CVE Database

Comprehensive vulnerability intelligence with advanced analytics

3.7

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ownership check in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.9.2. This makes it possible for unauthenticated attackers to delete arbitrary uploaded…

Published: Jan 15, 2026
EPSS: 0.04%
View Details
5.4

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Multiple Checkbox and Multiple Select user profile fields in all versions up to, and including, 3.5.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and…

Published: Jan 15, 2026
EPSS: 0.03%
View Details

Rejected reason: Not used

Published: Jan 15, 2026
View Details

Rejected reason: Not used

Published: Jan 15, 2026
View Details

Rejected reason: Not used

Published: Jan 15, 2026
View Details

Rejected reason: Not used

Published: Jan 15, 2026
View Details

Rejected reason: Not used

Published: Jan 15, 2026
View Details

Rejected reason: Not used

Published: Jan 15, 2026
View Details

Rejected reason: Not used

Published: Jan 15, 2026
View Details

Rejected reason: Not used

Published: Jan 15, 2026
View Details

Rejected reason: Not used

Published: Jan 15, 2026
View Details

Server-Side Request Forgery (SSRF) vulnerability in Sonatype Nexus Repository 3 versions 3.0.0 and later allows authenticated administrators to configure proxy repositories with URLs that can access unintended network destinations, potentially including cloud metadata services and internal network resources. A workaround configuration is available starting in version 3.88.0, but the product…

Published: Jan 14, 2026
EPSS: 0.04%
View Details
6.5

A potential vulnerability was reported in the BIOS of L13 Gen 6, L13 Gen 6 2-in-1, L14 Gen 6, and L16 Gen 2 ThinkPads which could result in Secure Boot being disabled even when configured as “On” in the BIOS setup menu. This issue only affects systems where Secure Boot…

Published: Jan 14, 2026
EPSS: 0.01%
View Details
3.2

A potential missing authentication vulnerability was reported in some Lenovo Tablets that could allow an unauthorized user with physical access to modify Control Center settings if the device is locked when the "Allow Control Center access when locked" option is disabled.

Published: Jan 14, 2026
EPSS: 0.02%
View Details
7.8

A vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to bypass ThinkPlus device authentication and enroll an untrusted fingerprint.

Published: Jan 14, 2026
EPSS: 0.02%
View Details
4.7

A potential vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to gain access to sensitive device information.

Published: Jan 14, 2026
EPSS: 0.01%
View Details
6.8

A potential vulnerability was reported in some ThinkPlus USB drives that could allow a user with physical access to read data stored on the drive.

Published: Jan 14, 2026
EPSS: 0.02%
View Details
5.5

An improper link following vulnerability was reported in the SmartPerformanceAddin for Lenovo Vantage that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges.

Published: Jan 14, 2026
EPSS: 0.02%
View Details

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Published: Jan 14, 2026
View Details
7.5

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to blind SQL Injection via the `order` and `append_where_sql` parameters in all versions up to, and including, 1.6.9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…

Published: Jan 14, 2026
EPSS: 0.06%
View Details

A reflected cross-site scripting vulnerability exists in Nexus Repository 3 that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted request requiring user interaction.

Published: Jan 14, 2026
EPSS: 0.11%
View Details
8.6

SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, there is a Untrusted Search Path vulnerability when Advanced Options setting is trigger. The application executes notepad.exe without specifying an absolute path when using the Advanced Options setting. On Windows, this allows execution of a malicious notepad.exe placed in…

Published: Jan 14, 2026
EPSS: 0.01%
View Details
5.3

SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service

Published: Jan 14, 2026
EPSS: 0.03%
View Details
5.5

BLF file parser crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service

Published: Jan 14, 2026
EPSS: 0.01%
View Details