CVE Database

Comprehensive vulnerability intelligence with advanced analytics

9.8

FreeImage 3.18.0 contains a Use After Free in PluginTARGA.cpp;loadRLE().

Published: Jan 14, 2026
View Details
10.0

Incorrect Privilege Assignment vulnerability in Modular DS allows Privilege Escalation.This issue affects Modular DS: from n/a through 2.5.1.

Published: Jan 14, 2026
Modified: Jan 14, 2026
EPSS: 0.04%
View Details
9.8

The News and Blog Designer Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1 via the template parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP…

Published: Jan 14, 2026
Modified: Jan 14, 2026
EPSS: 0.29%
View Details
9.8

The Integration Opvius AI for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.0. This is due to the `process_table_bulk_actions()` function processing user-supplied file paths without authentication checks, nonce verification, or path validation. This makes it possible for unauthenticated attackers to delete…

Published: Jan 14, 2026
Modified: Jan 14, 2026
EPSS: 0.09%
View Details
10.0

Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.7.0, there is a critical sandbox escape vulnerability in enclave-vm that allows untrusted, sandboxed JavaScript code to execute arbitrary code in the host Node.js runtime. When a tool invocation fails, enclave-vm exposes a host-side Error…

Published: Jan 14, 2026
Modified: Jan 14, 2026
EPSS: 0.10%
View Details
9.8

Webgrind 1.1 contains a remote command execution vulnerability that allows unauthenticated attackers to inject OS commands via the dataFile parameter in index.php. Attackers can execute arbitrary system commands by manipulating the dataFile parameter, such as using payload '0%27%26calc.exe%26%27' to execute commands on the target system.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.25%
View Details
9.8

eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by manipulating the login request. Attackers can exploit this flaw to upload malicious PHP files and execute remote commands on the vulnerable file management system.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.07%
View Details
9.8

Explorer32++ 1.3.5.531 contains a buffer overflow vulnerability in Structured Exception Handler (SEH) records that allows attackers to execute arbitrary code. Attackers can exploit the vulnerability by providing a long file name argument over 396 characters to corrupt the SEH chain and potentially execute malicious code.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.05%
View Details
9.8

Inbit Messenger versions 4.6.0 to 4.9.0 contain a remote stack-based buffer overflow vulnerability that allows unauthenticated attackers to execute arbitrary code by sending malformed network packets. Attackers can craft a specially designed payload targeting the messenger's network handler to overwrite the Structured Exception Handler (SEH) and execute shellcode on vulnerable…

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.13%
View Details
9.8

Inbit Messenger 4.6.0 - 4.9.0 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by exploiting a stack overflow in the messenger's protocol. Attackers can send specially crafted XML packets to port 10883 with a malicious payload to trigger the vulnerability and execute commands with…

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.19%
View Details
9.8

AimOne Video Converter 2.04 Build 103 contains a buffer overflow vulnerability in its registration form that causes application crashes. Attackers can generate a 7000-byte payload to trigger the denial of service and potentially exploit the software's registration mechanism.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.03%
View Details
9.8

Flame II HSPA USB Modem contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Internet Telcel\ApplicationController.exe' to execute arbitrary code with elevated system privileges.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.04%
View Details
9.8

WAGO 750-8212 PFC200 G2 2ETH RS firmware contains a privilege escalation vulnerability that allows attackers to manipulate user session cookies. Attackers can modify the cookie's 'name' and 'roles' parameters to elevate from ordinary user to administrative privileges without authentication.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.07%
View Details
9.8

Prowise Reflect version 1.0.9 contains a remote keystroke injection vulnerability that allows attackers to send keyboard events through an exposed WebSocket on port 8082. Attackers can craft malicious web pages to inject keystrokes, opening applications and typing arbitrary text by sending specific WebSocket messages.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.02%
View Details
9.8

Audio Conversion Wizard v2.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting memory with a specially crafted registration code. Attackers can generate a payload that overwrites the application's memory stack, potentially enabling remote code execution through a carefully constructed input buffer.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.18%
View Details
9.8

Tdarr 2.00.15 contains an unauthenticated remote code execution vulnerability in its Help terminal that allows attackers to inject and chain arbitrary commands. Attackers can exploit the lack of input filtering by chaining commands like `--help; curl .py | python` to execute remote code without authentication.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.32%
View Details
9.8

ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload potentially malicious files. Attackers can bypass file upload restrictions by using alternative file extensions .php2.php6.php7.phps.pht to execute arbitrary PHP code on the server.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.04%
View Details
9.8

e107 CMS version 3.2.1 contains multiple vulnerabilities that allow cross-site scripting (XSS) attacks. The first vulnerability is a reflected XSS that occurs in the news comment functionality when authenticated users interact with the comment form. An attacker can inject malicious JavaScript code through the URL parameter that gets executed when…

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.05%
View Details
9.8

VIAVIWEB Wallpaper Admin 1.0 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the img_id parameter. Attackers can send GET requests to edit_gallery_image.php with malicious img_id values to extract database information.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.03%
View Details
9.8

VIAVIWEB Wallpaper Admin 1.0 contains an unauthenticated remote code execution vulnerability in the image upload functionality. Attackers can upload a malicious PHP file through the add_gallery_image.php endpoint to execute arbitrary code on the server.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.20%
View Details
9.8

Covenant 0.1.3 - 0.5 contains a remote code execution vulnerability that allows attackers to craft malicious JWT tokens with administrative privileges. Attackers can generate forged tokens with admin roles and upload custom DLL payloads to execute arbitrary commands on the target system.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.52%
View Details
10.0

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.0.0 to 6.10.1, OpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter…

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.22%
View Details
9.8

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.1.0 through 7.1.8, FortiSIEM 7.0.0 through 7.0.4, FortiSIEM 6.7.0 through 6.7.10 may allow an attacker to execute unauthorized code or commands via crafted TCP requests.

Published: Jan 13, 2026
Modified: Jan 14, 2026
Product: fortinet fortisiem
EPSS: 0.07%
View Details
9.8

An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 through 7.0.1, FortiFone 3.0.13 through 3.0.23 allows an unauthenticated attacker to obtain the device configuration via crafted HTTP or HTTPS requests.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.50%
View Details
Page 1 Next