CVE Monitor

Monitor de vulnerabilidades: 2,030 registros - Actualizado: 26/01/2026 16:04:41

Página 34 de 170 Actualizar Datos
CVE-2026-21429 CVSS: 4.3
Emlog is an open source website building system. In version 2.5.23, the admin can set controls which makes users unable to edit or delete their articles after publishing them. As of time of publication, no known patched versions are available.
02 Jan 2026
security-advisories@github.com
CVE-2026-0567 CVSS: 7.3
A vulnerability was detected in code-projects Content Management System 1.0. The affected element is an unknown function of the file /pages.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.
02 Jan 2026
cna@vuldb.com
CVE-2026-0568 CVSS: 7.3
A flaw has been found in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /Frontend/ViewSongs.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.
02 Jan 2026
cna@vuldb.com
CVE-2026-0566 CVSS: 4.7
A security vulnerability has been detected in code-projects Content Management System 1.0. Impacted is an unknown function of the file /admin/edit_posts.php. The manipulation of the argument image leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
02 Jan 2026
cna@vuldb.com
CVE-2025-69416 CVSS: 5
In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve other tokens (intended for unrelated access) via clients.plex.tv/devices.xml.
02 Jan 2026
cve@mitre.org
CVE-2025-69417 CVSS: 5
In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve share tokens (intended for unrelated access) via a shared_servers endpoint.
02 Jan 2026
cve@mitre.org
CVE-2025-67158 CVSS: 7.5
An authentication bypass in the /cgi-bin/jvsweb.cgi endpoint of Revotech I6032W-FHW v1.0.0014 - 20210517 allows attackers to access sensitive information and escalate privileges via a crafted HTTP request.
02 Jan 2026
cve@mitre.org
CVE-2025-67159 CVSS: 7.5
Vatilon v1.12.37-20240124 was discovered to transmit user credentials in plaintext.
02 Jan 2026
cve@mitre.org
CVE-2025-67160 CVSS: 7.5
An issue in Vatilon v1.12.37-20240124 allows attackers to access sensitive directories and files via a directory traversal.
02 Jan 2026
cve@mitre.org
CVE-2025-69414 CVSS: 8.5
Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient access token.
02 Jan 2026
cve@mitre.org
CVE-2025-69415 CVSS: 7.1
In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly aligned with whether the device is currently associated with an account.
02 Jan 2026
cve@mitre.org
CVE-2025-34988 CVSS: N/A
Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.
02 Jan 2026
disclosure@vulncheck.com
Página 34 de 170