CVE-2025-21266: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
Published Jan 14, 2025 · Updated Jun 9, 2026
Browse CVE records published in January 2025, with severity, affected products, CWE, KEV, and source-backed vulnerability context.
Showing 50 of 3893 matching CVEs · Page 8 of 78.
Windows Telephony Service Remote Code Execution Vulnerability
Published Jan 14, 2025 · Updated Jun 9, 2026
Windows Digital Media Elevation of Privilege Vulnerability
Published Jan 14, 2025 · Updated Jun 9, 2026
Windows Digital Media Elevation of Privilege Vulnerability
Published Jan 14, 2025 · Updated Jun 9, 2026
Windows Digital Media Elevation of Privilege Vulnerability
Published Jan 14, 2025 · Updated Jun 9, 2026
Windows Digital Media Elevation of Privilege Vulnerability
Published Jan 14, 2025 · Updated Jun 9, 2026
Windows WLAN AutoConfig Service Information Disclosure Vulnerability
Published Jan 14, 2025 · Updated Jun 9, 2026
Windows Digital Media Elevation of Privilege Vulnerability
Published Jan 14, 2025 · Updated Jun 9, 2026
Windows Telephony Service Remote Code Execution Vulnerability
Published Jan 14, 2025 · Updated Jun 9, 2026
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Published Jan 14, 2025 · Updated Jun 9, 2026
Windows Digital Media Elevation of Privilege Vulnerability
Published Jan 14, 2025 · Updated Jun 9, 2026
Windows Telephony Service Remote Code Execution Vulnerability
Published Jan 14, 2025 · Updated Jun 9, 2026
Windows Telephony Service Remote Code Execution Vulnerability
Published Jan 14, 2025 · Updated Jun 9, 2026
Windows Telephony Service Remote Code Execution Vulnerability
Published Jan 14, 2025 · Updated Jun 9, 2026
Windows Kerberos Information Disclosure Vulnerability
Published Jan 14, 2025 · Updated Jun 9, 2026
Windows Telephony Service Remote Code Execution Vulnerability
Published Jan 14, 2025 · Updated Jun 9, 2026
Windows Telephony Service Remote Code Execution Vulnerability
Published Jan 14, 2025 · Updated Jun 9, 2026
Windows Telephony Service Remote Code Execution Vulnerability
Published Jan 14, 2025 · Updated Jun 9, 2026
Windows Telephony Service Remote Code Execution Vulnerability
Published Jan 14, 2025 · Updated Jun 9, 2026
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
Published Jan 14, 2025 · Updated Jun 9, 2026
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
Published Jan 14, 2025 · Updated Jun 9, 2026
Windows Telephony Service Remote Code Execution Vulnerability
Published Jan 14, 2025 · Updated Jun 9, 2026
Secure Boot Security Feature Bypass Vulnerability
Published Jan 14, 2025 · Updated Jun 9, 2026
Windows BitLocker Information Disclosure Vulnerability
Published Jan 14, 2025 · Updated Jun 9, 2026
Windows BitLocker Information Disclosure Vulnerability
Published Jan 14, 2025 · Updated Jun 9, 2026
.NET Remote Code Execution Vulnerability
Published Jan 14, 2025 · Updated Jun 9, 2026
Windows Telephony Service Remote Code Execution Vulnerability
Published Jan 14, 2025 · Updated Jun 9, 2026
Windows Telephony Service Remote Code Execution Vulnerability
Published Jan 14, 2025 · Updated Jun 9, 2026
A vulnerability has been identified in SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0) (All versions), SIMATIC ET 200MP IM 155-5 PN HF (6ES7155-5AA00-0AC0) (All versions >= V4.2.0), SIMATIC ET 200SP IM 155-6 MF HF (6ES7155-6MU00-0CN0) (All versions), SIMATIC ET 200SP IM 155-6 PN HA (incl. SIPLUS variants) (All versions < V1.3), SIMATIC ET 200SP IM 155-6 PN R1 (6ES7155-6AU00-0HM0) (All versions < V6.0.1), SIMATIC ET 200SP IM 155-6 PN/2 HF (6ES7155-6AU01-0CN0) (All versions >= V4.2.0 < V4.2.5), SIMATIC ET 200SP IM 155-6 PN/3 HF (6ES7155-6AU30-0CN0) (All versions < V4.2.2), SIMATIC PN/MF Coupler (6ES7158-3MU10-0XA0) (All versions), SIMATIC PN/PN Coupler (6ES7158-3AD10-0XA0) (All versions < V6.0.0), SIPLUS ET 200MP IM 155-5 PN HF (6AG1155-5AA00-2AC0) (All versions >= V4.2.0), SIPLUS ET 200MP IM 155-5 PN HF (6AG1155-5AA00-7AC0) (All versions >= V4.2.0), SIPLUS ET 200MP IM 155-5 PN HF T1 RAIL (6AG2155-5AA00-1AC0) (All versions >= V4.2.0), SIPLUS ET 200SP IM 155-6 PN HF (6AG1155-6AU01-2CN0) (All versions >= V4.2.0 < V4.2.5), SIPLUS ET 200SP IM 155-6 PN HF (6AG1155-6AU01-7CN0) (All versions >= V4.2.0 < V4.2.5), SIPLUS ET 200SP IM 155-6 PN HF T1 RAIL (6AG2155-6AU01-1CN0) (All versions >= V4.2.0 < V4.2.5), SIPLUS ET 200SP IM 155-6 PN HF TX RAIL (6AG2155-6AU01-4CN0) (All versions >= V4.2.0 < V4.2.5), SIPLUS NET PN/PN Coupler (6AG2158-3AD10-4XA0) (All versions < V6.0.0). Affected devices do not properly handle S7 protocol session disconnect requests. When receiving a valid S7 protocol Disconnect Request (COTP DR TPDU) on TCP port 102, the devices enter an improper session state. This could allow an attacker to cause the device to become unresponsive, leading to a denial-of-service condition that requires a power cycle to restore normal operation.
Published Jan 13, 2026 · Updated Jun 9, 2026
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: QTS 5.2.8.3332 build 20251128 and later QuTS hero h5.2.8.3321 build 20251117 and later QuTS hero h5.3.2.3354 build 20251225 and later
Published Jan 2, 2026 · Updated Jun 9, 2026
Generation of Error Message Containing Sensitive Information vulnerability in Codriapp Innovation and Software Technologies Inc. HeyGarson allows Fuzzing for application mapping. This issue affects HeyGarson: through 30012026. NOTE: The vendor was contacted several times to verifying fixing process but did not respond in any way.
Published Jan 30, 2026 · Updated Jun 6, 2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tapandsign Technologies Software Inc. Tap&Sign allows Cross-Site Scripting (XSS). This issue affects Tap&Sign: through 23012026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Published Jan 23, 2026 · Updated Jun 6, 2026
Improper Restriction of Excessive Authentication Attempts, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Birebirsoft Software and Technology Solutions Sufirmam allows Brute Force, Password Recovery Exploitation. This issue affects Sufirmam: through 23012026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Published Jan 23, 2026 · Updated Jun 5, 2026
Authentication Bypass by Primary Weakness, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Birebirsoft Software and Technology Solutions Sufirmam allows Authentication Bypass, Password Recovery Exploitation. This issue affects Sufirmam: through 23012026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Published Jan 23, 2026 · Updated Jun 5, 2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kodmatic Computer Software Tourism Construction Industry and Trade Ltd. Co. Online Exam and Assessment allows SQL Injection. This issue affects Online Exam and Assessment: through 30012026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Published Jan 30, 2026 · Updated Jun 5, 2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Aida Computer Information Technology Inc. Hotel Guest Hotspot allows Reflected XSS. This issue affects Hotel Guest Hotspot: through 22012026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Published Jan 22, 2026 · Updated Jun 5, 2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aida Computer Information Technology Inc. Hotel Guest Hotspot allows SQL Injection. This issue affects Hotel Guest Hotspot: through 22012026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Published Jan 22, 2026 · Updated Jun 5, 2026
Authorization Bypass Through User-Controlled Key vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Exploitation of Trusted Identifiers. This issue affects Menu Panel: through 29012026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Published Jan 29, 2026 · Updated Jun 5, 2026
Session Fixation vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Session Hijacking. This issue affects Menu Panel: through 29012026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Published Jan 29, 2026 · Updated Jun 5, 2026
Session Fixation vulnerability in Akın Software Computer Import Export Industry and Trade Ltd. QR Menu allows Session Fixation. This issue affects QR Menu: before s1.05.12.
Published Jan 29, 2026 · Updated Jun 5, 2026
Improper Access Control vulnerability in Akın Software Computer Import Export Industry and Trade Ltd. QR Menu allows Authentication Abuse. This issue affects QR Menu: before s1.05.12.
Published Jan 29, 2026 · Updated Jun 5, 2026
Authorization Bypass Through User-Controlled Key vulnerability in EXERT Computer Technologies Software Ltd. Co. Education Management System allows Parameter Injection. This issue affects Education Management System: through 23.09.2025.
Published Jan 22, 2026 · Updated Jun 5, 2026
Authorization Bypass Through User-Controlled Key vulnerability in Solvera Software Services Trade Inc. Teknoera allows Exploitation of Trusted Identifiers. This issue affects Teknoera: through 01102025.
Published Jan 22, 2026 · Updated Jun 5, 2026
Unrestricted Upload of File with Dangerous Type vulnerability in Solvera Software Services Trade Inc. Teknoera allows File Content Injection. This issue affects Teknoera: through 01102025.
Published Jan 22, 2026 · Updated Jun 5, 2026
Delta Electronics DIAView has multiple vulnerabilities.
Published Jan 16, 2026 · Updated Jun 4, 2026
Delta Electronics DIAView has multiple vulnerabilities.
Published Jan 16, 2026 · Updated Jun 4, 2026
Pega Customer Service Framework versions 8.7.0 through 25.1.0 are affected by a Unrestricted file upload vulnerability, where a privileged user could potentially upload a malicious file.
Published Jan 13, 2026 · Updated Jun 3, 2026
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to modify protected parts of the file system.
Published Jan 27, 2025 · Updated Jun 3, 2026
An input validation issue was addressed. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3. An attacker on the local network may be able to corrupt process memory.
Published Jan 27, 2025 · Updated Jun 3, 2026
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to cause unexpected system termination.
Published Jan 27, 2025 · Updated Jun 3, 2026
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. Deleting a conversation in Messages may expose user contact information in system logging.
Published Jan 27, 2025 · Updated Jun 3, 2026