Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-0019

In SettingsLib, there is a possible way to disable system components due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0018

In multiple functions of AccessibilityManagerService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0017

In onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0016

In updateProvidersWhenServiceRemoved of CredentialManagerService.java, there is a possible way to override settings across users due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
LOW
Conflicts
1

CVE-2026-0015

In multiple locations of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0014

In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0013

In setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0012

In setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0011

In enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0010

In onTransact of IDrmManagerService.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0009

In multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0008

In multiple locations, there is a possible privilege escalation due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0007

In writeToParcel of WindowInfo.cpp, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0006

In multiple locations, there is a possible out of bounds read and write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
CRITICAL
Conflicts
1

CVE-2026-0005

In onServiceDisconnected of KeyguardServiceDelegate.java, there is a possible partial bypass of app pinning allowing limited interaction with other apps without knowing the LSKF due to a missing permission check. This could lead to local information disclosure where the extent of interaction and impact is app-dependent with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
MEDIUM
Conflicts
1

CVE-2025-9999

Some payload elements of the messages sent between two stations in a networking architecture are not properly checked on the receiving station allowing an attacker to execute unauthorized commands in the application.

PUBLISHED
Vendor
arcinfo
Product
PcVue
Provider severity
HIGH
Conflicts
1

CVE-2025-9998

The sequence of packets received by a Networking server are not correctly checked. An attacker could exploit this vulnerability to send specially crafted messages to force the application to stop.

PUBLISHED
Vendor
arcinfo
Product
PcVue
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9997

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause command injection in BLMon that is executed in the operating system console when in a SSH session.

PUBLISHED
Vendor
Schneider Electric, Schneider Electric
Product
Saitel DP RTU, Saitel DR RTU
Provider severity
MEDIUM
Conflicts
1

CVE-2025-9996

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause the execution of any shell command when executing a netstat command using BLMon Console in an SSH session.

PUBLISHED
Vendor
Schneider Electric, Schneider Electric
Product
Saitel DP RTU, Saitel DR RTU
Provider severity
MEDIUM
Conflicts
1

CVE-2025-9994

The Amp’ed RF BT-AP 111 Bluetooth access point's HTTP admin interface does not have an authentication feature, allowing unauthorized access to anyone with network access.

PUBLISHED
Vendor
Amped RF
Product
BT-AP 111
Provider severity
CRITICAL
Conflicts
1

CVE-2025-9993

The Bei Fen – WordPress Backup Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.2 via the 'task'. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be upload

PUBLISHED
Vendor
d3rd4v1d
Product
Bei Fen – WordPress Backup Plugin
Provider severity
HIGH
Conflicts
0

CVE-2025-9992

The Ghost Kit – Page Builder Blocks, Motion Effects & Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS field in all versions up to, and including, 3.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
nko
Product
Ghost Kit – Page Builder Blocks, Motion Effects & Extensions
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9991

The Tiny Bootstrap Elements Light plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.3.34 via the 'language' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.

PUBLISHED
Vendor
migli
Product
Tiny Bootstrap Elements Light
Provider severity
HIGH
Conflicts
0

CVE-2025-9990

The WordPress Helpdesk Integration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.8.10 via the portal_type parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.

PUBLISHED
Vendor
smackcoders
Product
WordPress Helpdesk Integration
Provider severity
HIGH
Conflicts
0

CVE-2025-9989

The Broadstreet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.53.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been

PUBLISHED
Vendor
broadstreetads
Product
Broadstreet
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9988

The Broadstreet plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the create_advertiser AJAX action in all versions up to, and including, 1.53.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create advertisers.

PUBLISHED
Vendor
broadstreetads
Product
Broadstreet
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9987

The Broadstreet plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.53.1 via the get_sponsored_meta() AJAX action. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract data from password protected and private business details.

PUBLISHED
Vendor
broadstreetads
Product
Broadstreet
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9986

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vadi Corporate Information Systems Ltd. Co. DIGIKENT allows Excavation. This issue affects DIGIKENT: through 13092025.

PUBLISHED
Vendor
Vadi Corporate Information Systems Ltd. Co.
Product
DIGIKENT
Provider severity
HIGH
Conflicts
0

CVE-2025-9985

The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.7 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files.

PUBLISHED
Vendor
marceljm
Product
Featured Image from URL (FIFU)
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9984

The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the fifu_api_debug_posts() function in all versions up to, and including, 5.2.7. This makes it possible for unauthenticated attackers to read private/password protected posts.

PUBLISHED
Vendor
marceljm
Product
Featured Image from URL (FIFU)
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9983

GALAYOU G2 cameras stream video output via RTSP streams. By default these streams are protected by randomly generated credentials. However these credentials are not required to access the stream. Changing these values does not change camera's behavior. The vendor did not respond in any way. Only version 11.100001.01.28 was tested, other versions might also be vulnerable.

PUBLISHED
Vendor
GALAYOU
Product
G2
Provider severity
HIGH
Conflicts
0

CVE-2025-9982

A vulnerability exists in QuickCMS version 6.8 where sensitive admin credentials are hardcoded in a configuration file and stored in plaintext. This flaw allows attackers with access to the source code or the server file system to retrieve authentication details, potentially leading to privilege escalation. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnera

PUBLISHED
Vendor
OpenSolution
Product
QuickCMS
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9981

QuickCMS is vulnerable to multiple Stored XSS in slider editor functionality (sliders-form). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed on every page. By default admin user is not able to add JavaScript into the website. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable, other

PUBLISHED
Vendor
OpenSolution
Product
QuickCMS
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9980

QuickCMS is vulnerable to multiple Stored XSS in page editor functionality (pages-form). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. By default admin user is not able to add JavaScript into the website. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable

PUBLISHED
Vendor
OpenSolution
Product
QuickCMS
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9979

The Maspik plugin for WordPress is vulnerable to Missing Authorization in version 2.5.6 and prior. This is due to missing capability checks on the Maspik_spamlog_download_csv function. This makes it possible for authenticated attackers, with subscriber-level access and above, to export and download the spam log database containing blocked submission attempts, which may include misclassified but legitimate submissions with sensitive data.

PUBLISHED
Vendor
yonifre
Product
Maspik – Ultimate Spam Protection
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9978

The Jeg Kit for Elementor WordPress plugin before 2.7.0 does not sanitize SVG file contents when uploaded via xmlrpc.php, leading to a cross site scripting vulnerability.

PUBLISHED
Vendor
Unknown
Product
Jeg Kit for Elementor
Provider severity
MEDIUM
Conflicts
1

CVE-2025-9977

Value provided in one of POST parameters sent during the process of logging in to Times Software E-Payroll is not sanitized properly, which allows an unauthenticated attacker to perform DoS attacks. SQL injection attacks might also be feasible, although so far creating a working exploit has been prevented probably by backend filtering mechanisms. Additionally, command injection attempts cause the application to return extensive error messages disclosing some information about the internal infras

PUBLISHED
Vendor
Times Software
Product
E-Payroll
Provider severity
MEDIUM
Conflicts
1

CVE-2025-9976

An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x could allow an attacker to execute arbitrary code on the user's machine.

PUBLISHED
Vendor
Dassault Systèmes
Product
Station Launcher App in 3DEXPERIENCE platform
Provider severity
CRITICAL
Conflicts
0

CVE-2025-9975

The WP Scraper plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.8.1 via the wp_scraper_extract_content function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. On Cloud instances, this issue allows for metadata retrieving.

PUBLISHED
Vendor
rico-macchi
Product
WP Scraper
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9974

The unified WEBUI application of the ONT/Beacon device contains an input handling flaw that allows authenticated users to trigger unintended system-level command execution. Due to insufficient validation of user-supplied data, a low-privileged authenticated attacker may be able to execute arbitrary commands on the underlying ONT/Beacon operating system, potentially impacting the confidentiality, integrity, and availability of the device.

PUBLISHED
Vendor
Nokia
Product
Nokia ONT
Provider severity
HIGH
Conflicts
0

CVE-2025-9973

Due to not validating the organization context when executing adaptive authentication flows, the WSO2 Identity Server allows adaptive authentication logic to be triggered on unintended organizations. A malicious actor with privileges to configure adaptive authentication within one organization can leverage this functionality to execute authentication logic on other organizations and sub-organizations. This flaw allows bypassing authorization boundaries between organizations, leading to unauthor

PUBLISHED
Vendor
WSO2, WSO2
Product
WSO2 Identity Server, Conditional Authentication User and Roles Related Functions
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9972

Certain models of Industrial Cellular Gateway developed by Planet Technology have an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the device.

PUBLISHED
Vendor
Planet Technology, Planet Technology
Product
ICG-2510W-LTE (EU/US), ICG-2510WG-LTE (EU/US)
Provider severity
CRITICAL
Conflicts
2

CVE-2025-9971

Certain models of Industrial Cellular Gateway developed by Planet Technology have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to manipulate the device via a specific functionality.

PUBLISHED
Vendor
Planet Technology, Planet Technology
Product
ICG-2510W-LTE (EU/US), ICG-2510WG-LTE (EU/US)
Provider severity
CRITICAL
Conflicts
2

CVE-2025-9970

Cleartext Storage of Sensitive Information in Memory vulnerability in ABB MConfig.This issue affects MConfig: through 1.4.9.21.

PUBLISHED
Vendor
ABB
Product
MConfig
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2025-9969

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Vizly Web Design Real Estate Packages allows Content Spoofing, CAPEC - 593 - Session Hijacking, CAPEC - 591 - Reflected XSS. This issue affects Real Estate Packages: before 5.1.

PUBLISHED
Vendor
Vizly Web Design
Product
Real Estate Packages
Provider severity
HIGH
Conflicts
0

CVE-2025-9968

A link following vulnerability exists in the UnifyScanner component of Armoury Crate. This vulnerability may be triggered by creating a specially crafted junction, potentially leading to local privilege escalation. For more information, please refer to section 'Security Update for Armoury Crate App' in the ASUS Security Advisory.

PUBLISHED
Vendor
ASUS
Product
Armoury Crate
Provider severity
HIGH
Conflicts
0

CVE-2025-9967

The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.7. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's password to a one-time password if the attacker knows the user's phone number

PUBLISHED
Vendor
gsayed786
Product
Orion SMS OTP Verification.
Provider severity
CRITICAL
Conflicts
0

CVE-2025-9966

Improper privilege management vulnerability in Novakon P series allows attackers to gain root privileges if one service is compromized.This issue affects P series: P – V2001.A.C518o2 until P-2.0.05 Build 2026.02.06 (commit d0f97fd9).

PUBLISHED
Vendor
Novakon
Product
P series (P07, P10, P12, P15)
Provider severity
HIGH
Conflicts
0

CVE-2025-9965

Improper authentication vulnerability in Novakon P series allows unauthenticated attackers to upload and download any application from/to the device.This issue affects P series: P – V2001.A.C518o2 until P-2.0.05 Build 2026.02.06 (commit d0f97fd9).

PUBLISHED
Vendor
Novakon
Product
P series (P07, P10, P12, P15)
Provider severity
CRITICAL
Conflicts
0

CVE-2025-9964

No password for the root user is set in Novakon P series. This allows phyiscal attackers to enter the console easily. This issue affects P series: P – V2001.A.C518o2 until P-2.0.05 Build 2026.02.06 (commit d0f97fd9).

PUBLISHED
Vendor
Novakon
Product
P series (P07, P10, P12, P15)
Provider severity
HIGH
Conflicts
0