πŸ“… Weekly CVE Roundup

December 29 - January 4, 2026

100 Total CVEs
6 Critical
15 High
39 Medium

πŸ”΄ Critical & High Severity Vulnerabilities

These are the most dangerous vulnerabilities disclosed this week. Prioritize patching these.

CVE-2025-14998 9.8

The Branda WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to reset passwords for any user account, ...

Jan 2
CVE-2025-65125 9.8

This SQL injection vulnerability in the online-movie-booking system allows attackers to execute arbitrary SQL commands through the movie_details.php e...

Jan 2
CVE-2025-11837 9.8

This critical vulnerability in Malware Remover allows remote attackers to bypass security protections through improper code generation control. Attack...

Jan 2
CVE-2025-59389 9.8

An SQL injection vulnerability in Hyper Data Protector allows remote attackers to execute unauthorized SQL commands. This affects all systems running ...

Jan 2
CVE-2025-67268 9.8

This vulnerability in gpsd allows attackers to trigger heap-based out-of-bounds writes by sending specially crafted NMEA2000 PGN 129540 packets with e...

Jan 2
CVE-2025-68620 9.1

Signal K Server versions before 2.19.0 allow unauthenticated attackers to steal JWT authentication tokens through two chained vulnerabilities: unauthe...

Jan 1
CVE-2025-15428 8.8

This CVE describes a remote buffer overflow vulnerability in UTT 进取 512W router firmware version 1.7.7-171114. Attackers can exploit the strcpy fu...

Jan 2
CVE-2025-15429 8.8

A remote buffer overflow vulnerability in UTT 进取 512W firmware version 1.7.7-171114 allows attackers to execute arbitrary code or cause denial of ...

Jan 2
CVE-2025-15431 8.8

This vulnerability allows remote attackers to execute arbitrary code on UTT 进取 512W devices via a buffer overflow in the FTP server configuration ...

Jan 2
CVE-2025-52863 8.1

A buffer overflow vulnerability in QNAP operating systems allows authenticated remote attackers to modify memory or crash processes. This affects QNAP...

Jan 2
CVE-2025-52864 8.1

A buffer overflow vulnerability in QNAP operating systems allows authenticated remote attackers to modify memory or crash processes. This affects user...

Jan 2
CVE-2025-52872 8.1

A buffer overflow vulnerability in QNAP operating systems allows authenticated remote attackers to modify memory or crash processes. This affects user...

Jan 2
CVE-2025-59384 7.5

A path traversal vulnerability in Qfiling allows remote attackers to read arbitrary files on the system by manipulating file paths. This affects all Q...

Jan 2
CVE-2025-67269 7.5

An integer underflow vulnerability in gpsd's NAVCOM packet parser causes a denial of service condition. When processing malicious packets, the parser ...

Jan 2
CVE-2025-9110 7.5

This CVE-2025-9110 vulnerability allows remote attackers to read sensitive system information from affected QNAP devices without authorization. Attack...

Jan 2
CVE-2025-15420 7.3

This CVE describes a SQL injection vulnerability in Yonyou KSOA 9.0's /worksheet/agent_work_report.jsp endpoint via the ID parameter. Attackers can re...

Jan 2
CVE-2025-15421 7.3

This vulnerability allows remote attackers to execute arbitrary SQL commands via the ID parameter in the /worksheet/agent_worksadd.jsp endpoint of Yon...

Jan 2
CVE-2025-15424 7.3

This CVE describes a SQL injection vulnerability in Yonyou KSOA 9.0 through the /worksheet/agent_worksdel.jsp endpoint. Attackers can manipulate the I...

Jan 2
CVE-2025-15426 7.3

This vulnerability in jackying H-ui.admin allows attackers to upload arbitrary files without restrictions via the /lib/webuploader/0.1.5/server/previe...

Jan 2
CVE-2025-15434 7.3

This vulnerability allows remote attackers to execute SQL injection attacks against Yonyou KSOA 9.0 through the /kp/PrintZPYG.jsp file by manipulating...

Jan 2
CVE-2025-68619 7.2

Signal K Server versions before 2.19.0 allow authenticated administrators to install npm packages from arbitrary sources via the appstore interface. T...

Jan 1

🏒 Most Affected Vendors

Qnap 31 CVEs
Yonyou 4 CVEs
Signalk 4 CVEs
Utt 3 CVEs
Gpsd Project 2 CVEs

πŸ› Common Vulnerability Types

CWE-476 10 occurrences
CWE-74 5 occurrences
CWE-119 5 occurrences
CWE-22 5 occurrences
CWE-125 4 occurrences

πŸ“‹ All CVEs This Week

CVE-2025-14998 9.8

The Branda WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to reset pa...

CVE-2025-65125 9.8

This SQL injection vulnerability in the online-movie-booking system allows attackers to execute arbitrary SQL commands t...

CVE-2025-11837 9.8

This critical vulnerability in Malware Remover allows remote attackers to bypass security protections through improper c...

CVE-2025-59389 9.8

An SQL injection vulnerability in Hyper Data Protector allows remote attackers to execute unauthorized SQL commands. Thi...

CVE-2025-67268 9.8

This vulnerability in gpsd allows attackers to trigger heap-based out-of-bounds writes by sending specially crafted NMEA...

CVE-2025-68620 9.1

Signal K Server versions before 2.19.0 allow unauthenticated attackers to steal JWT authentication tokens through two ch...

CVE-2025-15428 8.8

This CVE describes a remote buffer overflow vulnerability in UTT 进取 512W router firmware version 1.7.7-171114. Attac...

CVE-2025-15429 8.8

A remote buffer overflow vulnerability in UTT 进取 512W firmware version 1.7.7-171114 allows attackers to execute arbi...

CVE-2025-15431 8.8

This vulnerability allows remote attackers to execute arbitrary code on UTT 进取 512W devices via a buffer overflow in...

CVE-2025-52863 8.1

A buffer overflow vulnerability in QNAP operating systems allows authenticated remote attackers to modify memory or cras...

CVE-2025-52864 8.1

A buffer overflow vulnerability in QNAP operating systems allows authenticated remote attackers to modify memory or cras...

CVE-2025-52872 8.1

A buffer overflow vulnerability in QNAP operating systems allows authenticated remote attackers to modify memory or cras...

CVE-2025-59384 7.5

A path traversal vulnerability in Qfiling allows remote attackers to read arbitrary files on the system by manipulating ...

CVE-2025-67269 7.5

An integer underflow vulnerability in gpsd's NAVCOM packet parser causes a denial of service condition. When processing ...

CVE-2025-9110 7.5

This CVE-2025-9110 vulnerability allows remote attackers to read sensitive system information from affected QNAP devices...

CVE-2025-15420 7.3

This CVE describes a SQL injection vulnerability in Yonyou KSOA 9.0's /worksheet/agent_work_report.jsp endpoint via the ...

CVE-2025-15421 7.3

This vulnerability allows remote attackers to execute arbitrary SQL commands via the ID parameter in the /worksheet/agen...

CVE-2025-15424 7.3

This CVE describes a SQL injection vulnerability in Yonyou KSOA 9.0 through the /worksheet/agent_worksdel.jsp endpoint. ...

CVE-2025-15426 7.3

This vulnerability in jackying H-ui.admin allows attackers to upload arbitrary files without restrictions via the /lib/w...

CVE-2025-15434 7.3

This vulnerability allows remote attackers to execute SQL injection attacks against Yonyou KSOA 9.0 through the /kp/Prin...

CVE-2025-68619 7.2

Signal K Server versions before 2.19.0 allow authenticated administrators to install npm packages from arbitrary sources...

CVE-2025-44013 6.5

A NULL pointer dereference vulnerability in QNAP operating systems allows authenticated remote attackers to cause denial...

CVE-2025-47208 6.5

This CVE describes a resource exhaustion vulnerability in QNAP operating systems where authenticated remote attackers ca...

CVE-2025-53591 6.5

A format string vulnerability in QNAP operating systems allows attackers with administrator access to read sensitive dat...

CVE-2025-53592 6.5

A NULL pointer dereference vulnerability in QNAP operating systems allows authenticated remote attackers to cause denial...

CVE-2025-53593 6.5

A buffer overflow vulnerability in QNAP operating systems allows remote attackers with administrator credentials to modi...

CVE-2025-48721 6.5

A buffer overflow vulnerability in QNAP operating systems allows remote attackers with administrator credentials to modi...

CVE-2025-52871 6.5

An out-of-bounds read vulnerability in QNAP License Center allows authenticated remote attackers to read sensitive memor...

CVE-2025-53597 6.5

A buffer overflow vulnerability in QNAP License Center allows authenticated administrators to modify memory or crash pro...

CVE-2025-62852 6.5

A buffer overflow vulnerability in QNAP operating systems allows remote attackers with administrator credentials to modi...

CVE-2025-69203 6.3

Signal K Server versions before 2.19.0 have vulnerabilities that allow attackers to craft convincing social engineering ...

CVE-2026-0547 6.3

This vulnerability allows remote attackers to upload arbitrary files via the photo parameter in the student registration...

CVE-2025-15439 6.3

This SQL injection vulnerability in Daptin's Aggregate API allows remote attackers to execute arbitrary SQL commands by ...

CVE-2025-13153 6.1

The Logo Slider WordPress plugin before version 4.9.0 contains a stored cross-site scripting (XSS) vulnerability. Users ...

CVE-2025-13456 6.1

ShopBuilder WordPress plugin before version 3.2.2 contains a reflected cross-site scripting (XSS) vulnerability where un...

CVE-2025-45286 6.1

This CVE describes a cross-site scripting (XSS) vulnerability in mccutchen httpbin v2.17.1 that allows attackers to inje...

CVE-2025-62857 6.1

A cross-site scripting (XSS) vulnerability in QuMagie allows remote attackers to inject malicious scripts that execute i...

CVE-2025-68273 5.3

Signal K Server versions before 2.19.0 have an unauthenticated information disclosure vulnerability that allows any user...

CVE-2025-15412 5.3

An out-of-bounds read vulnerability in wabt's wasm-decompile tool allows local attackers to read memory beyond intended ...

CVE-2025-15413 5.3

A memory corruption vulnerability in wasm3 up to version 0.5.0 allows local attackers to potentially execute arbitrary c...

CVE-2025-14047 5.3

This vulnerability in the WP User Frontend WordPress plugin allows unauthenticated attackers to delete attachments witho...

CVE-2025-15432 5.3

This is a path traversal vulnerability in yeqifu carRental software that allows attackers to access arbitrary files on t...

CVE-2024-55374 5.3

REDCap 14.3.13 has a username enumeration vulnerability where attackers can distinguish between valid and invalid userna...

CVE-2025-52426 4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credential...

CVE-2025-52430 4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credential...

CVE-2025-52431 4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credential...

CVE-2025-53405 4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credential...

CVE-2025-53414 4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credential...

CVE-2025-53589 4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credential...

CVE-2025-53590 4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credential...

CVE-2025-53596 4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credential...

CVE-2025-54164 4.9

An out-of-bounds read vulnerability in QNAP operating systems allows remote attackers with administrator credentials to ...

CVE-2025-54165 4.9

An out-of-bounds read vulnerability in QNAP operating systems allows remote attackers with administrator credentials to ...

CVE-2025-54166 4.9

An out-of-bounds read vulnerability in QNAP operating systems allows remote attackers with administrator credentials to ...

CVE-2025-57705 4.9

This CVE describes a resource allocation vulnerability in QNAP operating systems where an authenticated attacker with ad...

CVE-2025-59380 4.9

This CVE describes a path traversal vulnerability in QNAP operating systems that allows authenticated attackers with adm...

CVE-2025-59381 4.9

A path traversal vulnerability in QNAP operating systems allows authenticated administrators to read arbitrary files. Th...

CVE-2025-15414 4.7

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in go-sonic's Theme Fetching API. Attackers can ma...

CVE-2025-15438 4.7

This vulnerability in PluXml's Media Management Module allows remote attackers to execute arbitrary code through deseria...

CVE-2025-69284 4.3

This vulnerability in Plane.io allows guest users to access an API endpoint that lists workspace members, potentially ex...

CVE-2025-15437 3.5

This CVE describes a cross-site scripting (XSS) vulnerability in LigeroSmart's Environment Variable Handler component. A...

CVE-2025-69412 3.4

KDE messagelib versions before 25.11.90 ignore SSL certificate validation errors when contacting Google's Safe Browsing ...

CVE-2025-15418 3.3

A local denial-of-service vulnerability exists in Open5GS versions up to 2.7.6 where the ogs_gtp2_parse_bearer_qos funct...

CVE-2025-15416 2.4

This vulnerability allows attackers to inject malicious scripts into the 'Remark' or 'Variable Value' parameters of the ...

CVE-2025-34376 N/A

This CVE ID was reserved but never assigned to an actual vulnerability. No security vulnerability exists for CVE-2025-34...

CVE-2025-34377 N/A

This CVE ID was reserved but never assigned to an actual vulnerability. No security vulnerability exists for CVE-2025-34...

CVE-2025-34378 N/A

This CVE ID was reserved but never assigned to an actual vulnerability. No security vulnerability exists for this identi...

CVE-2025-34379 N/A

This CVE ID was reserved but never assigned to an actual vulnerability. No software or systems are affected by this iden...

CVE-2025-34380 N/A

This CVE ID was reserved but never assigned to an actual vulnerability. No security vulnerability exists for CVE-2025-34...

CVE-2025-34381 N/A

This CVE ID was reserved but never assigned to an actual vulnerability. No security vulnerability exists under this iden...

CVE-2025-34382 N/A

This CVE ID was reserved but never assigned to an actual vulnerability. No security vulnerability exists for this identi...

CVE-2025-34383 N/A

This CVE ID was reserved but never assigned to an actual vulnerability. No security vulnerability exists for CVE-2025-34...

CVE-2025-34384 N/A

This CVE ID was reserved but not used for any actual vulnerability disclosure. No vulnerability exists, and no systems a...

CVE-2025-34385 N/A

This CVE ID (CVE-2025-34385) was rejected and never assigned to an actual vulnerability. It was reserved but not used fo...

CVE-2025-34386 N/A

This CVE ID was reserved but never assigned to an actual vulnerability. No security vulnerability exists for CVE-2025-34...

CVE-2025-34387 N/A

This CVE ID was reserved but never assigned to an actual vulnerability. No security vulnerability exists for this identi...

CVE-2025-34388 N/A

This CVE ID was reserved but not used for any actual vulnerability disclosure. No vulnerability exists under this identi...

CVE-2025-34389 N/A

This CVE ID was reserved but never assigned to an actual vulnerability. No security vulnerability exists for CVE-2025-34...

CVE-2025-34390 N/A

This CVE ID (CVE-2025-34390) was rejected because it was reserved but never used for an actual vulnerability disclosure....

CVE-2025-34391 N/A

This CVE ID was reserved but not used for any actual vulnerability disclosure. No vulnerability exists, and no systems a...

CVE-2025-34405 N/A

This CVE ID (CVE-2025-34405) was rejected and never assigned to an actual vulnerability. It was reserved but not used fo...

CVE-2025-34415 N/A

This CVE ID was reserved but never assigned to an actual vulnerability. No software or systems are affected by this iden...

CVE-2025-34426 N/A

This CVE ID (CVE-2025-34426) was rejected and never assigned to an actual vulnerability. It was reserved but not used fo...

CVE-2025-34431 N/A

This CVE ID was reserved but never assigned to an actual vulnerability. No security vulnerability exists under this iden...

CVE-2025-34432 N/A

This CVE ID (CVE-2025-34432) was reserved but never assigned to an actual vulnerability. It represents a placeholder tha...

CVE-2025-34443 N/A

CVE-2025-34443 is not an actual vulnerability. It was a CVE ID that was reserved but never assigned to a real security i...

CVE-2025-34444 N/A

This CVE ID was reserved but not used for any actual vulnerability disclosure. No vulnerability exists, and no systems a...

CVE-2025-34445 N/A

This CVE ID was reserved but never assigned to an actual vulnerability. No software or systems are affected by this iden...

CVE-2025-34446 N/A

This CVE ID was reserved but never assigned to an actual vulnerability. No security vulnerability exists for this identi...

CVE-2025-34447 N/A

This CVE ID (CVE-2025-34447) was rejected because it was reserved but never used for an actual vulnerability disclosure....

CVE-2025-34448 N/A

This CVE ID was reserved but not used for any actual vulnerability disclosure. No vulnerability exists under this identi...

CVE-2025-34453 N/A

This CVE ID was reserved but never assigned to an actual vulnerability. No security vulnerability exists for this identi...

CVE-2025-34454 N/A

This CVE ID was reserved but never assigned to an actual vulnerability. No security vulnerability exists for CVE-2025-34...

CVE-2025-34455 N/A

This CVE ID (CVE-2025-34455) was rejected because it was reserved but never used for an actual vulnerability disclosure....

CVE-2025-34456 N/A

This CVE ID was reserved but never assigned to an actual vulnerability. No software or systems are affected by this iden...

CVE-2025-34459 N/A

This CVE ID was reserved but never assigned to an actual vulnerability. No security vulnerability exists under this iden...

CVE-2025-34460 N/A

This CVE has been reserved by a CVE Numbering Authority but no details have been published yet. The vulnerability descri...

CVE-2025-34461 N/A

This CVE ID (CVE-2025-34461) was reserved but never assigned to an actual vulnerability. It represents a placeholder tha...

CVE-2025-34462 N/A

This CVE ID was reserved but never assigned to an actual vulnerability. No security vulnerability exists for CVE-2025-34...

CVE-2025-34463 N/A

This CVE ID was reserved but not used for any actual vulnerability disclosure. No vulnerability exists under this identi...

πŸ“š Past Roundups