a attacker may access to the web interface of the affected product without authentication and change settings or perform other ope... Read more
- Published: Dec. 22, 2025
- Modified: Jan. 15, 2026
- Vuln Type: Authentication
-
7.8
HIGHCVE-2026-20976
Improper input validation in Galaxy Store prior to version 4.6.02 allows local attacker to execute arbitrary script.... Read more
Affected Products : galaxy_store- Published: Jan. 09, 2026
- Modified: Jan. 15, 2026
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2026-20975
Improper handling of insufficient permission in Samsung Cloud prior to version 5.6.11 allows local attackers to access specific files in arbitrary path.... Read more
Affected Products : cloud- Published: Jan. 09, 2026
- Modified: Jan. 15, 2026
- Vuln Type: Path Traversal