Skip to main content

Year archive

CVEs published in 2026

Archive summary

42,985 CVEs published in 2026 — 4,543 Critical, 17,077 High, 17,292 Medium, 3,586 Low, 487 Unrated.

CVE-2026-0546

Published Jan 2, 2026

A vulnerability was determined in code-projects Content Management System 1.0. This impacts an unknown function of the file search.php. This manipulation of the argument Value cau…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2025-15437

Published Jan 2, 2026

A vulnerability was found in LigeroSmart up to 6.1.24. This affects an unknown part of the component Environment Variable Handler. Performing a manipulation of the argument REQUES…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-15436

Published Jan 2, 2026

A vulnerability has been found in Yonyou KSOA 9.0. Affected by this issue is some unknown functionality of the file /worksheet/work_edit.jsp. Such manipulation of the argument Rep…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-15435

Published Jan 2, 2026

A flaw has been found in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /worksheet/work_update.jsp. This manipulation of the argument Repo…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-15434

Published Jan 2, 2026

A vulnerability was detected in Yonyou KSOA 9.0. Affected is an unknown function of the file /kp/PrintZPYG.jsp. The manipulation of the argument zpjhid results in sql injection. I…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-15432

Published Jan 2, 2026

A vulnerability has been found in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3. This vulnerability affects the function downloadShowFile of the file /file/downl…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-15431

Published Jan 2, 2026

A flaw has been found in UTT 进取 512W 1.7.7-171114. This affects the function strcpy of the file /goform/formFtpServerDirConfig. Executing a manipulation of the argument filename c…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-15430

Published Jan 2, 2026

A vulnerability was detected in UTT 进取 512W 1.7.7-171114. Affected by this issue is the function strcpy of the file /goform/formFtpServerShareDirSelcet. Performing a manipulation…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-15429

Published Jan 2, 2026

A security vulnerability has been detected in UTT 进取 512W 1.7.7-171114. Affected by this vulnerability is the function strcpy of the file /goform/formConfigCliForEngineerOnly. Suc…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-14072

Published Jan 2, 2026

The Ninja Forms WordPress plugin before 3.13.3 allows unauthenticated attackers to generate valid access tokens via the REST API which can then be used to read form submissions.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-13456

Published Jan 2, 2026

The ShopBuilder WordPress plugin before 3.2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which co…

CVSS 6.1 · Medium

CVE-2025-13153

Published Jan 2, 2026

The Logo Slider WordPress plugin before 4.9.0 does not validate and escape some of its slider options before outputting them back in the dashboard, which could allow users with t…

CVSS 6.1 · Medium

CVE-2025-12685

Published Jan 2, 2026

The WPBookit WordPress plugin through 1.0.7 lacks a CSRF check when deleting customers. This could allow an unauthenticated attacker to delete any customer through a CSRF attack.

CVSS 6.5 · Medium

CVE-2025-15428

Published Jan 2, 2026

A weakness has been identified in UTT 进取 512W 1.7.7-171114. Affected is the function strcpy of the file /goform/formRemoteControl. This manipulation of the argument Profile causes…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-15426

Published Jan 2, 2026

A vulnerability was identified in jackying H-ui.admin up to 3.1. This affects an unknown function in the library /lib/webuploader/0.1.5/server/preview.php. The manipulation leads…

CVSS 5.5 · Medium

CVE-2025-15425

Published Jan 2, 2026

A vulnerability was determined in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /worksheet/del_user.jsp of the component HTTP GET Parameter Handler. Exe…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-15424

Published Jan 2, 2026

A vulnerability was found in Yonyou KSOA 9.0. The affected element is an unknown function of the file /worksheet/agent_worksdel.jsp of the component HTTP GET Parameter Handler. Pe…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-15423

Published Jan 2, 2026

A vulnerability has been found in EmpireSoft EmpireCMS up to 8.0. Impacted is the function CheckSaveTranFiletype of the file e/class/connect.php. Such manipulation leads to unrest…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-14998

Published Jan 2, 2026

The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.24. This is due to the plugin not properly val…

CVSS 9.8 · Critical

CVE-2025-14047

Published Jan 2, 2026

The Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User Frontend plugin for WordPress is vulnerable to unauthorized…

CVSS 5.3 · Medium

CVE-2025-15422

Published Jan 2, 2026

A flaw has been found in EmpireSoft EmpireCMS up to 8.0. This issue affects the function egetip of the file e/class/connect.php of the component IP Address Handler. This manipulat…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-15421

Published Jan 2, 2026

A vulnerability was detected in Yonyou KSOA 9.0. This vulnerability affects unknown code of the file /worksheet/agent_worksadd.jsp of the component HTTP GET Parameter Handler. The…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-15420

Published Jan 2, 2026

A security vulnerability has been detected in Yonyou KSOA 9.0. This affects an unknown part of the file /worksheet/agent_work_report.jsp. The manipulation of the argument ID leads…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-15419

Published Jan 2, 2026

A weakness has been identified in Open5GS up to 2.7.6. Affected by this issue is the function sgwc_s5c_handle_create_session_response of the file src/sgwc/s5c-handler.c of the com…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-15418

Published Jan 2, 2026

A security flaw has been discovered in Open5GS up to 2.7.6. Affected by this vulnerability is the function ogs_gtp2_parse_bearer_qos in the library lib/gtp/v2/types.c of the compo…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort
Showing 42,926-42,950 of 42,985 CVEsPage 1718 of 1720