Latest CVE Feed
-
10.0
CRITICALCVE-2025-67109
Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certificate checks and execute commands with System privileges.... Read more
Affected Products : cyclone_data_distribution_service- Published: Dec. 23, 2025
- Modified: Jan. 06, 2026
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-67111
An integer overflow in the RTPS protocol implementation of OpenDDS DDS before v3.33.0 allows attackers to cause a Denial of Service (DoS) via a crafted message.... Read more
Affected Products : opendds- Published: Dec. 23, 2025
- Modified: Jan. 06, 2026
- Vuln Type: Denial of Service
-
8.1
HIGHCVE-2025-32304
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mojoomla WPCHURCH allows PHP Local File Inclusion.This issue affects WPCHURCH: from n/a through 2.7.0.... Read more
Affected Products :- Published: Jan. 06, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Path Traversal
-
10.0
CRITICALCVE-2024-57521
SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the createTable function in SqlUtil.java.... Read more
Affected Products : ruoyi- Published: Dec. 23, 2025
- Modified: Jan. 06, 2026
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-29228
Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter.... Read more
- Published: Dec. 23, 2025
- Modified: Jan. 06, 2026
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-29229
linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus.... Read more
- Published: Dec. 23, 2025
- Modified: Jan. 06, 2026
- Vuln Type: Injection
-
6.2
MEDIUMCVE-2025-65410
A stack overflow in the src/main.c component of GNU Unrtf v0.21.10 allows attackers to cause a Denial of Service (DoS) via injecting a crafted input into the filename parameter.... Read more
Affected Products : unrtf- Published: Dec. 23, 2025
- Modified: Jan. 06, 2026
- Vuln Type: Denial of Service
-
4.0
MEDIUMCVE-2025-65713
Home Assistant Core before v2025.8.0 is vulnerable to Directory Traversal. The Downloader integration does not fully validate file paths during concatenation, leaving a path traversal vulnerability.... Read more
Affected Products : home-assistant- Published: Dec. 23, 2025
- Modified: Jan. 06, 2026
- Vuln Type: Path Traversal
-
9.4
CRITICALCVE-2025-14942
wolfSSH’s key exchange state machine can be manipulated to leak the client’s password in the clear, trick the client to send a bogus signature, or trick the client into skipping user authentication. This affects client applications with wolfSSH version 1.... Read more
Affected Products :- Published: Jan. 06, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-51511
Cadmium CMS v.0.4.9 has a background arbitrary file upload vulnerability in /admin/content/filemanager/uploads.... Read more
Affected Products : cadmium_cms- Published: Dec. 23, 2025
- Modified: Jan. 06, 2026
- Vuln Type: Misconfiguration
-
8.4
HIGHCVE-2025-25364
A command injection vulnerability in the me.connectify.SMJobBlessHelper XPC service of Speedify VPN up to v15.0.0 allows attackers to execute arbitrary commands with root-level privileges.... Read more
Affected Products : speedify- Published: Dec. 23, 2025
- Modified: Jan. 06, 2026
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-65354
Improper input handling in /Grocery/search_products_itname.php inPuneethReddyHC event-management 1.0 permits SQL injection via the sitem_name POST parameter. Crafted payloads can alter query logic and disclose database contents. Exploitation may result in... Read more
Affected Products : event_management- Published: Dec. 23, 2025
- Modified: Jan. 06, 2026
- Vuln Type: Injection
-
0.0
NACVE-2025-69364
Missing Authorization vulnerability in Cloudways Breeze breeze allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Breeze: from n/a through <= 2.2.21.... Read more
Affected Products :- Published: Jan. 06, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Authorization
-
0.0
NACVE-2025-69363
Missing Authorization vulnerability in CyberChimps Responsive Addons for Elementor responsive-addons-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Responsive Addons for Elementor: from n/a through... Read more
Affected Products :- Published: Jan. 06, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Authorization
-
0.0
NACVE-2025-69362
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH UiChemy uichemy allows Stored XSS.This issue affects UiChemy: from n/a through <= 4.4.2.... Read more
Affected Products :- Published: Jan. 06, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Cross-Site Scripting
-
0.0
NACVE-2025-69361
Missing Authorization vulnerability in PublishPress Post Expirator post-expirator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Expirator: from n/a through <= 4.9.3.... Read more
Affected Products :- Published: Jan. 06, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Authorization
-
0.0
NACVE-2025-69360
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for WPBakery) thegem-elements allows DOM-Based XSS.This issue affects TheGem Theme Elements (for WPBakery): from n/a t... Read more
Affected Products :- Published: Jan. 06, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Cross-Site Scripting
-
0.0
NACVE-2025-69359
Missing Authorization vulnerability in WPFunnels Creator LMS creatorlms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Creator LMS: from n/a through <= 1.1.12.... Read more
Affected Products :- Published: Jan. 06, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Authorization
-
0.0
NACVE-2025-69357
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor allows Stored XSS.This issue affects TheGem Theme Elements (for Elementor): f... Read more
Affected Products :- Published: Jan. 06, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Cross-Site Scripting
-
0.0
NACVE-2025-69356
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor allows PHP Local File Inclusion.This issue affects TheGem ... Read more
Affected Products :- Published: Jan. 06, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Path Traversal