Browse CVEs

225 CVEs analyzed. 428 pending.

All Critical High Medium Low
CVE-2025-14740 6.7

Docker Desktop for Windows installer has permission assignment vulnerabilities allowing low-privileged attackers to gain code execution. Attackers can...

Feb 4, 2026
CVE-2025-15368 8.8

The SportsPress WordPress plugin has a Local File Inclusion vulnerability in all versions up to 2.7.26. Authenticated attackers with contributor-level...

Feb 4, 2026
CVE-2025-5329 9.8

This SQL injection vulnerability in Martcode Software's Delta Course Automation allows attackers to execute arbitrary SQL commands on the database. Al...

Feb 4, 2026
CVE-2025-8589 7.6

This CVE describes a reflected cross-site scripting (XSS) vulnerability in AKCE Software's SKSPro product. Attackers can inject malicious scripts into...

Feb 3, 2026
CVE-2026-24465 9.8

A stack-based buffer overflow vulnerability in ELECOM wireless LAN access point devices allows remote attackers to execute arbitrary code by sending s...

Feb 3, 2026
CVE-2026-1210 6.4

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to inject malicious scripts into pages using the Happy...

Feb 3, 2026
CVE-2026-1447 5.4

The Mail Mint WordPress plugin is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to 1.19.2, allowing unauthenticated attackers to ...

Feb 3, 2026
CVE-2026-20704 4.3

A cross-site request forgery (CSRF) vulnerability exists in ELECOM WRC-X1500GS-B and WRC-X1500GSA-B wireless routers. Attackers can trick authenticate...

Feb 3, 2026
CVE-2026-22550 7.2

An OS command injection vulnerability in ELECOM WRC-X1500GS-B and WRC-X1500GSA-B wireless routers allows authenticated attackers to execute arbitrary ...

Feb 3, 2026
CVE-2026-24449 4.6

This vulnerability allows attackers to calculate initial administrative passwords for affected ELECOM wireless routers using publicly available system...

Feb 3, 2026
CVE-2026-0617 7.2

This stored XSS vulnerability in the LatePoint WordPress plugin allows unauthenticated attackers to inject malicious scripts into customer profile fie...

Feb 3, 2026
CVE-2026-1058 7.1

The Form Maker WordPress plugin has a stored XSS vulnerability in versions up to 1.15.35. Unauthenticated attackers can inject malicious JavaScript in...

Feb 3, 2026
CVE-2026-1065 7.2

The Form Maker by 10Web WordPress plugin allows unauthenticated attackers to upload malicious SVG files containing JavaScript code due to weak file ex...

Feb 3, 2026
CVE-2025-9711 N/A

This vulnerability allows local authenticated users on Brocade Fabric OS systems to escalate their privileges to root level using specific commands. I...

Feb 3, 2026
CVE-2026-0950 5.3

The Spectra Gutenberg Blocks plugin for WordPress has an information disclosure vulnerability that allows unauthenticated attackers to read excerpts f...

Feb 3, 2026
CVE-2026-24694 7.8

This vulnerability allows attackers to execute arbitrary code by exploiting insecure DLL loading in Roland Cloud Manager. Attackers can plant maliciou...

Feb 3, 2026
CVE-2025-14274 5.4

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to inject malicious scripts into web pages via the Bor...

Feb 3, 2026
CVE-2025-58381 N/A

This vulnerability in Brocade Fabric OS allows authenticated administrators to abuse shell commands (source, ping6, sleep, disown, wait) to manipulate...

Feb 3, 2026
CVE-2025-58380 N/A

This vulnerability allows authenticated administrators on Brocade Fabric OS to use the 'grep' shell command for directory traversal, potentially acces...

Feb 3, 2026
CVE-2026-0909 5.3

The WP ULike WordPress plugin has an Insecure Direct Object Reference vulnerability that allows authenticated attackers with Subscriber-level access o...

Feb 3, 2026
CVE-2026-1788 N/A

CVE-2026-1788 is an out-of-bounds write vulnerability in Xquic Server's packet processing module that allows attackers to manipulate buffers. This aff...

Feb 3, 2026
CVE-2026-24936 N/A

An unauthenticated remote attacker can write arbitrary data to any file on Asustor ADM systems when a specific function is enabled during AD Domain jo...

Feb 3, 2026
CVE-2026-0383 N/A

This vulnerability in Brocade Fabric OS allows authenticated local attackers with Bash shell access to read insecurely stored file contents, including...

Feb 3, 2026
CVE-2026-24932 N/A

This vulnerability allows attackers to perform Man-in-the-Middle attacks on DDNS update communications by exploiting improper TLS/SSL certificate vali...

Feb 3, 2026
CVE-2026-24933 N/A

This vulnerability allows unauthenticated remote attackers to perform Man-in-the-Middle attacks by intercepting HTTPS communications due to improper S...

Feb 3, 2026
CVE-2026-24934 N/A

This CVE describes an insecure DDNS implementation in ASUSTOR ADM software where HTTP connections lack SSL/TLS certificate validation. Unauthenticated...

Feb 3, 2026
CVE-2026-24935 N/A

This vulnerability allows a Man-in-the-Middle attacker to intercept or redirect NAT tunnel establishment due to improper SSL/TLS certificate validatio...

Feb 3, 2026
CVE-2025-67480 N/A

This vulnerability in MediaWiki's API query revisions base component could allow attackers to access or manipulate revision data improperly. It affect...

Feb 3, 2026
CVE-2025-67481 N/A

This is a cross-site scripting (XSS) vulnerability in MediaWiki's jQueryMsg JavaScript library that allows attackers to inject malicious scripts into ...

Feb 3, 2026
CVE-2025-67482 N/A

This vulnerability in Wikimedia's Scribunto extension and luasandbox library allows attackers to execute arbitrary Lua code within the context of the ...

Feb 3, 2026
CVE-2025-67483 N/A

This CVE describes a cross-site scripting (XSS) vulnerability in MediaWiki's page preview JavaScript component. Attackers can inject malicious scripts...

Feb 3, 2026
CVE-2025-67484 N/A

This vulnerability in MediaWiki's XML API formatting component could allow attackers to execute unauthorized actions or access sensitive data. It affe...

Feb 3, 2026
CVE-2025-61656 N/A

This CVE describes a cross-site scripting (XSS) vulnerability in Wikimedia VisualEditor's clipboard handling component. It allows attackers to inject ...

Feb 3, 2026
CVE-2025-61657 N/A

This is a cross-site scripting (XSS) vulnerability in Wikimedia Foundation's Vector skin that allows attackers to inject malicious scripts into web pa...

Feb 3, 2026
CVE-2025-61658 N/A

This vulnerability in Wikimedia Foundation's CheckUser extension allows unauthorized access to sensitive user contribution data. It affects administra...

Feb 3, 2026
CVE-2025-67475 N/A

This CVE describes a cross-site scripting (XSS) vulnerability in MediaWiki's CommentFormatter/CommentParser.php that allows attackers to inject malici...

Feb 3, 2026
CVE-2025-67476 N/A

This vulnerability in MediaWiki's ImportableOldRevisionImporter.php allows attackers to potentially execute unauthorized actions during content import...

Feb 3, 2026
CVE-2025-67477 N/A

This is a cross-site scripting (XSS) vulnerability in MediaWiki's ApiSandboxLayout.js file that allows attackers to inject malicious scripts into web ...

Feb 3, 2026
CVE-2025-67478 N/A

This vulnerability in Wikimedia Foundation's CheckUser extension allows attackers to potentially execute unauthorized actions through the Mail/UserMai...

Feb 3, 2026
CVE-2025-67479 N/A

This vulnerability in MediaWiki and its Cite extension allows attackers to inject malicious content through parser functions. It affects all MediaWiki...

Feb 3, 2026
CVE-2025-58382 N/A

This vulnerability in Brocade Fabric OS allows authenticated remote attackers with administrative credentials to execute arbitrary commands as root us...

Feb 3, 2026
CVE-2025-58383 N/A

This vulnerability allows administrator-level users on Brocade Fabric OS to execute the bind command, enabling privilege escalation and bypassing secu...

Feb 3, 2026
CVE-2025-61651 N/A

This CVE describes a cross-site scripting (XSS) vulnerability in Wikimedia Foundation's CheckUser extension. Attackers can inject malicious scripts in...

Feb 3, 2026
CVE-2025-61652 N/A

This vulnerability in Wikimedia Foundation DiscussionTools allows attackers to execute unauthorized actions or access restricted functionality. It aff...

Feb 3, 2026
CVE-2025-61653 N/A

This vulnerability in Wikimedia Foundation's TextExtracts extension allows attackers to execute arbitrary code or access sensitive data through improp...

Feb 3, 2026
CVE-2025-61654 N/A

This vulnerability in Wikimedia Foundation's Thanks extension allows attackers to execute unauthorized actions through the ThanksQueryHelper.php file....

Feb 3, 2026
CVE-2025-61655 N/A

This CVE describes a cross-site scripting (XSS) vulnerability in Wikimedia Foundation's VisualEditor component. Attackers can inject malicious scripts...

Feb 3, 2026
CVE-2025-12774 N/A

A vulnerability in Brocade SANnav migration scripts before version 3.0 allows sensitive database information to be captured in support save files. Att...

Feb 3, 2026
CVE-2025-58379 N/A

This vulnerability in Brocade Fabric OS allows local authenticated users with lower privileges to view command line passwords and access sensitive inf...

Feb 3, 2026
CVE-2025-61645 N/A

This is a cross-site scripting (XSS) vulnerability in MediaWiki's CodexTablePager component that allows attackers to inject malicious scripts into web...

Feb 3, 2026