8.1

CVSS3.1

CVE-2025-47411 - Apache StreamPipes: Leverage of User ID for Privilege Escalation

A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows them to swap the username of an existing user with that of an administrator.  This vulnerability allows an attacker to gain administrative control over…

📅 Published: Jan. 1, 2026, 4:41 p.m. 🔄 Last Modified: Jan. 6, 2026, 2:40 p.m.

6.4

CVSS3.1

CVE-2025-14627 - WP Import – Ultimate CSV XML Importer for WordPress <= 7.35 - Authenticated (Contributor+) Server-S…

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.35. This is due to inadequate validation of the resolved URL after following Bitly shortlink redirects in the `upload_function()` method.…

📅 Published: Jan. 1, 2026, 4:19 p.m. 🔄 Last Modified: April 8, 2026, 5:04 p.m.

4.3

CVSS3.1

CVE-2025-14428 - My Sticky Elements <= 2.3.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Bulk L…

The All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs - My Sticky Elements plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'my_sticky_elements_bulks' function in all versions up to, and including, 2.3.3. This…

📅 Published: Jan. 1, 2026, 4:19 p.m. 🔄 Last Modified: April 8, 2026, 4:38 p.m.

5.3

CVSS3.1

CVE-2025-48769 - Apache NuttX RTOS: fs/vfs/fs_rename: use after free

Use After Free vulnerability was discovered in fs/vfs/fs_rename code of the Apache NuttX RTOS, that due recursive implementation and single buffer use by two different pointer variables allowed arbitrary user provided size buffer reallocation and write to the previously freed heap chunk, that in sp…

📅 Published: Jan. 1, 2026, 4:14 p.m. 🔄 Last Modified: Jan. 6, 2026, 2:35 p.m.

5.3

CVSS3.1

CVE-2025-48768 - Apache NuttX RTOS: fs/inode: fs_inoderemove root inode removal

Release of Invalid Pointer or Reference vulnerability was discovered in fs/inode/fs_inoderemove code of the Apache NuttX RTOS that allowed root filesystem inode removal leading to a debug assert trigger (that is disabled by default), NULL pointer dereference (handled differently depending on the ta…

📅 Published: Jan. 1, 2026, 4:14 p.m. 🔄 Last Modified: Jan. 6, 2026, 2:39 p.m.

6.9

CVSS4.0

CVE-2025-66023 - NanoMQ has Use-After-Free of malformed bridging message

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.5 have a Heap-Use-After-Free (UAF) vulnerability within the MQTT bridge client component (implemented via the underlying NanoNNG library). The vulnerability is triggered when NanoMQ acts as a bridge connect…

📅 Published: Jan. 1, 2026, 3:11 p.m. 🔄 Last Modified: Feb. 18, 2026, 4:34 p.m.

5.3

CVSS4.0

CVE-2025-15405 - PHPEMS cross-site request forgery

A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function. The manipulation results in cross-site request forgery. The attack may be launched remotely.

📅 Published: Jan. 1, 2026, 3:02 p.m. 🔄 Last Modified: Feb. 23, 2026, 8:01 a.m.

5.3

CVSS4.0

CVE-2025-15404 - campcodes School File Management System save_file.php unrestricted upload

A security vulnerability has been detected in campcodes School File Management System 1.0. The affected element is an unknown function of the file /save_file.php. The manipulation of the argument File leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed…

📅 Published: Jan. 1, 2026, 1:32 p.m. 🔄 Last Modified: Feb. 23, 2026, 8:01 a.m.

6.9

CVSS4.0

CVE-2026-0544 - itsourcecode School Management System index.php sql injection

A security flaw has been discovered in itsourcecode School Management System 1.0. This affects an unknown part of the file /student/index.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and …

📅 Published: Jan. 1, 2026, 9:02 a.m. 🔄 Last Modified: Feb. 23, 2026, 8:03 a.m.

7.8

CVSS3.1

CVE-2025-11157 - Arbitrary Code Execution in feast-dev/feast

A high-severity remote code execution vulnerability exists in feast-dev/feast version 0.53.0, specifically in the Kubernetes materializer job located at `feast/sdk/python/feast/infra/compute_engines/kubernetes/main.py`. The vulnerability arises from the use of `yaml.load(..., Loader=yaml.Loader)` t…

📅 Published: Jan. 1, 2026, 7:03 a.m. 🔄 Last Modified: Jan. 5, 2026, 7:59 p.m.
Total resulsts: 343970
Page 1794 of 34,397
« previous page » next page
Filters