CVE Monitor
3.44K subscribers
33.2K links
Download Telegram
{
"Source": "CVE FEED",
"Title": "CVE-2026-21492 - iccDEV ToneMap Writer has NULL Pointer Member Call",
"Content": "CVE ID : CVE-2026-21492
Published : Jan. 6, 2026, 9:15 p.m. | 27 minutes ago
Description : iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a NULL pointer member call vulnerability. This vulnerability affects users of the iccDEV library who process ICC color profiles. Version 2.3.1.2 contains a patch. No known workarounds are available.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "06 Jan 2026",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-29004 - Privilege Escalation Vulnerability in AA-Team WordPress plugins",
"Content": "CVE ID : CVE-2025-29004
Published : Jan. 6, 2026, 9:15 p.m. | 27 minutes ago
Description : Incorrect Privilege Assignment vulnerability in AA-Team Premium Age Verification / Restriction for WordPress, AA-Team Responsive Coming Soon Landing Page / Holding Page for WordPress allows Privilege Escalation.This issue affects Premium Age Verification / Restriction for WordPress: from n/a through 3.0.2; Responsive Coming Soon Landing Page / Holding Page for WordPress: from n/a through 3.0.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "06 Jan 2026",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-30631 - Reflected Cross Site Scripting (XSS) vulnerability in AA-Team WordPress plugins",
"Content": "CVE ID : CVE-2025-30631
Published : Jan. 6, 2026, 9:15 p.m. | 27 minutes ago
Description : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA-Team Woocommerce Sales Funnel Builder, AA-Team Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer) allows Reflected XSS.This issue affects Woocommerce Sales Funnel Builder: from n/a through 1.1; Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer): from n/a through 1.2.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "06 Jan 2026",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-30996 - Arbitrary File Upload Vulnerability in WordPress themes by Themify",
"Content": "CVE ID : CVE-2025-30996
Published : Jan. 6, 2026, 9:15 p.m. | 27 minutes ago
Description : Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Sidepane WordPress Theme, Themify Themify Newsy, Themify Themify Folo, Themify Themify Edmin, Themify Bloggie, Themify Photobox, Themify Wigi, Themify Rezo, Themify Slide allows Upload a Web Shell to a Web Server.This issue affects Themify Sidepane WordPress Theme: from n/a through 1.9.8; Themify Newsy: from n/a through 1.9.9; Themify Folo: from n/a through 1.9.6; Themify Edmin: from n/a through 2.0.0; Bloggie: from n/a through 2.0.8; Photobox: from n/a through 2.0.1; Wigi: from n/a through 2.0.1; Rezo: from n/a through 1.9.7; Slide: from n/a through 1.7.5.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "06 Jan 2026",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-13744 - Improper Neutralization of Input During Web Page Generation vulnerability was identified in GitHub Enterprise Server that allowed rendering of malicious HTML",
"Content": "CVE ID : CVE-2025-13744
Published : Jan. 6, 2026, 9:15 p.m. | 27 minutes ago
Description : An Improper Neutralization of Input During Web Page Generation vulnerability was identified in GitHub Enterprise Server that allowed attacker controlled HTML to be rendered by the Filter component (search) across GitHub that could be used to exfiltrate sensitive information. An attacker would require permissions to create or modify the names of milestones, issues, pull requests, or similar entities that are rendered in the vulnerable filter/search components. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.20 and was fixed in versions 3.19.1, and 3.18.2, 3.17.8, 3.16.11, 3.15.15, and 3.14.20. This vulnerability was reported via the GitHub Bug Bounty program.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "06 Jan 2026",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-31642 - WordPress WPCHURCH plugin <= 2.7.0 - reflected cross site scripting (xss) vulnerability",
"Content": "CVE ID : CVE-2025-31642
Published : Jan. 6, 2026, 9:14 p.m. | 28 minutes ago
Description : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dasinfomedia WPCHURCH allows Reflected XSS.This issue affects WPCHURCH: from n/a through 2.7.0.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "06 Jan 2026",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-31051 - WordPress Plant - Gardening & Houseplants WordPress Theme <= 1.0.0 - sensitive data exposure vulnerability",
"Content": "CVE ID : CVE-2025-31051
Published : Jan. 6, 2026, 9:13 p.m. | 30 minutes ago
Description : Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EngoTheme Plant - Gardening & Houseplants WordPress Theme allows Retrieve Embedded Sensitive Data.This issue affects Plant - Gardening & Houseplants WordPress Theme: from n/a through 1.0.0.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "06 Jan 2026",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-14596 - Quartus Prime Pro Edition Installer Advisory",
"Content": "CVE ID : CVE-2025-14596
Published : Jan. 6, 2026, 9:06 p.m. | 36 minutes ago
Description : Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro Installer (SFX)

on Windows allows Search Order Hijacking.This issue affects Quartus Prime Pro: from 23.3 through 24.3.1.
Severity: 6.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "06 Jan 2026",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2023-5069 - CVE-2022-1234: Apache HTTP Server Cross-Site Request Forgery",
"Content": "CVE ID : CVE-2023-5069
Published : Jan. 6, 2026, 8:15 p.m. | 1 hour, 27 minutes ago
Description : Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "06 Jan 2026",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-47396 - Double Free in Graphics",
"Content": "CVE ID : CVE-2025-47396
Published : Jan. 6, 2026, 10:48 p.m. | 55 minutes ago
Description : Memory corruption occurs when a secure application is launched on a device with insufficient memory.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "07 Jan 2026",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-47395 - Buffer Over-read in WLAN Firmware",
"Content": "CVE ID : CVE-2025-47395
Published : Jan. 6, 2026, 10:48 p.m. | 55 minutes ago
Description : Transient DOS while parsing a WLAN management frame with a Vendor Specific Information Element.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "07 Jan 2026",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-47394 - Buffer Copy Without Checking Size of Input in DSP Service",
"Content": "CVE ID : CVE-2025-47394
Published : Jan. 6, 2026, 10:48 p.m. | 55 minutes ago
Description : Memory corruption when copying overlapping buffers during memory operations due to incorrect offset calculations.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "07 Jan 2026",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-47393 - Improper Validation of Array Index in Automotive Linux OS",
"Content": "CVE ID : CVE-2025-47393
Published : Jan. 6, 2026, 10:48 p.m. | 55 minutes ago
Description : Memory corruption when accessing resources in kernel driver.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "07 Jan 2026",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-47388 - Buffer Copy without Checking Size of Input in DSP Service",
"Content": "CVE ID : CVE-2025-47388
Published : Jan. 6, 2026, 10:48 p.m. | 55 minutes ago
Description : Memory corruption while passing pages to DSP with an unaligned starting address.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "07 Jan 2026",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-47380 - Untrusted Pointer Dereference in Camera",
"Content": "CVE ID : CVE-2025-47380
Published : Jan. 6, 2026, 10:48 p.m. | 55 minutes ago
Description : Memory corruption while preprocessing IOCTLs in sensors.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "07 Jan 2026",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-47369 - Information Exposure in Computer Vision",
"Content": "CVE ID : CVE-2025-47369
Published : Jan. 6, 2026, 10:48 p.m. | 55 minutes ago
Description : Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "07 Jan 2026",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-47356 - Double Free in Video",
"Content": "CVE ID : CVE-2025-47356
Published : Jan. 6, 2026, 10:48 p.m. | 55 minutes ago
Description : Memory Corruption when multiple threads concurrently access and modify shared resources.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "07 Jan 2026",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-47348 - Use of Uninitialized Variable in HLOS",
"Content": "CVE ID : CVE-2025-47348
Published : Jan. 6, 2026, 10:48 p.m. | 55 minutes ago
Description : Memory corruption while processing identity credential operations in the trusted application.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "07 Jan 2026",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-47346 - Out-of-bounds Write in HLOS",
"Content": "CVE ID : CVE-2025-47346
Published : Jan. 6, 2026, 10:48 p.m. | 55 minutes ago
Description : Memory corruption while processing a secure logging command in the trusted application.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "07 Jan 2026",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-47345 - Reusing a Nonce, Key Pair in Encryption in Automotive Platform",
"Content": "CVE ID : CVE-2025-47345
Published : Jan. 6, 2026, 10:48 p.m. | 55 minutes ago
Description : Cryptographic issue may occur while encrypting license data.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "07 Jan 2026",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹
{
"Source": "CVE FEED",
"Title": "CVE-2025-47344 - Time-of-check Time-of-use (TOCTOU) Race Condition in Camera Driver",
"Content": "CVE ID : CVE-2025-47344
Published : Jan. 6, 2026, 10:48 p.m. | 55 minutes ago
Description : Memory corruption while handling sensor utility operations.
Severity: 6.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "07 Jan 2026",
"Type": "Vulnerability"
}
🔹 t.me/cvedetector 🔹