CVE Monitor

Monitor de vulnerabilidades: 2,030 registros - Actualizado: 26/01/2026 16:04:41

Página 7 de 170 Actualizar Datos
CVE-2025-69327 CVSS: 4.3
Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Car Rental Manager: from n/a through <= 1.0.9.
06 Jan 2026
audit@patchstack.com
CVE-2025-69331 CVSS: 4.3
Missing Authorization vulnerability in Jeroen Schmit Theater for WordPress theatre allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Theater for WordPress: from n/a through <= 0.19.
06 Jan 2026
audit@patchstack.com
CVE-2025-47553 CVSS: 8.8
Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This issue affects DZS Video Gallery: from n/a through 12.25.
06 Jan 2026
audit@patchstack.com
CVE-2025-60534 CVSS: 9.8
Blue Access Cobalt v02.000.195 suffers from an authentication bypass vulnerability, which allows an attacker to selectively proxy requests in order to operate functionality on the web application without the need to authenticate with legitimate credentials.
06 Jan 2026
cve@mitre.org
CVE-2025-63082 CVSS: N/A
Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags.
06 Jan 2026
security@joomla.org
CVE-2025-63083 CVSS: N/A
Lack of output escaping leads to a XSS vector in the pagebreak plugin.
06 Jan 2026
security@joomla.org
CVE-2024-31088 CVSS: 6.5
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPShop.Ru AdsPlace'r – Ad Manager, Inserter, AdSense Ads allows DOM-Based XSS.This issue affects AdsPlace'r – Ad Manager, Inserter, AdSense Ads: from n/a through 1.1.5.
06 Jan 2026
audit@patchstack.com
CVE-2025-36589 CVSS: 7.6
Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to data and resources outside of the intended sphere of control.
06 Jan 2026
security_alert@emc.com
CVE-2025-39477 CVSS: 9.8
Missing Authorization vulnerability in Sfwebservice InWave Jobs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects InWave Jobs: from n/a through 3.5.8.
06 Jan 2026
audit@patchstack.com
CVE-2024-30547 CVSS: 7.1
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Shazdeh Header Image Slider header-image-slider allows DOM-Based XSS.This issue affects Header Image Slider: from n/a through 0.3.
06 Jan 2026
audit@patchstack.com
CVE-2026-0640 CVSS: 8.8
A weakness has been identified in Tenda AC23 16.03.07.52. This affects the function sscanf of the file /goform/PowerSaveSet. Executing a manipulation of the argument Time can lead to buffer overflow. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
06 Jan 2026
cna@vuldb.com
CVE-2025-14979 CVSS: N/A
AirVPN Eddie on MacOS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root.This issue affects Eddie: 2.24.6.
06 Jan 2026
help@fluidattacks.com
Página 7 de 170