Daily digest
Thursday 1 January 2026
21 new CVEs this day, in line with the recent average. Severity skewed high: 2 critical and 9 high, 52% of the total. 2 arrived with exploitation evidence or public exploit code already attached. signalk was the most-affected vendor with 6.
New this day, ranked by depth score
The 12 that matter most of the 21 published.
CVE-2025-66398Critical· 9.6PoCSignal K Server is a server application that runs on a central hub in a boat
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the internal state (`restoreFilePath`) of the server via the `/skServer/validateBackup` endpoi…
CVE-2025-68620Critical· 9.1Signal K Server is a server application that runs on a central hub in a boat
Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 expose two features that can be chained together to steal JWT authentication tokens without any prior authentication. The attack combi…
CVE-2025-47411High· 8.1A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows them to swap the username of an existing user with that of an administrator. This vulner…
A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows them to swap the username of an existing user with that of an administrator. This vulner…
CVE-2025-48769High· 8.1Use After Free vulnerability was discovered in fs/vfs/fs_rename code of the Apache NuttX RTOS, that due recursive implementation and single buffer use by two different pointer variables allowed arbitrary user provided size buffer realloc…
Use After Free vulnerability was discovered in fs/vfs/fs_rename code of the Apache NuttX RTOS, that due recursive implementation and single buffer use by two different pointer variables allowed arbitrary user provided size buffer realloc…
CVE-2025-11157High· 7.8A high-severity remote code execution vulnerability exists in feast-dev/feast version 0.53.0, specifically in the Kubernetes materializer job located at `feast/sdk/python/feast/infra/compute_engines/kubernetes/main.py`
A high-severity remote code execution vulnerability exists in feast-dev/feast version 0.53.0, specifically in the Kubernetes materializer job located at `feast/sdk/python/feast/infra/compute_engines/kubernetes/main.py`. The vulnerability…
CVE-2025-68273Medium· 5.3PoCSignal K Server is a server application that runs on a central hub in a boat
Signal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure vulnerability in versions prior to 2.19.0 allows any user to retrieve sensitive system information, including the ful…
CVE-2025-68272High· 7.5Signal K Server is a server application that runs on a central hub in a boat
Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service (DoS) vulnerability in versions prior to 2.19.0 allows an unauthenticated attacker to crash the SignalK Server by flooding the access reque…
CVE-2025-68619High· 7.2Signal K Server is a server application that runs on a central hub in a boat
Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the appstore interface allow administrators to install npm packages through a REST API endpoint. While the endpoint validates that …
CVE-2025-15410High· 7.3A vulnerability was identified in code-projects Online Guitar Store 1.0
A vulnerability was identified in code-projects Online Guitar Store 1.0. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument L_email leads to sql injection. It is possible to init…
CVE-2025-15409High· 7.3A vulnerability was determined in code-projects Online Guitar Store 1.0
A vulnerability was determined in code-projects Online Guitar Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/Delete_product.php. Executing a manipulation of the argument del_pro can lead to sql i…
CVE-2025-15408High· 7.3A vulnerability was found in code-projects Online Guitar Store 1.0
A vulnerability was found in code-projects Online Guitar Store 1.0. Affected is an unknown function of the file /admin/Create_product.php. Performing a manipulation of the argument dre_title results in sql injection. The attack is possib…
CVE-2025-15407High· 7.3A vulnerability has been found in code-projects Online Guitar Store 1.0
A vulnerability has been found in code-projects Online Guitar Store 1.0. This impacts an unknown function of the file /admin/Create_category.php. Such manipulation of the argument dre_Ctitle leads to sql injection. The attack can be exec…
Most-affected vendors
By CVEs published in the period.