CVE Monitor

Monitor de vulnerabilidades: 2,030 registros - Actualizado: 26/01/2026 16:04:41

Página 12 de 170 Actualizar Datos
CVE-2026-21677 CVSS: 8.8
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below have Undefined Behavior in its CIccCLUT::Init function which initializes and sets the size of a CLUT. This issue is fixed in version 2.3.1.1.
06 Jan 2026
security-advisories@github.com
CVE-2026-21744 CVSS: N/A
Rejected reason: Not used
06 Jan 2026
psirt@fortinet.com
CVE-2026-21745 CVSS: N/A
Rejected reason: Not used
06 Jan 2026
psirt@fortinet.com
CVE-2026-21746 CVSS: N/A
Rejected reason: Not used
06 Jan 2026
psirt@fortinet.com
CVE-2026-21747 CVSS: N/A
Rejected reason: Not used
06 Jan 2026
psirt@fortinet.com
CVE-2026-21748 CVSS: N/A
Rejected reason: Not used
06 Jan 2026
psirt@fortinet.com
CVE-2026-21749 CVSS: N/A
Rejected reason: Not used
06 Jan 2026
psirt@fortinet.com
CVE-2026-21750 CVSS: N/A
Rejected reason: Not used
06 Jan 2026
psirt@fortinet.com
CVE-2025-14034 CVSS: 5.3
The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'delete_single_ticket_callback' and 'change_ticket_status_callback' functions in all versions up to, and including, 1.2.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary support tickets and modify their status.
06 Jan 2026
security@wordfence.com
CVE-2025-14153 CVSS: 6.5
The Page Expire Popup/Redirection for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' shortcode attribute in all versions up to, and including, 1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
06 Jan 2026
security@wordfence.com
CVE-2026-0604 CVSS: 6.5
The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.7 via the 'dir_path' parameter in the 'njt-fastdup/v1/template/directory-tree' REST API endpoint. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary directories on the server, which can contain sensitive information.
06 Jan 2026
security@wordfence.com
CVE-2026-21485 CVSS: 8.8
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below are prone to have Undefined Behavior (UB) and Out of Memory errors. This issue is fixed in version 2.3.1.2.
06 Jan 2026
security-advisories@github.com
Página 12 de 170