Common Vulnerabilities and Exposures (CVE)

CVE-2025-14835

Jan 7, 2026 05:25:55 UTC

The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘shortcode’ parameter in all versions up to, and including, 9.1.05.008 due to insufficient input sanitization and output escaping. This mak...

CVE-2025-46696

Jan 7, 2026 04:56:06 UTC

Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application, version(s) versions 5.26 to 5.30, contain(s) an Execution with Unnecessary Privileges vulnerability. A high privileged attacker with local access could potentially exploit thi...

CVE-2025-20781

Jan 7, 2026 04:56:04 UTC

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch...

CVE-2025-20780

Jan 7, 2026 04:56:03 UTC

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch...

CVE-2025-20779

Jan 7, 2026 04:56:01 UTC

In display, there is a possible use after free due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ...

CVE-2025-20778

Jan 7, 2026 04:55:59 UTC

In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitat...

CVE-2026-0625

Jan 7, 2026 04:55:58 UTC

Multiple D-Link DSL gateway devices contain a command injection vulnerability in the dnscfg.cgi endpoint due to improper sanitization of user-supplied DNS configuration parameters. An unauthenticated remote attacker can inject and execute a...

CVE-2025-20802

Jan 7, 2026 04:55:56 UTC

In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Pat...

CVE-2025-20801

Jan 7, 2026 04:55:54 UTC

In seninf, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patc...

CVE-2025-20800

Jan 7, 2026 04:55:52 UTC

In mminfra, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitat...

CVE-2025-20799

Jan 7, 2026 04:55:51 UTC

In c2ps, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID...

CVE-2025-20798

Jan 7, 2026 04:55:49 UTC

In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitat...

CVE-2025-20797

Jan 7, 2026 04:55:48 UTC

In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitat...

CVE-2025-20796

Jan 7, 2026 04:55:47 UTC

In imgsys, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitatio...

CVE-2025-20795

Jan 7, 2026 04:55:45 UTC

In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploi...