Posts

Showing posts from January, 2026

CVE-2025-15497 - OpenVPN Epoch Key Slot Processing Denial of Service

CVE ID : CVE-2025-15497 Published : Jan. 30, 2026, 6:15 p.m. | 1 hour, 24 minutes ago Description : Insufficient epoch key slot processing in OpenVPN 2.7_alpha1 through 2.7_rc5 allows remote authenticated users to trigger an assert resulting in a denial of service Severity: 3.8 | LOW

CVE-2025-62514 - `libparsec_crypto` does not check for weak order point of curve 25519

CVE ID : CVE-2025-62514 Published : Jan. 29, 2026, 4:16 p.m. | 1 hour, 30 minutes ago Description : Parsec is a cloud-based application for cryptographically secure file sharing. In versions on the 3.x branch prior to 3.6.0, `libparsec_crypto`, a component of the Parsec application, does not check for weak order point of Curve25519 when compiled with its RustCrypto backend. In practice this means an attacker in a man-in-the-middle position would be able to provide weak order points to both parties in the Diffie-Hellman exchange, resulting in a high probability to for both parties to obtain the same shared key (hence leading to a successful SAS code exchange, misleading both parties into thinking no MITM has occurred) which is also known by the attacker. Note only Parsec web is impacted (as Parsec desktop uses `libparsec_crypto` with the libsodium backend). Version 3.6.0 of Parsec patches the issue. Severity: 8.3 | HIGH

CVE-2025-57283 - Browserstack Local Command Injection Vulnerability

CVE ID : CVE-2025-57283 Published : Jan. 28, 2026, 4:16 p.m. | 1 hour, 14 minutes ago Description : The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability. This occurs because the logfile variable is not properly sanitized in lib/Local.js.

CVE-2026-24831 - Infinite loop (DoS) in ixray-1.6-stcop

CVE ID : CVE-2026-24831 Published : Jan. 27, 2026, 4:16 p.m. | 58 minutes ago Description : Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3. Severity: 7.5 | HIGH

CVE-2020-36956 - Openfire 4.6.0 - 'path' Stored XSS

CVE ID : CVE-2020-36956 Published : Jan. 26, 2026, 6:16 p.m. | 1 hour, 3 minutes ago Description : Openfire 4.6.0 contains a stored cross-site scripting vulnerability in the nodejs plugin that allows attackers to inject malicious scripts through the 'path' parameter. Attackers can craft a payload with script tags to execute arbitrary JavaScript in the context of administrative users viewing the nodejs configuration page. Severity: 6.4 | MEDIUM

CVE-2026-1410 - Beetel 777VR1 UART missing authentication

CVE ID : CVE-2026-1410 Published : Jan. 26, 2026, 12:02 a.m. | 1 hour, 14 minutes ago Description : A vulnerability was detected in Beetel 777VR1 up to 01.00.09/01.00.09_55. Impacted is an unknown function of the component UART Interface. The manipulation results in missing authentication. An attack on the physical device is feasible. This attack is characterized by high complexity. The exploitability is considered difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-1407 - Beetel 777VR1 UART information disclosure

CVE ID : CVE-2026-1407 Published : Jan. 25, 2026, 10:16 p.m. | 1 hour ago Description : A security flaw has been discovered in Beetel 777VR1 up to 01.00.09/01.00.09_55. This affects an unknown part of the component UART Interface. Performing a manipulation results in information disclosure. The attack may be carried out on the physical device. The attack is considered to have high complexity. It is indicated that the exploitability is difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 2.0 | LOW

CVE-2026-1406 - lcg0124 BootDo Host Header AccessControlFilter.java redirectToLogin

CVE ID : CVE-2026-1406 Published : Jan. 25, 2026, 12:15 p.m. | 59 minutes ago Description : A vulnerability was determined in lcg0124 BootDo up to 5ccd963c74058036b466e038cff37de4056c1600. Affected by this vulnerability is the function redirectToLogin of the file AccessControlFilter.java of the component Host Header Handler. This manipulation of the argument Hostname causes open redirect. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. Severity: 5.1 | MEDIUM

Swiftbuy V 1.0 | /login.php - No Limit To Authentication Attempts To Admin Login

Image
Hi all, I am Maloy Roy Orko . Recently,in one of my pentest research,I found a web application project and it was SwiftBuy — a modern PHP + MySQL e-commerce website featuring user and admin dashboards, product management, cart system, checkout, and real-time sales analytics. Built with HTML, CSS, JavaScript, Tailwind CSS, and Chart.js. by MD Tasin Rahman (Software Engineer) So,I downloaded this and started to find vulnerabilities if it has. CVE Number : In Review After fiddling with the source code, I found that the admin/login.php file is vulnerable to CWE-307: Improper Restriction of Excessive Authentication Attempts. It can lead into: - Unauthorized Data Access - Account Takeover - Privilege Escalation - Denial of Service (DoS) - Reputation Damage - Regulatory Consequences The Main Thing Is,If any NON-IT personal uses this template,he will fall into this vulnerability and his companies reputation can be lost too. Thats why, I am trying to inform everyone about this. Title of the Vu...

CVE-2022-25369 - Dynamicweb Unauthenticated Remote Command Execution

CVE ID : CVE-2022-25369 Published : Jan. 23, 2026, 5:16 p.m. | 1 hour, 53 minutes ago Description : An issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authentication. This flaw exists due to a logic issue when determining if the setup phases of the product can be run again. Once an attacker is authenticated as the new admin user they have added, it is possible to upload an executable file and achieve command execution. This is fixed in 9.5.9, 9.6.16, 9.7.8, 9.8.11, 9.9.8, 9.10.18, 9.12.8, and 9.13.0 (and later).

CVE-2021-47863 - MacPaw Encrypto 1.0.1 - 'Encrypto Service' Unquoted Service Path

CVE ID : CVE-2021-47863 Published : Jan. 21, 2026, 5:27 p.m. | 24 minutes ago Description : MacPaw Encrypto 1.0.1 contains an unquoted service path vulnerability in its Encrypto Service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files\Encrypto\ to inject malicious executables and escalate privileges on Windows systems. Severity: 8.5 | HIGH

CVE-2025-14883 - Apache HTTP Server Remote Code Execution

CVE ID : CVE-2025-14883 Published : Jan. 20, 2026, 4:16 p.m. | 38 minutes ago Description : Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-68016. Reason: This candidate is a reservation duplicate of CVE-2025-68016. Notes: All CVE users should reference CVE-2025-68016 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. Severity: 0.0 | NA

CVE-2025-11043 - Improper Server Certificate Validation in Automation Studio

CVE ID : CVE-2025-11043 Published : Jan. 19, 2026, 4:15 p.m. | 1 hour, 30 minutes ago Description : An Improper Certificate Validation vulnerability in the OPC-UA client and ANSL over TLS client used in Automation Studio versions before 6.5 could allow an unauthenticated attacker on the network to position themselves to intercept and interfere with data exchanges. Severity: 7.4 | HIGH

CVE-2026-0863 - Sandbox escape in n8n Python task runner allows for arbitrary code execution on the underlying host.

CVE ID : CVE-2026-0863 Published : Jan. 18, 2026, 4:15 p.m. | 1 hour, 28 minutes ago Description : Using string formatting and exception handling, an attacker may bypass n8n's python-task-executor sandbox restrictions and run arbitrary unrestricted Python code in the underlying operating system. The vulnerability can be exploited via the Code block by an authenticated user with basic permissions and can lead to a full n8n instance takeover on instances operating under "Internal" execution mode. If the instance is operating under the "External" execution mode (ex. n8n's official Docker image) - arbitrary code execution occurs inside a Sidecar container and not the main node, which significantly reduces the vulnerability impact. Severity: 8.5 | HIGH

CVE-2026-1049 - LigeroSmart index.pl cross site scripting

CVE ID : CVE-2026-1049 Published : Jan. 17, 2026, 6:15 p.m. | 1 hour, 24 minutes ago Description : A security vulnerability has been detected in LigeroSmart up to 6.1.26. The affected element is an unknown function of the file /otrs/index.pl. Such manipulation of the argument TicketID leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. Severity: 5.1 | MEDIUM

CVE-2025-15531 - Open5GS context.c sgwc_bearer_add assertion

CVE ID : CVE-2025-15531 Published : Jan. 17, 2026, 4:16 p.m. | 1 hour, 24 minutes ago Description : A vulnerability was identified in Open5GS up to 2.7.5. This vulnerability affects the function sgwc_bearer_add of the file src/sgwc/context.c. The manipulation leads to reachable assertion. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The issue report is flagged as already-fixed. Severity: 5.5 | MEDIUM

CVE-2025-29943 - AMD CPU Pipeline Configuration Corruption Vulnerability

CVE ID : CVE-2025-29943 Published : Jan. 16, 2026, 4:15 p.m. | 1 hour, 22 minutes ago Description : Write what were condition within AMD CPUs may allow an admin-privileged attacker to modify the configuration of the CPU pipeline potentially resulting in the corruption of the stack pointer inside an SEV-SNP guest. Severity: 4.6 | MEDIUM

CVE-2025-64516 - GLPI incorrectly authorizes access to documents

CVE ID : CVE-2025-64516 Published : Jan. 15, 2026, 4:16 p.m. | 1 hour, 18 minutes ago Description : GLPI is a free asset and IT management software package. Prior to 10.0.21 and 11.0.3, an unauthorized user can access GLPI documents attached to any item (ticket, asset, ...). If the public FAQ is enabled, this unauthorized access can be performed by an anonymous user. This vulnerability is fixed in 10.0.21 and 11.0.3. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/CGlYgwH via IFTTT

CVE-2025-37181 - Authenticated SQL Injection in EdgeConnect SD-WAN Orchestrator Web-Based Management Interface

CVE ID : CVE-2025-37181 Published : Jan. 14, 2026, 5:16 p.m. | 49 minutes ago Description : Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially leading to unauthorized data access or data manipulation. Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/rkl2tpi via IFTTT

CVE-2025-71099 - drm/xe/oa: Fix potential UAF in xe_oa_add_config_ioctl()

CVE ID : CVE-2025-71099 Published : Jan. 13, 2026, 4:16 p.m. | 1 hour, 16 minutes ago Description : In the Linux kernel, the following vulnerability has been resolved: drm/xe/oa: Fix potential UAF in xe_oa_add_config_ioctl() In xe_oa_add_config_ioctl(), we accessed oa_config->id after dropping metrics_lock. Since this lock protects the lifetime of oa_config, an attacker could guess the id and call xe_oa_remove_config_ioctl() with perfect timing, freeing oa_config before we dereference it, leading to a potential use-after-free. Fix this by caching the id in a local variable while holding the lock. v2: (Matt A) - Dropped mutex_unlock(&oa->metrics_lock) ordering change from xe_oa_remove_config_ioctl() (cherry picked from commit 28aeaed130e8e587fd1b73b6d66ca41ccc5a1a31) Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/6Rg7vVK via IFTTT

CVE-2025-66939 - AltumCode 66biolinks Cross-Site Scripting (XSS)

CVE ID : CVE-2025-66939 Published : Jan. 12, 2026, 4:16 p.m. | 1 hour, 16 minutes ago Description : Cross Site Scripting vulnerability in 66biolinks by AltumCode v.61.0.1 allows an attacker to execute arbitrary code via a crafted favicon file Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/WIGp1Ow via IFTTT

CVE-2025-52694 - Execution of arbitrary SQL commands

CVE ID : CVE-2025-52694 Published : Jan. 12, 2026, 3:16 a.m. | 16 minutes ago Description : Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet. Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/UhKDBVC via IFTTT

CVE-2026-0838 - UTT 进取 520W ConfigWirelessBase strcpy buffer overflow

CVE ID : CVE-2026-0838 Published : Jan. 11, 2026, 6:15 a.m. | 1 hour, 14 minutes ago Description : A security flaw has been discovered in UTT 进取 520W 1.7.7-180627. This impacts the function strcpy of the file /goform/ConfigWirelessBase. Performing a manipulation of the argument ssid results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/v3it7Y6 via IFTTT

CVE-2026-0836 - UTT 进取 520W formConfigFastDirectionW strcpy buffer overflow

CVE ID : CVE-2026-0836 Published : Jan. 11, 2026, 4:32 a.m. | 57 minutes ago Description : A vulnerability was determined in UTT 进取 520W 1.7.7-180627. The impacted element is the function strcpy of the file /goform/formConfigFastDirectionW. This manipulation of the argument ssid causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/R4Mjy1Q via IFTTT

CVE-2025-15505 - Luxul XWR-600 Web Administration cross site scripting

CVE ID : CVE-2025-15505 Published : Jan. 11, 2026, 2:15 a.m. | 1 hour, 14 minutes ago Description : A vulnerability was found in Luxul XWR-600 up to 4.0.1. The affected element is an unknown function of the component Web Administration Interface. The manipulation of the argument Guest Network/Wireless Profile SSID results in cross site scripting. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond with a technical statement. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/qTJjdby via IFTTT

CVE-2025-67278 - TIM Solution GmbH TIM BPM Suite & TIM FLOW Remote Privilege Escalation Vulnerability

CVE ID : CVE-2025-67278 Published : Jan. 9, 2026, 4:16 p.m. | 1 hour, 15 minutes ago Description : An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges via a crafted HTTP request Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/EubaxF0 via IFTTT

CVE-2025-56424 - Insiders Technologies GmbH e-invoice pro Denial of Service

CVE ID : CVE-2025-56424 Published : Jan. 8, 2026, 5:15 p.m. | 15 minutes ago Description : An issue in Insiders Technologies GmbH e-invoice pro before release 1 Service Pack 2 allows a remote attacker to cause a denial of service via a crafted script Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/EbT3fvM via IFTTT

CVE-2026-21505 - iccDEV has Undefined Behavior (UB) - Invalid Enum Value

CVE ID : CVE-2026-21505 Published : Jan. 7, 2026, 5:10 p.m. | 20 minutes ago Description : iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV has undefined behavior due to an invalid enum value. This issue has been patched in version 2.3.1.2. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/dIks6FM via IFTTT

CVE-2025-15382 - Client SCP Request Triggers Buffer Overread by 1 Byte

CVE ID : CVE-2025-15382 Published : Jan. 6, 2026, 6:15 p.m. | 1 hour, 15 minutes ago Description : A heap buffer over-read vulnerability exists in the wolfSSH_CleanPath() function in wolfSSH. An authenticated remote attacker can trigger the issue via crafted SCP path input containing '/./' sequences, resulting in a heap over read by 1 byte. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/ijbmQDs via IFTTT

CVE-2025-55204 - muffon has One-click Remote Code Execution via XSS and Custom URL Handling

CVE ID : CVE-2025-55204 Published : Jan. 5, 2026, 6:15 p.m. | 1 hour, 14 minutes ago Description : muffon is a cross-platform music streaming client for desktop. Versions prior to 2.3.0 have a one-click Remote Code Execution (RCE) vulnerability in. An attacker can exploit this issue by embedding a specially crafted `muffon://` link on any website they control. When a victim visits the site or clicks the link, the browser triggers Muffon’s custom URL handler, causing the application to launch and process the URL. This leads to RCE on the victim's machine without further interaction. Version 2.3.0 patches the issue. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/MkitWsx via IFTTT

CVE-2025-15447 - Seeyon Zhiyuan OA Web Application System assetsService.j%73p sql injection

CVE ID : CVE-2025-15447 Published : Jan. 5, 2026, 12:15 a.m. | 1 hour, 14 minutes ago Description : A vulnerability has been found in Seeyon Zhiyuan OA Web Application System up to 20251223. This affects an unknown function of the file /assetsGroupReport/assetsService.j%73p. The manipulation of the argument unitCode leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/XS7irbH via IFTTT

CVE-2025-15446 - Seeyon Zhiyuan OA Web Application System fixedAssetsList.j%73p sql injection

CVE ID : CVE-2025-15446 Published : Jan. 4, 2026, 11:15 p.m. | 14 minutes ago Description : A flaw has been found in Seeyon Zhiyuan OA Web Application System up to 20251223. The impacted element is an unknown function of the file /assetsGroupReport/fixedAssetsList.j%73p. Executing a manipulation of the argument unitCode can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/QjLabxk via IFTTT

CVE-2025-15115 - Petlibro Smart Pet Feeder Platform through 1.7.31 Authentication Bypass via API endpoint

CVE ID : CVE-2025-15115 Published : Jan. 4, 2026, 12:15 a.m. | 1 hour, 14 minutes ago Description : Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authentication bypass vulnerability that allows unauthenticated attackers to access any user account by exploiting OAuth token validation flaws in the social login system. Attackers can send requests to /member/auth/thirdLogin with arbitrary Google IDs and phoneBrand parameters to obtain full session tokens and account access without proper OAuth verification. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/38uVpPH via IFTTT

CVE-2025-65125 - Gosaliajainam Online-Movie-Booking SQL Injection Vulnerability

CVE ID : CVE-2025-65125 Published : Jan. 2, 2026, 3:16 p.m. | 2 hours, 13 minutes ago Description : SQL injection in gosaliajainam/online-movie-booking 5.5 in movie_details.php allows attackers to gain sensitive information. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/6vpEfbL via IFTTT

CVE-2025-48768 - Apache NuttX RTOS: fs/inode: fs_inoderemove root inode removal

CVE ID : CVE-2025-48768 Published : Jan. 1, 2026, 4:14 p.m. | 1 hour, 13 minutes ago Description : Release of Invalid Pointer or Reference vulnerability was discovered in fs/inode/fs_inoderemove code of the Apache NuttX RTOS that allowed root filesystem inode removal leading to a debug assert trigger (that is disabled by default), NULL pointer dereference (handled differently depending on the target architecture), or in general, a Denial of Service. This issue affects Apache NuttX RTOS: from 10.0.0 before 12.10.0. Users of filesystem based services with write access that were exposed over the network (i.e. FTP) are affected and recommended to upgrade to version 12.10.0 that fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/TnfWjhS via IFTTT