TheHackerWire
banner
thehackerwire.bsky.social
TheHackerWire
@thehackerwire.bsky.social
Knowledge is the ultimate weapon against cyber threats.
🟠 CVE-2026-21452 - High (7.5)

MessagePack for Java is a serializer implementation for Java. A denial-of-service vulnerability e...

https://www.thehackerwire.com/vulnerability/CVE-2026-21452/

#infosec #cybersecurity #CVE #vulnerability #security
January 2, 2026 at 10:00 PM
🟠 CVE-2026-21433 - High (7.7)

Emlog is an open source website building system. Versions up to and including 2.5.19 are vulnerab...

https://www.thehackerwire.com/vulnerability/CVE-2026-21433/

#infosec #cybersecurity #CVE #vulnerability #security
January 2, 2026 at 7:51 PM
🟠 CVE-2025-69414 - High (8.5)

Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /...

https://www.thehackerwire.com/vulnerability/CVE-2025-69414/

#infosec #cybersecurity #CVE #vulnerability #security
January 2, 2026 at 5:18 PM
🟠 CVE-2025-69414 - High (8.5)

Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /...

https://www.thehackerwire.com/vulnerability/CVE-2025-69414/

#infosec #cybersecurity #CVE #vulnerability #security
January 2, 2026 at 5:18 PM
🟠 CVE-2025-66723 - High (7.5)

inMusic Brands Engine DJ 4.3.0 suffers from Insecure Permissions due to exposed HTTP service in t...

https://www.thehackerwire.com/vulnerability/CVE-2025-66723/

#infosec #cybersecurity #CVE #vulnerability #security
January 2, 2026 at 3:22 PM
🟠 CVE-2025-13029 - High (7.5)

The Knowband Mobile App Builder WordPress plugin before 3.0.0 does not have authorisation when de...

https://www.thehackerwire.com/vulnerability/CVE-2025-13029/

#infosec #cybersecurity #CVE #vulnerability #security
January 2, 2026 at 3:22 PM
🟠 CVE-2025-15430 - High (8.8)

A vulnerability was detected in UTT 进取 512W 1.7.7-171114. Affected by this issue is the funct...

https://www.thehackerwire.com/vulnerability/CVE-2025-15430/

#infosec #cybersecurity #CVE #vulnerability #security
January 2, 2026 at 7:01 AM
🟠 CVE-2025-15429 - High (8.8)

A security vulnerability has been detected in UTT 进取 512W 1.7.7-171114. Affected by this vuln...

https://www.thehackerwire.com/vulnerability/CVE-2025-15429/

#infosec #cybersecurity #CVE #vulnerability #security
January 2, 2026 at 7:00 AM
🟠 CVE-2025-15431 - High (8.8)

A flaw has been found in UTT 进取 512W 1.7.7-171114. This affects the function strcpy of the fi...

https://www.thehackerwire.com/vulnerability/CVE-2025-15431/

#infosec #cybersecurity #CVE #vulnerability #security
January 2, 2026 at 7:00 AM
🟠 CVE-2025-15428 - High (8.8)

A weakness has been identified in UTT 进取 512W 1.7.7-171114. Affected is the function strcpy o...

https://www.thehackerwire.com/vulnerability/CVE-2025-15428/

#infosec #cybersecurity #CVE #vulnerability #security
January 2, 2026 at 6:00 AM
🔴 CVE-2025-14998 - Critical (9.8)

The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all...

https://www.thehackerwire.com/vulnerability/CVE-2025-14998/

#infosec #cybersecurity #CVE #vulnerability #security
January 2, 2026 at 3:49 AM
🔴 CVE-2025-68620 - Critical (9.1)

Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2...

https://www.thehackerwire.com/vulnerability/CVE-2025-68620/

#infosec #cybersecurity #CVE #vulnerability #security
January 1, 2026 at 8:01 PM
🟠 CVE-2025-55065 - High (7.5)

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

https://www.thehackerwire.com/vulnerability/CVE-2025-55065/

#infosec #cybersecurity #CVE #vulnerability #security
January 1, 2026 at 8:01 PM
🟠 CVE-2025-68272 - High (7.5)

Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service...

https://www.thehackerwire.com/vulnerability/CVE-2025-68272/

#infosec #cybersecurity #CVE #vulnerability #security
January 1, 2026 at 6:22 PM
🔴 CVE-2025-66398 - Critical (9.6)

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2....

https://www.thehackerwire.com/vulnerability/CVE-2025-66398/

#infosec #cybersecurity #CVE #vulnerability #security
January 1, 2026 at 6:22 PM
🟠 CVE-2025-68272 - High (7.5)

Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service...

https://www.thehackerwire.com/vulnerability/CVE-2025-68272/

#infosec #cybersecurity #CVE #vulnerability #security
January 1, 2026 at 6:22 PM
🔴 CVE-2025-66398 - Critical (9.6)

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2....

https://www.thehackerwire.com/vulnerability/CVE-2025-66398/

#infosec #cybersecurity #CVE #vulnerability #security
January 1, 2026 at 6:21 PM
🟠 CVE-2025-11157 - High (7.8)

A high-severity remote code execution vulnerability exists in feast-dev/feast version 0.53.0, spe...

https://www.thehackerwire.com/vulnerability/CVE-2025-11157/

#infosec #cybersecurity #CVE #vulnerability #security
January 1, 2026 at 7:37 AM
🔴 CVE-2025-69288 - Critical (9.1)

Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any a...

https://www.thehackerwire.com/vulnerability/CVE-2025-69288/

#infosec #cybersecurity #CVE #vulnerability #security
December 31, 2025 at 11:00 PM
🟠 CVE-2025-30628 - High (8.5)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerabilit...

https://www.thehackerwire.com/vulnerability/CVE-2025-30628/

#infosec #cybersecurity #CVE #vulnerability #security
December 31, 2025 at 9:00 PM
🟠 CVE-2025-28949 - High (8.5)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerabilit...

https://www.thehackerwire.com/vulnerability/CVE-2025-28949/

#infosec #cybersecurity #CVE #vulnerability #security
December 31, 2025 at 9:00 PM
🟠 CVE-2025-15389 - High (8.8)

VPN Firewall developed by QNO Technology has an OS Command Injection vulnerability, allowing auth...

https://www.thehackerwire.com/vulnerability/CVE-2025-15389/

#infosec #cybersecurity #CVE #vulnerability #security
December 31, 2025 at 10:36 AM
🟠 CVE-2025-15387 - High (8.8)

VPN Firewall developed by QNO Technology has a Insufficient Entropy vulnerability, allowing unaut...

https://www.thehackerwire.com/vulnerability/CVE-2025-15387/

#infosec #cybersecurity #CVE #vulnerability #security
December 31, 2025 at 9:18 AM
🟠 CVE-2025-15388 - High (8.8)

VPN Firewall developed by QNO Technology has an OS Command Injection vulnerability, allowing auth...

https://www.thehackerwire.com/vulnerability/CVE-2025-15388/

#infosec #cybersecurity #CVE #vulnerability #security
December 31, 2025 at 9:18 AM
🟠 CVE-2025-15270 - High (8.8)

FontForge SFD File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability...

https://www.thehackerwire.com/vulnerability/CVE-2025-15270/

#infosec #cybersecurity #CVE #vulnerability #security
December 31, 2025 at 7:49 AM