Latest CVE Feed
-
0.0
NACVE-2026-21496
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to NULL pointer dereference via the signature parser. This issue ha... Read more
Affected Products :- Published: Jan. 07, 2026
- Modified: Jan. 07, 2026
- Vuln Type: Memory Corruption
-
7.1
HIGHCVE-2025-4677
Insufficient Session Expiration vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.This issue affects WebPro SNMP Card PowerValue: through 1.1.8.K; WebPro SNMP Card PowerValue UL: through 1.1.8.K.... Read more
Affected Products :- Published: Jan. 07, 2026
- Modified: Jan. 07, 2026
- Vuln Type: Authentication
-
0.0
NACVE-2026-21497
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to NULL pointer dereference via an unknown tag parser. This issue h... Read more
Affected Products :- Published: Jan. 07, 2026
- Modified: Jan. 07, 2026
- Vuln Type: Memory Corruption
-
0.0
NACVE-2026-21495
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to division by zero in the TIFF Image Reader. This issue has been p... Read more
Affected Products :- Published: Jan. 07, 2026
- Modified: Jan. 07, 2026
- Vuln Type: Denial of Service
-
9.2
CRITICALCVE-2026-22542
An attacker with access to the system's internal network can cause a denial of service on the system by making two concurrent connections through the Telnet service.... Read more
Affected Products :- Published: Jan. 07, 2026
- Modified: Jan. 07, 2026
- Vuln Type: Denial of Service
-
8.2
HIGHCVE-2026-22541
The massive sending of ICMP requests causes a denial of service on one of the boards from the EVCharger that allows control the EV interfaces. Since the board must be operating correctly for the charger to also function correctly.... Read more
Affected Products :- Published: Jan. 07, 2026
- Modified: Jan. 07, 2026
- Vuln Type: Denial of Service
-
5.3
MEDIUMCVE-2026-21635
An Improper Access Control could allow a malicious actor in Wi-Fi range to the EV Station Lite (v1.5.2 and earlier) to use WiFi AutoLink feature on a device that was only adopted via Ethernet.... Read more
Affected Products :- Published: Jan. 05, 2026
- Modified: Jan. 07, 2026
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-69335
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Team Showcase team-showcase allows Stored XSS.This issue affects Team Showcase: from n/a through <= 2.9.... Read more
Affected Products : team_showcase- Published: Jan. 06, 2026
- Modified: Jan. 07, 2026
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-69091
Missing Authorization vulnerability in Kraft Plugins Demo Importer Plus demo-importer-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Demo Importer Plus: from n/a through <= 2.0.8.... Read more
Affected Products : demo_importer_plus- Published: Dec. 30, 2025
- Modified: Jan. 07, 2026
- Vuln Type: Authorization
-
4.9
MEDIUMCVE-2025-62327
In HCL DevOps Deploy 8.1.2.0 through 8.1.2.3, a user with LLM configuration privileges may be able to recover a credential previously saved for performing authenticated LLM Queries.... Read more
Affected Products :- Published: Jan. 07, 2026
- Modified: Jan. 07, 2026
- Vuln Type: Authentication
-
3.1
LOWCVE-2025-43531
A race condition was addressed with improved state handling. This issue is fixed in watchOS 26.2, Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, tvOS 26.2. Processing maliciously crafted web content m... Read more
- Published: Dec. 17, 2025
- Modified: Jan. 07, 2026
- Vuln Type: Race Condition
-
4.3
MEDIUMCVE-2025-43501
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Processing maliciously crafted web content may lead to an une... Read more
- Published: Dec. 17, 2025
- Modified: Jan. 07, 2026
- Vuln Type: Memory Corruption
-
7.3
HIGHCVE-2025-14325
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability affects Firefox < 146, Firefox ESR < 140.6, Thunderbird < 146, and Thunderbird < 140.6.... Read more
- Published: Dec. 09, 2025
- Modified: Jan. 07, 2026
- Vuln Type: Memory Corruption
-
4.3
MEDIUMCVE-2025-14023
LINE client for iOS prior to 15.19 allows UI spoofing due to inconsistencies between the navigation state and the in-app browser's user interface, which could create confusion about the trust context of displayed pages or interactive elements under specif... Read more
Affected Products : line- Published: Dec. 15, 2025
- Modified: Jan. 07, 2026
- Vuln Type: Misconfiguration
-
7.7
HIGHCVE-2025-14022
LINE client for iOS prior to 15.4 allows man-in-the-middle attacks due to improper SSL/TLS certificate validation in an integrated financial SDK. The SDK interfered with the application's network processing, causing server certificate verification to be d... Read more
Affected Products : line- Published: Dec. 15, 2025
- Modified: Jan. 07, 2026
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-15269
FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit this vulnerability in that ... Read more
Affected Products : fontforge- Published: Dec. 31, 2025
- Modified: Jan. 07, 2026
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-15270
FontForge SFD File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit this vu... Read more
Affected Products : fontforge- Published: Dec. 31, 2025
- Modified: Jan. 07, 2026
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-15271
FontForge SFD File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit this vu... Read more
Affected Products : fontforge- Published: Dec. 31, 2025
- Modified: Jan. 07, 2026
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-15272
FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit this vulnerabil... Read more
Affected Products : fontforge- Published: Dec. 31, 2025
- Modified: Jan. 07, 2026
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-15273
FontForge PFB File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit this vulnerabi... Read more
Affected Products : fontforge- Published: Dec. 31, 2025
- Modified: Jan. 07, 2026
- Vuln Type: Memory Corruption