Common Vulnerabilities and Exposures (CVE)

CVE-2025-34449

Dec 22, 2025 17:47:59 UTC

Genymobile/scrcpy versions up to and including 3.3.3, prior to commit 3e40b24, contain a buffer overflow vulnerability in the sc_device_msg_deserialize() function. A compromised device can send crafted messages that cause out-of-bounds read...

CVE-2011-10037

Dec 22, 2025 17:24:04 UTC

Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the handling of xiwindow variables used to build permalinks in the web interface. Insufficient validation or escaping of user-supplied input may allow an ...

CVE-2025-8383

Dec 22, 2025 17:22:32 UTC

The Depicter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less than, or equal to, 4.0.4. This is due to missing or incorrect nonce validation on the depicter-document-rules-store function. This makes it possi...

CVE-2025-11587

Dec 22, 2025 17:20:17 UTC

The Call Now Button – The #1 Click to Call Button for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the activate function in all versions up to, and including, 1.5.3. ...

CVE-2025-15013

Dec 22, 2025 17:09:32 UTC

A vulnerability was identified in floooh sokol up to 5d11344150973f15e16d3ec4ee7550a73fb995e0. The impacted element is the function _sg_validate_pipeline_desc in the library sokol_gfx.h. Such manipulation leads to stack-based buffer overflo...

CVE-2025-15014

Dec 22, 2025 17:08:58 UTC

A security flaw has been discovered in loganhong php loganSite up to c035fb5c3edd0b2a5e32fd4051cbbc9e61a31426. This affects an unknown function of the file /includes/article_detail.php of the component Article Handler. Performing manipulati...

CVE-2025-12049

Dec 22, 2025 17:07:30 UTC

Missing Authentication for Critical Function vulnerability in Sharp Display Solutions Media Player MP-01 All Verisons allows a attacker may access to the web interface of the affected product without authentication and change settings or pe...

CVE-2025-11540

Dec 22, 2025 17:06:40 UTC

Path Traversal vulnerability in Sharp Display Solutions projectors allows a attacker may access and read any files within the projector.

CVE-2025-8304

Dec 22, 2025 17:05:37 UTC

An authenticated local user can obtain information that allows claiming security policy rules of another user due to sensitive information being accessible in the Windows Registry keys for Check Point Identity Agent running on a Terminal Se...

CVE-2025-67443

Dec 22, 2025 17:01:28 UTC

Schlix CMS before v2.2.9-5 is vulnerable to Cross Site Scripting (XSS). Due to lack of javascript sanitization in the login form, incorrect login attempts in logs are triggered as XSS in the admin panel.

CVE-2025-14990

Dec 22, 2025 16:49:55 UTC

A security flaw has been discovered in Campcodes Complete Online Beauty Parlor Management System 1.0. Impacted is an unknown function of the file /admin/view-appointment.php. Performing manipulation of the argument viewid results in sql inj...

CVE-2025-7195

Dec 22, 2025 16:49:33 UTC

Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/pass...

CVE-2025-9343

Dec 22, 2025 16:49:21 UTC

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ticket subjects in all versions up to, and including, 3.3.4 due to insufficient input sanitization and output esca...

CVE-2023-53945

Dec 22, 2025 16:41:22 UTC

BrainyCP 1.0 contains an authenticated remote code execution vulnerability that allows logged-in users to inject arbitrary commands through the crontab configuration interface. Attackers can exploit the crontab endpoint by adding a maliciou...

CVE-2025-12977

Dec 22, 2025 16:40:18 UTC

Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins fail to sanitize tag_key inputs. An attacker with network access or the ability to write records into Splunk or Elasticsearch can supply tag_key values containing special cha...