8.5

CVSS4.0

CVE-2025-14338 - Polkit authentication dis isabled by default in inputplumber

Polkit authentication dis isabled by default and a race condition in the Polkit authorization check in versions before v0.69.0 can lead to the same issues as in CVE-2025-66005.

๐Ÿ“… Published: Jan. 14, 2026, 11:55 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2025-66005 - Lack of Authentication in the InputManager D-Bus interface

Lack of authorization of the InputManager D-Bus interface in InputPlumber versions before v0.63.0 can lead to local Denial-of-Service, information leak or even privilege escalation in the context of the currently active user session.

๐Ÿ“… Published: Jan. 14, 2026, 11:53 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-66169 - Apache Camel Neo4j: Cypher injection vulnerability in Camel-Neo4j component

Cypher Injection vulnerability in Apache Camel camel-neo4j component. This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0 Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0.

๐Ÿ“… Published: Jan. 14, 2026, 11:45 a.m. ๐Ÿ”„ Last Modified: Jan. 16, 2026, 2:29 p.m.

5.1

CVSS4.0

CVE-2025-67859 - Polkit Authorization Check can be Bypassed in the TLP power daemon

A Improper Authentication vulnerability in TLP allows local users to arbitrarily control the power profile in use as well as the daemonโ€™s log settings.This issue affects TLP: from 1.9 before 1.9.1.

๐Ÿ“… Published: Jan. 14, 2026, 11:34 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.9

CVSS3.1

CVE-2025-0647 -

In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a TLBI is issued to the PE, either by the same PE or another PE in the shareability domain. In this case, the PE may retain stale TLB entries which should have been invalidated by tโ€ฆ

๐Ÿ“… Published: Jan. 14, 2026, 10:58 a.m. ๐Ÿ”„ Last Modified: Jan. 26, 2026, 7:40 p.m.

8.6

CVSS3.1

CVE-2026-0532 - External Control of File Name or Path and Server-Side Request Forgery (SSRF) in Kibana Google Geminโ€ฆ

External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file disclosure through a specially crafted credentials JSON payload in the Google Gemini connector configuration. This requires an attacker to have authenticaโ€ฆ

๐Ÿ“… Published: Jan. 14, 2026, 10:14 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 6:30 a.m.

6.5

CVSS3.1

CVE-2026-0529 - Improper Validation of Array Index in Packetbeat Leading to Overflow Buffers

Improper Validation of Array Index (CWE-129) in Packetbeatโ€™s MongoDB protocol parser can allow an attacker to cause Overflow Buffers (CAPEC-100) through specially crafted network traffic. This requires an attacker to send a malformed payload to a monitored network interface where MongoDB protocol pโ€ฆ

๐Ÿ“… Published: Jan. 14, 2026, 10:09 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 6:30 a.m.

10

CVSS3.1

CVE-2026-23550 - WordPress Modular DS plugin <= 2.5.1 - Privilege Escalation vulnerability

Incorrect Privilege Assignment vulnerability in Modular DS Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from n/a through <= 2.5.1.

๐Ÿ“… Published: Jan. 14, 2026, 8:44 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:36 p.m.

5.3

CVSS3.1

CVE-2025-15475 - PayHere Payment Gateway Plugin for WooCommerce <= 2.3.9 - Missing Authorization to Unauthenticated โ€ฆ

The PayHere Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to an improper validation logic in the check_payhere_response function in all versions up to, and including, 2.3.9. This makes it possible for unauthenticated attackers to โ€ฆ

๐Ÿ“… Published: Jan. 14, 2026, 6:40 a.m. ๐Ÿ”„ Last Modified: April 20, 2026, 9:15 p.m.

4.3

CVSS3.1

CVE-2025-15376 - Stopwords for comments <= 1.1 - Missing Authorization to Cross-Site Request Forgery

The Stopwords for comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing nonce validation on the 'set_stopwords_for_comments' and 'delete_stopwords_for_comments' functions. This makes it possible for unauthenticateโ€ฆ

๐Ÿ“… Published: Jan. 14, 2026, 6:40 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 12:30 a.m.
Total resulsts: 349182
Page 2131 of 34,919
ยซ previous page ยป next page
Filters