CVE Database

Comprehensive vulnerability intelligence with advanced analytics

9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in xenioushk BWL Pro Voting Manager bwl-pro-voting-manager allows Blind SQL Injection.This issue affects BWL Pro Voting Manager: from n/a through

Published: Dec 30, 2025
Modified: Dec 31, 2025
EPSS: 0.04%
View Details
9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Cinerama - A WordPress Theme for Movie Studios and Filmmakers cinerama allows PHP Local File Inclusion.This issue affects Cinerama - A WordPress Theme for Movie Studios and Filmmakers: from n/a through

Published: Dec 30, 2025
Modified: Dec 31, 2025
EPSS: 0.15%
View Details
9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Aora aora allows PHP Local File Inclusion.This issue affects Aora: from n/a through

Published: Dec 30, 2025
Modified: Dec 31, 2025
EPSS: 0.15%
View Details
9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Puca puca allows PHP Local File Inclusion.This issue affects Puca: from n/a through

Published: Dec 30, 2025
Modified: Dec 31, 2025
EPSS: 0.15%
View Details
9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Greenmart greenmart allows PHP Local File Inclusion.This issue affects Greenmart: from n/a through

Published: Dec 30, 2025
Modified: Dec 31, 2025
EPSS: 0.15%
View Details
9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange WordPress Social Login and Register miniorange-login-openid allows PHP Local File Inclusion.This issue affects WordPress Social Login and Register: from n/a through

Published: Dec 30, 2025
Modified: Dec 31, 2025
EPSS: 0.15%
View Details
9.1

DVP-12SE11T - Out-of-bound memory write Vulnerability

Published: Dec 30, 2025
Modified: Jan 05, 2026
EPSS: 0.06%
View Details
9.1

DVP-12SE11T - Password Protection Bypass

Published: Dec 30, 2025
Modified: Jan 06, 2026
EPSS: 0.06%
View Details
9.1

Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment.

Published: Dec 30, 2025
Modified: Jan 13, 2026
EPSS: 0.04%
View Details
9.8

Authentication Bypass Using an Alternate Path or Channel vulnerability in Mobile Builder Mobile builder allows Authentication Abuse.This issue affects Mobile builder: from n/a through 1.4.2.

Published: Dec 29, 2025
Modified: Dec 31, 2025
EPSS: 0.09%
View Details
9.9

Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG allows Upload a Web Shell to a Web Server.This issue affects MapSVG: from n/a through 8.7.3.

Published: Dec 29, 2025
Modified: Dec 31, 2025
EPSS: 0.05%
View Details
9.8

givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload.

Published: Dec 29, 2025
Modified: Jan 02, 2026
Product: vvveb vvvebjs
EPSS: 0.06%
View Details
9.8

givanz VvvebJs 1.7.2 suffers from a File Upload vulnerability via save.php.

Published: Dec 29, 2025
Modified: Jan 02, 2026
Product: vvveb vvvebjs
EPSS: 0.06%
View Details
9.1

A critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSRF) and arbitrary file reading. The vulnerability stems from improper handling of user-supplied URLs in the "file_get_contents" function within the "save.php" file.

Published: Dec 29, 2025
Modified: Jan 07, 2026
Product: vvveb vvvebjs
EPSS: 0.04%
View Details
9.8

A stack-based buffer overflow exists in the GoAhead-Webs HTTP daemon on KuWFi 4G LTE AC900 devices with firmware 1.0.13. The /goform/formMultiApnSetting handler uses sprintf() to copy the user-supplied pincode parameter into a fixed 132-byte stack buffer with no bounds checks. This allows an attacker to corrupt adjacent stack memory, crash…

Published: Dec 29, 2025
Modified: Jan 15, 2026
Product: kuwfi ac900_firmware
EPSS: 0.10%
View Details
9.9

Improper Control of Generation of Code ('Code Injection') vulnerability in Mohammad I. Okfie IF AS Shortcode allows Code Injection.This issue affects IF AS Shortcode: from n/a through 1.2.

Published: Dec 29, 2025
Modified: Dec 31, 2025
EPSS: 0.05%
View Details
9.8

An issue in Fossorial fosrl/pangolin v.1.6.2 and before allows a remote attacker to escalate privileges via the 2FA component

Published: Dec 29, 2025
Modified: Jan 07, 2026
EPSS: 0.16%
View Details
9.8

A vulnerability was found in D-Link DIR-600 up to 2.15WWb02. Affected by this vulnerability is an unknown functionality of the file hedwig.cgi of the component HTTP Header Handler. The manipulation of the argument Cookie results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has…

Published: Dec 29, 2025
Modified: Jan 13, 2026
Product: dlink dir-600_firmware
EPSS: 0.07%
View Details
9.0

Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with specific permissions could be tricked into accessing a specially crafted link. This could lead to a malicious template being executed on the server, resulting in remote code execution. Versions 14.99.6 and 15.88.1 fix…

Published: Dec 29, 2025
Modified: Dec 31, 2025
Product: frappe frappe
EPSS: 0.13%
View Details
9.8

A type confusion in jsish 2.0 allows incorrect control flow during execution of the OP_NEXT opcode. When an “instanceof” expression uses an array element access as the left-hand operand inside a for-in loop, the instructions implementation leaves an additional array reference on the stack rather than consuming it during OP_INSTANCEOF.…

Published: Dec 29, 2025
Modified: Dec 31, 2025
Product: jsish jsish
EPSS: 0.09%
View Details
9.8

File upload vulnerability in machsol machpanel 8.0.32 allows attacker to gain a webshell.

Published: Dec 29, 2025
Modified: Dec 31, 2025
Product: machsol machpanel
EPSS: 0.06%
View Details
9.8

BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

Published: Dec 29, 2025
Modified: Dec 31, 2025
EPSS: 0.26%
View Details
9.8

WMPro developed by Sunnet has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

Published: Dec 29, 2025
Modified: Dec 31, 2025
Product: sun.net wmpro
EPSS: 0.26%
View Details
10.0

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.

Published: Dec 29, 2025
Modified: Jan 08, 2026
Product: smartertools smartermail
EPSS: 10.87%
View Details