Latest Security Vulnerabilities
Friday January 23, 2026
Thursday January 22, 2026
Friday January 16, 2026
Tuesday January 13, 2026
Microsoft Windows 10
CVE-2026-20804 Jan 2026: Windows Hello Tampering VulnerabilityCVE-2026-20805 Jan 2026: Desktop Window Manager Information Disclosure Vulnerability
CVE-2026-20809 Jan 2026: Windows Kernel Memory Elevation of Privilege Vulnerability
CVE-2026-20810 Jan 2026: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-20812 Jan 2026: LDAPÂ Tampering Vulnerability
CVE-2026-20814 Jan 2026: DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2026-20816 Jan 2026: Windows Installer Elevation of Privilege Vulnerability
CVE-2026-20821 Jan 2026: Remote Procedure Call Information Disclosure Vulnerability
CVE-2026-20822 Jan 2026: Windows Graphics Component Elevation of Privilege Vulnerability
And others...
Microsoft Windows Server 2025
CVE-2026-20808 Jan 2026: Windows File Explorer Elevation of Privilege VulnerabilityCVE-2026-20815 Jan 2026: Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability
CVE-2026-20830 Jan 2026: Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability
CVE-2026-20835 Jan 2026: Capability Access Management Service (camsvc) Information Disclosure Vulnerability
CVE-2026-20851 Jan 2026: Capability Access Management Service (camsvc) Information Disclosure Vulnerability
CVE-2026-20854 Jan 2026: Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerabi
CVE-2026-20859 Jan 2026: Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
CVE-2026-20870 Jan 2026: Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
CVE-2026-20876 Jan 2026: Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
And others...
Microsoft Windows Server 2022
CVE-2026-20811 Jan 2026: Win32k Elevation of Privilege VulnerabilityCVE-2026-20817 Jan 2026: Windows Error Reporting Service Elevation of Privilege Vulnerability
CVE-2026-20820 Jan 2026: Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2026-20838 Jan 2026: Windows Kernel Information Disclosure Vulnerability
CVE-2026-20842 Jan 2026: Microsoft DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-20863 Jan 2026: Win32k Elevation of Privilege Vulnerability
CVE-2026-20871 Jan 2026: Desktop Windows Manager Elevation of Privilege Vulnerability
CVE-2026-20920 Jan 2026: Win32k Elevation of Privilege Vulnerability
CVE-2026-20922 Jan 2026: Windows NTFS Remote Code Execution Vulnerability
Microsoft Windows 11 2h2
CVE-2026-20819 Jan 2026: Windows Virtualization-Based Security (VBS) Information Disclosure VulnerabilityCVE-2026-20938 Jan 2026: Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
CVE-2026-20962 Jan 2026: Dynamic Root of Trust for Measurement (DRTM) Information Disclosure Vulnerability
Microsoft Sharepoint Server 2016
CVE-2026-20947 Jan 2026: Microsoft SharePoint Server Remote Code Execution VulnerabilityCVE-2026-20948 Jan 2026: Microsoft Word Remote Code Execution Vulnerability
CVE-2026-20951 Jan 2026: Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-20958 Jan 2026: Microsoft SharePoint Information Disclosure Vulnerability
CVE-2026-20959 Jan 2026: Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-20963 Jan 2026: Microsoft SharePoint Remote Code Execution Vulnerability
Wednesday January 7, 2026
Sunday December 28, 2025
Unclassified
CVE-2025-15122 JeecgBoot <=3.9.0: Improper Auth via loadDatarule (Remote)CVE-2025-15119 JeecgBoot <3.9.0 remote auth flaw via deptId (CVE-2025-15119)
CVE-2025-15120 JeecgBoot <=3.9.0: getDeptRoleList Auth Bypass
CVE-2025-15123 JeecgBoot <=3.9.0 Improper Auth via SysDepartPermission DataRule
CVE-2025-15125 Unauthorized Access via departId manipulation in JeecgBoot 3.9.0
CVE-2025-15126 JeecgBoot <3.9.0 Improper Auth via getPositionUserList (PositionId)
CVE-2025-15121 JeecgBoot <3.9.0 Info Disclosure via departId
CVE-2025-15131 ZSPACE Z4Pro+ 1.0.0440024 - HTTP POST Request Handler Command Injection
CVE-2025-15124 JeecgBoot <=3.9.0 Improper Auth via departId in getParameterMap Remote
And others...
Saturday December 27, 2025
Unclassified
CVE-2025-15122 JeecgBoot <=3.9.0: Improper Auth via loadDatarule (Remote)CVE-2025-15119 JeecgBoot <3.9.0 remote auth flaw via deptId (CVE-2025-15119)
CVE-2025-15120 JeecgBoot <=3.9.0: getDeptRoleList Auth Bypass
CVE-2025-15123 JeecgBoot <=3.9.0 Improper Auth via SysDepartPermission DataRule
CVE-2025-15125 Unauthorized Access via departId manipulation in JeecgBoot 3.9.0
CVE-2025-15126 JeecgBoot <3.9.0 Improper Auth via getPositionUserList (PositionId)
CVE-2025-15121 JeecgBoot <3.9.0 Info Disclosure via departId
CVE-2025-15131 ZSPACE Z4Pro+ 1.0.0440024 - HTTP POST Request Handler Command Injection
CVE-2025-15124 JeecgBoot <=3.9.0 Improper Auth via departId in getParameterMap Remote
And others...
Friday December 26, 2025
Gitea
CVE-2025-68940 Gitea 1.22.5: Branch Deletion Permissions Not Properly EnforcedCVE-2025-68939 Gitea <1.23.0: Attachment API Bypasses Forbidden Extension Check
CVE-2025-68941 Gitea <1.22.3: Limited-API-token can read private resources
CVE-2025-68942 Gitea <1.22.2 XSS: search box uses v-html (v-text missing)
CVE-2025-68943 Gitea <=1.21.7: Login Time Disclosure via explore/users Order
CVE-2025-68945 Gitea <1.21.2: Anonymous View of Private Projects
CVE-2025-68944 Token Scope Propagation Flaw in Gitea <1.22.2 (Package Registry Access Control)
CVE-2025-68946 Gitea <1.20.1 XSS via forbidden URL Scheme
CVE-2025-68938 Gitea <1.25.2 Release deletion auth bypass
Eaton
CVE-2025-59887 Eaton UPS Companion Improper Auth of Lib Files Leading to Code ExecCVE-2025-59888 Eaton UPS Companion Installer Quotation Flaw Allows RCE
CVE-2025-67450 Eaton UPS Companion insecure lib loading leads to RCE
Unclassified
CVE-2025-15122 JeecgBoot <=3.9.0: Improper Auth via loadDatarule (Remote)CVE-2025-15119 JeecgBoot <3.9.0 remote auth flaw via deptId (CVE-2025-15119)
CVE-2025-15120 JeecgBoot <=3.9.0: getDeptRoleList Auth Bypass
CVE-2025-15123 JeecgBoot <=3.9.0 Improper Auth via SysDepartPermission DataRule
CVE-2025-15125 Unauthorized Access via departId manipulation in JeecgBoot 3.9.0
CVE-2025-15126 JeecgBoot <3.9.0 Improper Auth via getPositionUserList (PositionId)
CVE-2025-15121 JeecgBoot <3.9.0 Info Disclosure via departId
CVE-2025-15131 ZSPACE Z4Pro+ 1.0.0440024 - HTTP POST Request Handler Command Injection
CVE-2025-15124 JeecgBoot <=3.9.0 Improper Auth via departId in getParameterMap Remote
And others...
N8n
CVE-2025-68668 n8n Pyodide Sandbox Bypass Python Code Node (<=1.99)CVE-2025-68697 n8n 2.0.0 File System Access Bypass in Code Node Pre2.0.0 Auth Escalation
CVE-2025-61914 n8n 1.114.0: Stored XSS in Respond to Webhook node

