Vulnerabilities (CVE)

Angry Yack Logo
Total 336347 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-25485 1 Craftcms 1 Craft Commerce 2026-02-10 N/A 4.8 MEDIUM
Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability in Craft Commerce allows attackers to execute malicious JavaScript in an administrator’s browser. This occurs because the Shipping Categories (Name & Description) fields in the Store Management section are not properly sanitized before being displayed in the admin panel. This issue has been patched in versions 4.10.1 and 5.5.2.
CVE-2026-2011 1 Itsourcecode 1 School Management System 2026-02-10 7.5 HIGH 7.3 HIGH
A vulnerability was found in itsourcecode Student Management System 1.0. The affected element is an unknown function of the file /ramonsys/enrollment/controller.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.
CVE-2026-25486 1 Craftcms 1 Craft Commerce 2026-02-10 N/A 4.8 MEDIUM
Craft Commerce is an ecommerce platform for Craft CMS. From version 5.0.0 to 5.5.1, a stored XSS vulnerability in Craft Commerce allows attackers to execute malicious JavaScript in an administrator’s browser. This occurs because the Shipping Methods Name field in the Store Management section is not properly sanitized before being displayed in the admin panel. This issue has been patched in version 5.5.2.
CVE-2026-24926 1 Huawei 1 Harmonyos 2026-02-10 N/A 8.4 HIGH
Out-of-bounds write vulnerability in the camera module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-24925 1 Huawei 1 Harmonyos 2026-02-10 N/A 7.3 HIGH
Heap-based buffer overflow vulnerability in the image module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-25487 1 Craftcms 1 Craft Commerce 2026-02-10 N/A 4.8 MEDIUM
Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability in Craft Commerce allows attackers to execute malicious JavaScript in an administrator's browser. This occurs because the Tax Rates 'Name' field in the Store Management section is not properly sanitized before being displayed in the admin panel. This issue has been patched in versions 4.10.1 and 5.5.2.
CVE-2026-24923 1 Huawei 1 Harmonyos 2026-02-10 N/A 6.3 MEDIUM
Permission control vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2026-25488 1 Craftcms 1 Craft Commerce 2026-02-10 N/A 4.8 MEDIUM
Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability in Craft Commerce allows attackers to execute malicious JavaScript in an administrator’s browser. This occurs because the Tax Categories (Name & Description) fields in the Store Management section are not properly sanitized before being displayed in the admin panel. This issue has been patched in versions 4.10.1 and 5.5.2.
CVE-2026-24922 1 Huawei 1 Harmonyos 2026-02-10 N/A 6.9 MEDIUM
Buffer overflow vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-25489 1 Craftcms 1 Craft Commerce 2026-02-10 N/A 4.8 MEDIUM
Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability in Craft Commerce allows attackers to execute malicious JavaScript in an administrator’s browser. This occurs because the Name & Description fields in Tax Zones are not properly sanitized before being displayed in the admin panel. This issue has been patched in versions 4.10.1 and 5.5.2.
CVE-2026-25490 1 Craftcms 1 Craft Commerce 2026-02-10 N/A 4.8 MEDIUM
Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability in Craft Commerce allows attackers to execute malicious JavaScript in an administrator’s browser. This occurs because the 'Address Line 1' field in Inventory Locations is not properly sanitized before being displayed in the admin panel. This issue has been patched in versions 4.10.1 and 5.5.2.
CVE-2025-15325 1 Tanium 1 Discover 2026-02-10 N/A 6.3 MEDIUM
Tanium addressed an improper input validation vulnerability in Discover.
CVE-2026-24921 1 Huawei 1 Harmonyos 2026-02-10 N/A 4.8 MEDIUM
Address read vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
CVE-2025-15339 1 Tanium 1 Discover 2026-02-10 N/A 6.5 MEDIUM
Tanium addressed an incorrect default permissions vulnerability in Discover.
CVE-2025-15341 1 Tanium 1 Benchmark 2026-02-10 N/A 6.5 MEDIUM
Tanium addressed an incorrect default permissions vulnerability in Benchmark.
CVE-2025-15342 1 Tanium 1 Reputation 2026-02-10 N/A 4.3 MEDIUM
Tanium addressed an improper access controls vulnerability in Reputation.
CVE-2026-24919 1 Huawei 2 Emui, Harmonyos 2026-02-10 N/A 6.0 MEDIUM
Out-of-bounds write vulnerability in the DFX module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-24918 1 Huawei 2 Emui, Harmonyos 2026-02-10 N/A 6.8 MEDIUM
Address read vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-24917 1 Huawei 2 Emui, Harmonyos 2026-02-10 N/A 6.5 MEDIUM
UAF vulnerability in the security module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-24916 1 Huawei 1 Harmonyos 2026-02-10 N/A 5.9 MEDIUM
Identity authentication bypass vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2026-25483 1 Craftcms 1 Craft Commerce 2026-02-10 N/A 5.4 MEDIUM
Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability exists in Craft Commerce’s Order Status History Message. The message is rendered using the |md filter, which permits raw HTML, enabling malicious script execution. If a user has database backup utility permissions (which do not require an elevated session), an attacker can exfiltrate the entire database, including all user credentials, customer PII, orde ...

Show More

CVE-2026-24915 1 Huawei 1 Harmonyos 2026-02-10 N/A 6.2 MEDIUM
Out-of-bounds read issue in the media subsystem. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
CVE-2026-24914 1 Huawei 1 Harmonyos 2026-02-10 N/A 4.0 MEDIUM
Type confusion vulnerability in the camera module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2025-56230 1 Tencent 1 Docs 2026-02-10 N/A 7.5 HIGH
Tencent Docs Desktop 3.9.20 and earlier suffers from Missing SSL Certificate Validation in the update component.
CVE-2026-1897 1 Wekan Project 1 Wekan 2026-02-10 4.0 MEDIUM 4.3 MEDIUM
A vulnerability was found in WeKan up to 8.20. Affected by this issue is some unknown functionality of the file server/methods/positionHistory.js of the component Position-History Tracking. The manipulation results in missing authorization. The attack may be performed from remote. Upgrading to version 8.21 can resolve this issue. The patch is identified as 55576ec17722db094835470b386162c9a662fb60. It is advisable to upgrade the affected component.
CVE-2026-1896 1 Wekan Project 1 Wekan 2026-02-10 6.5 MEDIUM 6.3 MEDIUM
A vulnerability has been found in WeKan up to 8.20. Affected by this vulnerability is the function ComprehensiveBoardMigration of the file server/migrations/comprehensiveBoardMigration.js of the component Migration Operation Handler. The manipulation of the argument boardId leads to improper access controls. The attack is possible to be carried out remotely. Upgrading to version 8.21 addresses this issue. The identifier of the patch is cc35dafef57ef6e44a514a523f9a8d891e74ad8f. Upgrading the affe ...

Show More

CVE-2026-1892 1 Wekan Project 1 Wekan 2026-02-10 4.6 MEDIUM 5.0 MEDIUM
A security vulnerability has been detected in WeKan up to 8.20. This affects the function setBoardOrgs of the file models/boards.js of the component REST API. Such manipulation of the argument item.cardId/item.checklistId/card.boardId leads to improper authorization. The attack may be launched remotely. A high complexity level is associated with this attack. The exploitability is reported as difficult. Upgrading to version 8.21 mitigates this issue. The name of the patch is cabfeed9a68e21c469bf2 ...

Show More

CVE-2025-11653 1 Utt 2 2620g, 2620g Firmware 2026-02-10 9.0 HIGH 8.8 HIGH
A vulnerability was determined in UTT HiPER 2620G up to 3.1.4. Impacted is the function strcpy of the file /goform/fNTP. This manipulation of the argument NTPServerIP causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-2009 1 Mayurik 1 Gas Agency Management System 2026-02-10 6.5 MEDIUM 6.3 MEDIUM
A flaw has been found in SourceCodester Gas Agency Management System 1.0. This issue affects some unknown processing of the file /gasmark/php_action/createUser.php. Executing a manipulation can lead to improper access controls. It is possible to launch the attack remotely. The exploit has been published and may be used.
CVE-2026-1746 1 Jeecg 1 Jeecg Boot 2026-02-10 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was identified in JeecgBoot 3.9.0. This vulnerability affects unknown code of the file /JeecgBoot/sys/api/loadDictItemByKeyword of the component Online Report API. Such manipulation of the argument keyword leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-1744 1 Dlink 2 Dsl-6641k, Dsl-6641k Firmware 2026-02-10 3.3 LOW 2.4 LOW
A vulnerability was found in D-Link DSL-6641K N8.TR069.20131126. Affected by this issue is the function doSubmitPPP of the file sp_pppoe_user.js. The manipulation of the argument Username results in cross site scripting. The attack may be launched remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-1596 1 Dlink 2 Dwr-m961, Dwr-m961 Firmware 2026-02-10 6.5 MEDIUM 6.3 MEDIUM
A flaw has been found in D-Link DWR-M961 1.1.47. This vulnerability affects the function sub_419920 of the file /boafrm/formLtefotaUpgradeQuectel. This manipulation of the argument fota_url causes command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
CVE-2025-59596 1 Absolute 1 Secure Access 2026-02-10 N/A 6.5 MEDIUM
CVE-2025-59596 is a denial-of-service vulnerability in Secure Access Windows client versions 12.0 to 14.10 that is addressed in version 14.12. If a local networking policy is active, attackers on an adjacent network may be able to send a crafted packet and cause the client system to crash.
CVE-2025-12735 2 Jorenbroekema, Silentmatt 2 Javascript Expression Evaluator, Javascript Expression Evaluator 2026-02-10 N/A 9.8 CRITICAL
The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressions with user-defined variables. However, due to insufficient input validation, an attacker can pass a crafted context object or use MEMBER of the context object into the evaluate() function and trigger arbitrary code execution.
CVE-2026-24673 1 Gunet 1 Open Eclass Platform 2026-02-10 N/A 4.3 MEDIUM
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a file upload validation bypass vulnerability allows attackers to upload files with prohibited extensions by embedding them inside ZIP archives and extracting them using the application’s built-in decompression functionality. This issue has been patched in version 4.2.
CVE-2025-15289 1 Tanium 1 Interact 2026-02-10 N/A 3.1 LOW
Tanium addressed an improper access controls vulnerability in Interact.
CVE-2025-15328 1 Enforce 1 Enforce 2026-02-10 N/A 5.0 MEDIUM
Tanium addressed an improper link resolution before file access vulnerability in Enforce.
CVE-2025-15343 1 Tanium 1 Enforce 2026-02-10 N/A 6.5 MEDIUM
Tanium addressed an incorrect default permissions vulnerability in Enforce.
CVE-2025-15324 1 Tanium 1 Engage 2026-02-10 N/A 6.6 MEDIUM
Tanium addressed a documentation issue in Engage.
CVE-2025-15330 1 Tanium 1 Deploy 2026-02-10 N/A 8.8 HIGH
Tanium addressed an improper input validation vulnerability in Deploy.