Common Vulnerabilities and Exposures (CVE)

CVE-2025-7195

Jan 16, 2026 23:49:06 UTC

Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/pass...

CVE-2026-22865

Jan 16, 2026 22:46:19 UTC

Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a repository ...

CVE-2026-22816

Jan 16, 2026 22:45:48 UTC

Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a repository ...

CVE-2026-1009

Jan 16, 2026 22:41:01 UTC

A stored cross-site scripting (XSS) vulnerability exists in the Altium Forum due to missing server-side input sanitization in forum post content. An authenticated attacker can inject arbitrary JavaScript into forum posts, which is stored an...

CVE-2026-1008

Jan 16, 2026 22:39:35 UTC

A stored cross-site scripting (XSS) vulnerability exists in the user profile text fields of Altium 365. Insufficient server-side input sanitization allows authenticated users to inject arbitrary HTML and JavaScript payloads using whitespace...

CVE-2026-1010

Jan 16, 2026 22:27:55 UTC

A stored cross-site scripting (XSS) vulnerability exists in the Altium Workflow Engine due to missing server-side input sanitization in workflow form submission APIs. A regular authenticated user can inject arbitrary JavaScript into workflo...

CVE-2026-1011

Jan 16, 2026 22:19:11 UTC

A stored cross-site scripting (XSS) vulnerability exists in the Altium Support Center AddComment endpoint due to missing server-side input sanitization. Although the client interface applies HTML escaping, the backend accepts and stores arb...

CVE-2025-15529

Jan 16, 2026 22:02:10 UTC

A vulnerability was found in Open5GS up to 2.7.6. Affected by this issue is the function sgwc_s5c_handle_create_session_response of the file src/sgwc/s5c-handler.c. Performing a manipulation results in denial of service. Remote exploitation...

CVE-2025-15528

Jan 16, 2026 22:02:07 UTC

A vulnerability has been found in Open5GS up to 2.7.6. Affected by this vulnerability is an unknown functionality of the component GTPv2 Bearer Response Handler. Such manipulation leads to denial of service. The attack may be launched remot...

CVE-2026-23745

Jan 16, 2026 22:00:08 UTC

node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure behavior). This allows malicious archives to bypass th...

CVE-2026-21223

Jan 16, 2026 21:50:24 UTC

Microsoft Edge Elevation Service exposes a privileged COM interface that inadequately validates the privileges of the calling process. A standard (non‑administrator) local user can invoke the IElevatorEdge interface method LaunchUpdateCmdEl...

CVE-2026-20960

Jan 16, 2026 21:49:30 UTC

Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.

CVE-2025-56451

Jan 16, 2026 21:48:17 UTC

Cross site scripting vulnerability in seeyon Zhiyuan A8+ Collaborative Management Software 7.0 via the topValue parameter to the seeyon/main.do endpoint.

CVE-2025-69581

Jan 16, 2026 21:46:13 UTC

An issue was discovered in Chamillo LMS 1.11.2. The Social Network /personal_data endpoint exposes full sensitive user information even after logout because proper cache-control is missing. Using the browser back button restores all persona...

CVE-2025-14894

Jan 16, 2026 21:44:06 UTC

Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE through upload of a malicious php file that can then be executed ...