6.5

CVSS3.1

CVE-2025-14980 - BetterDocs <= 4.3.3 - Authenticated (Contributor+) Sensitive Information Exposure

The BetterDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.3 via the scripts() function. This makes it possible for authenticated attackers, with contributor-level access and above, to extract sensitive data including the OpenAI API…

πŸ“… Published: Jan. 9, 2026, 6:34 a.m. πŸ”„ Last Modified: April 22, 2026, 4 p.m.

6.4

CVSS3.1

CVE-2025-15019 - BIALTY - Bulk Image Alt Text (Alt tag, Alt Attribute) with Yoast SEO + WooCommerce <= 2.2.1 - Authe…

The BIALTY - Bulk Image Alt Text (Alt tag, Alt Attribute) with Yoast SEO + WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bialty_cs_alt' post meta in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This mak…

πŸ“… Published: Jan. 9, 2026, 6:34 a.m. πŸ”„ Last Modified: April 22, 2026, 8:15 p.m.

9.8

CVSS3.1

CVE-2025-14736 - Frontend Admin by DynamiApps <= 3.28.29 - Unauthenticated Privilege Escalation to Administrator via…

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.28.29. This is due to insufficient validation of user-supplied role values in the 'validate_value', 'pre_update_value', and 'get_fields_display' functions. This makes …

πŸ“… Published: Jan. 9, 2026, 6:34 a.m. πŸ”„ Last Modified: April 22, 2026, 8:15 p.m.

5.1

CVSS4.0

CVE-2026-20976 - Local Script Execution via Improper Input Validation in Galaxy Store

Improper input validation in Galaxy Store prior to version 4.6.02 allows local attacker to execute arbitrary script.

πŸ“… Published: Jan. 9, 2026, 6:17 a.m. πŸ”„ Last Modified: April 18, 2026, 7:30 p.m.

2.1

CVSS4.0

CVE-2026-20975 - Local Permission Escalation in Samsung Cloud Allows Access to Arbitrary Files

Improper handling of insufficient permission in Samsung Cloud prior to version 5.6.11 allows local attackers to access specific files in arbitrary path.

πŸ“… Published: Jan. 9, 2026, 6:16 a.m. πŸ”„ Last Modified: April 18, 2026, 4:45 p.m.

5.2

CVSS4.0

CVE-2026-20974 - Physical Attack Can Bypass Carrier Lock via Improper Network Restriction Input Validation

Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 allows physical attackers to bypass Carrier Relock.

πŸ“… Published: Jan. 9, 2026, 6:16 a.m. πŸ”„ Last Modified: April 18, 2026, 8 p.m.

5.3

CVSS3.1

CVE-2026-20973 - Out‑of‑Bounds Read in Samsung Android Image Codec Enables Remote Memory Disclosure

Out-of-bounds read in libimagecodec.quram.so prior to SMR Jan-2026 Release 1 allows remote attacker to access out-of-bounds memory.

πŸ“… Published: Jan. 9, 2026, 6:16 a.m. πŸ”„ Last Modified: April 18, 2026, 7:30 p.m.

4.8

CVSS4.0

CVE-2026-20972 - Local Attack Can Enable Ultra Wideband on Samsung Android Devices

Improper Export of Android Application Components in UwbTest prior to SMR Jan-2026 Release 1 allows local attackers to enable UWB.

πŸ“… Published: Jan. 9, 2026, 6:16 a.m. πŸ”„ Last Modified: April 18, 2026, 7:30 a.m.

7.3

CVSS4.0

CVE-2026-20971 - Use After Free in PROCA Driver Enables Local Code Execution

Use After Free in PROCA driver prior to SMR Jan-2026 Release 1 allows local attackers to potentially execute arbitrary code.

πŸ“… Published: Jan. 9, 2026, 6:16 a.m. πŸ”„ Last Modified: April 18, 2026, 8 p.m.

6.8

CVSS4.0

CVE-2026-20970 - Improper Access Control in Samsung Android SLocation Service Enables Local Privilege Escalation

Improper access control in SLocation prior to SMR Jan-2026 Release 1 allows local attackers to execute the privileged APIs.

πŸ“… Published: Jan. 9, 2026, 6:16 a.m. πŸ”„ Last Modified: April 18, 2026, 7:30 p.m.
Total resulsts: 348415
Page 2139 of 34,842
Β« previous page Β» next page
Filters