7.5

CVSS3.1

CVE-2025-52435 - Apache Mynewt NimBLE: Invalid error handling in pause encryption procedure in NimBLE controller

J2EE Misconfiguration: Data Transmission Without Encryption vulnerability in Apache NimBLE. Improper handling of Pause Encryption procedure on Link Layer results in a previously encrypted connection being left in un-encrypted state allowing an eavesdropper to observe the remainder of the exchange.…

📅 Published: Jan. 10, 2026, 9:47 a.m. 🔄 Last Modified: Jan. 12, 2026, 7:07 p.m.

0.0

CVE-2025-53470 - Apache Mynewt NimBLE: Out-of-Bounds Write Vulnerability in NimBLE HCI H4 driver

Out-of-bounds Read vulnerability in Apache NimBLE HCI H4 driver. Specially crafted HCI event could lead to invalid memory read in H4 driver. This issue affects Apache NimBLE: through 1.8.  This issue requires a broken or bogus Bluetooth controller and thus severity is considered low. Users are …

📅 Published: Jan. 10, 2026, 9:46 a.m. 🔄 Last Modified: Jan. 12, 2026, 7:12 p.m.

7.5

CVSS3.1

CVE-2025-53477 - Apache Mynewt NimBLE: NULL Pointer Dereference in NimBLE host HCI layer

NULL Pointer Dereference vulnerability in Apache Nimble. Missing validation of HCI connection complete or HCI command TX buffer could lead to NULL pointer dereference. This issue requires disabled asserts and broken or bogus Bluetooth controller and thus severity is considered low. This issue aff…

📅 Published: Jan. 10, 2026, 9:45 a.m. 🔄 Last Modified: Jan. 12, 2026, 4:54 p.m.

0.0

CVE-2025-62235 - Apache Mynewt NimBLE: Incorrect handling of SMP Security Request could lead to undesirable pairing

Authentication Bypass by Spoofing vulnerability in Apache NimBLE. Receiving specially crafted Security Request could lead to removal of original bond and re-bond with impostor. This issue affects Apache NimBLE: through 1.8.0. Users are recommended to upgrade to version 1.9.0, which fixes the issu…

📅 Published: Jan. 10, 2026, 9:42 a.m. 🔄 Last Modified: Jan. 12, 2026, 4:45 p.m.

5.3

CVSS3.1

CVE-2026-0831 - Templately <= 3.4.8 - Unauthenticated Limited Arbitrary JSON File Write

The Templately plugin for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 3.4.8. This is due to inadequate input validation in the `save_template_to_file()` function where user-controlled parameters like `session_id`, `content_id`, and `ai_page_ids` are used to…

📅 Published: Jan. 10, 2026, 9:22 a.m. 🔄 Last Modified: Jan. 10, 2026, 9:22 a.m.

6.9

CVSS4.0

CVE-2025-15503 - Sangfor Operation and Maintenance Management System common.jsp unrestricted upload

A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted element is an unknown function of the file /fort/trust/version/common/common.jsp. Performing a manipulation of the argument File results in unrestricted upload. The attack is possibl…

📅 Published: Jan. 10, 2026, 9:02 a.m. 🔄 Last Modified: Jan. 10, 2026, 9:02 a.m.

5.4

CVSS3.1

CVE-2025-14976 - User Registration & Membership <= 4.4.8 - Cross-Site Request Forgery to Arbitrary Post Deletion

The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.4.8. This is due to missing or incorrect nonce val…

📅 Published: Jan. 10, 2026, 8:22 a.m. 🔄 Last Modified: Jan. 10, 2026, 8:22 a.m.

6.9

CVSS4.0

CVE-2025-15502 - Sangfor Operation and Maintenance Management System session SessionController os command injection

A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.8. The affected element is the function SessionController of the file /isomp-protocol/protocol/session. Such manipulation of the argument Hostname leads to os command injection. The attack can be execute…

📅 Published: Jan. 10, 2026, 8:02 a.m. 🔄 Last Modified: Jan. 12, 2026, 2:38 p.m.

5.3

CVSS3.1

CVE-2025-14948 - miniOrange OTP Verification and SMS Notification for WooCommerce <= 4.3.8 - Missing Authorization t…

The miniOrange OTP Verification and SMS Notification for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `enable_wc_sms_notification` AJAX action in all versions up to, and including, 4.3.8. This makes it possible for unau…

📅 Published: Jan. 10, 2026, 7:03 a.m. 🔄 Last Modified: Jan. 10, 2026, 7:03 a.m.

7.5

CVSS3.1

CVE-2026-22777 - ComfyUI-Manager is Vulnerable to CRLF Injection in Configuration Handler

ComfyUI-Manager is an extension designed to enhance the usability of ComfyUI. Prior to versions 3.39.2 and 4.0.5, an attacker can inject special characters into HTTP query parameters to add arbitrary configuration values to the config.ini file. This can lead to security setting tampering or modific…

📅 Published: Jan. 10, 2026, 6:43 a.m. 🔄 Last Modified: Jan. 10, 2026, 6:43 a.m.
Total resulsts: 327160
Page 18 of 32,716
« previous page » next page
Filters