5.3

CVSS3.1

CVE-2026-20973 -

Out-of-bounds read in libimagecodec.quram.so prior to SMR Jan-2026 Release 1 allows remote attacker to access out-of-bounds memory.

πŸ“… Published: Jan. 9, 2026, 6:16 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 7:09 p.m.

4.8

CVSS4.0

CVE-2026-20972 -

Improper Export of Android Application Components in UwbTest prior to SMR Jan-2026 Release 1 allows local attackers to enable UWB.

πŸ“… Published: Jan. 9, 2026, 6:16 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 7:18 p.m.

7.3

CVSS4.0

CVE-2026-20971 -

Use After Free in PROCA driver prior to SMR Jan-2026 Release 1 allows local attackers to potentially execute arbitrary code.

πŸ“… Published: Jan. 9, 2026, 6:16 a.m. πŸ”„ Last Modified: Jan. 10, 2026, 4:55 a.m.

6.8

CVSS4.0

CVE-2026-20970 -

Improper access control in SLocation prior to SMR Jan-2026 Release 1 allows local attackers to execute the privileged APIs.

πŸ“… Published: Jan. 9, 2026, 6:16 a.m. πŸ”„ Last Modified: Jan. 10, 2026, 4:55 a.m.

2.3

CVSS4.0

CVE-2026-20969 -

Improper input validation in SecSettings prior to SMR Jan-2026 Release 1 allows local attacker to access file with system privilege. User interaction is required for triggering this vulnerability.

πŸ“… Published: Jan. 9, 2026, 6:15 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 7:18 p.m.

6.7

CVSS4.0

CVE-2026-20968 -

Use after free in DualDAR prior to SMR Jan-2026 Release 1 allows local privileged attackers to execute arbitrary code.

πŸ“… Published: Jan. 9, 2026, 6:15 a.m. πŸ”„ Last Modified: Jan. 10, 2026, 4:55 a.m.

6.8

CVSS3.1

CVE-2025-14803 - Nex-Forms Express WP Form Builder < 9.1.8 - Authenticated Stored XSS

The NEX-Forms WordPress plugin before 9.1.8 does not sanitise and escape some of its settings. The NEX-Forms WordPress plugin before 9.1.8 can be configured in such a way that could allow subscribers to perform Stored Cross-Site Scripting.

πŸ“… Published: Jan. 9, 2026, 6 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 4:16 p.m.

4.3

CVSS3.1

CVE-2025-13749 - Clearfy <= 2.4.0 - Cross-Site Request Forgery to Update Notification Tampering

The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.0. This is due to missing nonce validation on the "wbcr_upm_change_flag" function. This makes it possible for un…

πŸ“… Published: Jan. 9, 2026, 5:25 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 6:25 p.m.

5.3

CVSS3.1

CVE-2025-14886 - Japanized for WooCommerce <= 2.7.17 - Missing Authorization to Unauthenticated Order Status Modific…

The Japanized for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `order` REST API endpoint in all versions up to, and including, 2.7.17. This makes it possible for unauthenticated attackers to mark any WooCommerce order a…

πŸ“… Published: Jan. 9, 2026, 4:31 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 6:17 p.m.

4.3

CVSS3.1

CVE-2025-66315 - ZTE MF258K Pro Version Server has a Configuration Defect Vulnerability

There is a configuration defect vulnerability in the version server of ZTE MF258K Pro products. Due to improper directory permission settings, an attacker can execute write permissions in a specific directory.

πŸ“… Published: Jan. 9, 2026, 2:24 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 2:24 a.m.
Total resulsts: 327160
Page 34 of 32,716
Β« previous page Β» next page
Filters