🛡️ CVE Vulnerability Database
CVE vulnerabilities with bilingual AI analysis tailored for Saudi Arabia
| CVE ID | Title / Description | Severity | CVSS | Status | Published |
|---|---|---|---|---|---|
| CVE-2026-21913 |
An Incorrect Initialization of Resource vulnerability in the Inte…
An Incorrect Initialization of Resource vulnerability in the Internal Device Manager (IDM) of Junipe…
|
HIGH |
7.5
|
✅ | Jan 15, 2026 |
| CVE-2026-21914 |
An Improper Locking vulnerability in the GTP plugin of Juniper Ne…
An Improper Locking vulnerability in the GTP plugin of Juniper Networks Junos OS on SRX Series allow…
|
HIGH |
7.5
|
✅ | Jan 15, 2026 |
| CVE-2026-21917 |
An Improper Validation of Syntactic Correctness of Input vulnerab…
An Improper Validation of Syntactic Correctness of Input vulnerability in the Web-Filtering module o…
|
HIGH |
7.5
|
✅ | Jan 15, 2026 |
| CVE-2026-21918 |
A Double Free vulnerability in the flow processing daemon (flowd)…
A Double Free vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SR…
|
HIGH |
7.5
|
✅ | Jan 15, 2026 |
| CVE-2026-21920 |
An Unchecked Return Value vulnerability in the DNS module of Juni…
An Unchecked Return Value vulnerability in the DNS module of Juniper Networks Junos OS on SRX Series…
|
HIGH |
7.5
|
✅ | Jan 15, 2026 |
| CVE-2026-22803 |
SvelteKit is a framework for rapidly developing robust, performan…
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Fr…
|
HIGH |
7.5
|
✅ | Jan 15, 2026 |
| CVE-2026-22863 |
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before…
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.6.0, node:crypto doesn't finaliz…
|
HIGH |
7.5
|
⚡ ✅ | Jan 15, 2026 |
| CVE-2026-23622 |
Easy!Appointments is a self hosted appointment scheduler. In 1.5.…
Easy!Appointments is a self hosted appointment scheduler. In 1.5.2 and earlier, application/core/EA_…
|
HIGH |
8.8
|
⚡ ✅ | Jan 15, 2026 |
| CVE-2026-21889 |
Weblate is a web based localization tool. Prior to 5.15.2, the sc…
Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directl…
|
HIGH |
7.5
|
✅ | Jan 14, 2026 |
| CVE-2026-22240 |
The vulnerability exists in BLUVOYIX due to an improper password …
The vulnerability exists in BLUVOYIX due to an improper password storage implementation and subseque…
|
HIGH |
7.5
|
✅ | Jan 14, 2026 |
| CVE-2026-22856 |
FreeRDP is a free implementation of the Remote Desktop Protocol. …
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race in the seri…
|
HIGH |
8.1
|
⚡ ✅ | Jan 14, 2026 |
| CVE-2026-23498 |
Shopware is an open commerce platform. From 6.7.0.0 to before 6.7…
Shopware is an open commerce platform. From 6.7.0.0 to before 6.7.6.1, a regression of CVE-2023-2017…
|
HIGH |
7.2
|
✅ | Jan 14, 2026 |
| CVE-2026-23512 |
SumatraPDF is a multi-format reader for Windows. In 3.5.2 and ear…
SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, there is a Untrusted Search P…
|
HIGH |
8.6
|
⚡ ✅ | Jan 14, 2026 |
| CVE-2025-12166 |
The Appointment Booking Calendar — Simply Schedule Appointments B…
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress …
|
HIGH |
7.5
|
✅ | Jan 14, 2026 |
| CVE-2025-13455 |
A vulnerability was reported in ThinkPlus configuration software …
A vulnerability was reported in ThinkPlus configuration software that could allow a local authentica…
|
HIGH |
7.8
|
✅ | Jan 14, 2026 |
| CVE-2025-14613 |
The GetContentFromURL plugin for WordPress is vulnerable to Serve…
The GetContentFromURL plugin for WordPress is vulnerable to Server-Side Request Forgery in all versi…
|
HIGH |
7.2
|
✅ | Jan 14, 2026 |
| CVE-2025-14615 |
The DASHBOARD BUILDER – WordPress plugin for Charts and Graphs pl…
The DASHBOARD BUILDER – WordPress plugin for Charts and Graphs plugin for WordPress is vulnerable to…
|
HIGH |
7.1
|
✅ | Jan 14, 2026 |
| CVE-2025-14770 |
The Shipping Rate By Cities plugin for WordPress is vulnerable to…
The Shipping Rate By Cities plugin for WordPress is vulnerable to SQL Injection via the 'city' param…
|
HIGH |
7.5
|
✅ | Jan 14, 2026 |
| CVE-2025-15266 |
The GeekyBot — Generate AI Content Without Prompt, Chatbot and Le…
The GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation plugin for WordPress …
|
HIGH |
7.2
|
✅ | Jan 14, 2026 |
| CVE-2025-15283 |
The Name Directory plugin for WordPress is vulnerable to Stored C…
The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name_d…
|
HIGH |
7.2
|
✅ | Jan 14, 2026 |
| CVE-2025-15378 |
The AJS Footnotes plugin for WordPress is vulnerable to Stored Cr…
The AJS Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'note_li…
|
HIGH |
7.2
|
✅ | Jan 14, 2026 |
| CVE-2025-40942 |
A vulnerability has been identified in TeleControl Server Basic (…
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.4). Affected …
|
HIGH |
8.8
|
✅ | Jan 13, 2026 |
| CVE-2025-40944 |
A vulnerability has been identified in SIMATIC ET 200AL IM 157-1 …
A vulnerability has been identified in SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0) (All versio…
|
HIGH |
7.5
|
✅ | Jan 13, 2026 |
| CVE-2025-46685 |
Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, conta…
Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File Wit…
|
HIGH |
7.5
|
✅ | Jan 13, 2026 |
| CVE-2025-59022 |
Backend users who had access to the recycler module could delete …
Backend users who had access to the recycler module could delete arbitrary data from any database ta…
|
HIGH |
8.1
|
✅ | Jan 13, 2026 |