5.3

CVSS3.1

CVE-2026-22911 -

Firmware update files may expose password hashes for system accounts, which could allow a remote attacker to recover credentials and gain unauthorized access to the device.

πŸ“… Published: Jan. 15, 2026, 1:02 p.m. πŸ”„ Last Modified: Jan. 23, 2026, 3:35 p.m.

7.5

CVSS3.1

CVE-2026-22910 -

The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized access. This represents a high risk to the integrity of the system.

πŸ“… Published: Jan. 15, 2026, 1:02 p.m. πŸ”„ Last Modified: Jan. 23, 2026, 3:45 p.m.

7.5

CVSS3.1

CVE-2026-22909 -

Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete installed applications, potentially disrupting system operations.

πŸ“… Published: Jan. 15, 2026, 1:01 p.m. πŸ”„ Last Modified: Jan. 23, 2026, 3:46 p.m.

9.1

CVSS3.1

CVE-2026-22908 -

Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially compromising its integrity and confidentiality.

πŸ“… Published: Jan. 15, 2026, 1 p.m. πŸ”„ Last Modified: Jan. 23, 2026, 3:46 p.m.

9.9

CVSS3.1

CVE-2026-22907 -

An attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system data.

πŸ“… Published: Jan. 15, 2026, 12:59 p.m. πŸ”„ Last Modified: Jan. 23, 2026, 3:49 p.m.

3.7

CVSS3.1

CVE-2025-14457 - Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.2 - Missing Authorization to Unauthe…

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ownership check in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.9.2. This makes it possible for unauthenticated …

πŸ“… Published: Jan. 15, 2026, 6:45 a.m. πŸ”„ Last Modified: Jan. 23, 2026, 3:56 p.m.

5.4

CVSS3.1

CVE-2025-14448 - WP-Members Membership Plugin <= 3.5.4.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting v…

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Multiple Checkbox and Multiple Select user profile fields in all versions up to, and including, 3.5.4.3 due to insufficient input sanitization and output escaping. This makes it possible for a…

πŸ“… Published: Jan. 15, 2026, 5:24 a.m. πŸ”„ Last Modified: Jan. 23, 2026, 4:06 p.m.

5.5

CVSS3.1

CVE-2025-70310 -

A heap overflow in the vorbis_to_intern() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .ogg file.

πŸ“… Published: Jan. 15, 2026, midnight πŸ”„ Last Modified: Jan. 23, 2026, 5:34 p.m.

9.4

CVSS3.1

CVE-2025-67822 -

A vulnerability in the Provisioning Manager component of Mitel MiVoice MX-ONE 7.3 (7.3.0.0.50) through 7.8 SP1 (7.8.1.0.14) could allow an unauthenticated attacker to conduct an authentication bypass attack due to improper authentication mechanisms. A successful exploit could allow an attacker to g…

πŸ“… Published: Jan. 15, 2026, midnight πŸ”„ Last Modified: Jan. 21, 2026, 9:06 p.m.

9.9

CVSS3.1

CVE-2025-67084 -

File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which can later be executed remotely, leading to Remote Code Execution (RCE).

πŸ“… Published: Jan. 15, 2026, midnight πŸ”„ Last Modified: Jan. 22, 2026, 4:03 p.m.
Total resulsts: 330542
Page 269 of 33,055
Β« previous page Β» next page
Filters