CVE Database

Comprehensive vulnerability intelligence with advanced analytics

10.0

Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. The title and oIP parameters are also used.

Published: Dec 27, 2025
Modified: Jan 09, 2026
EPSS: 0.41%
View Details
9.8

FreshRSS is a free, self-hostable RSS aggregator. Prior to version 1.28.0, FreshRSS uses cryptographically weak random number generators (mt_rand() and uniqid()) to generate remember-me authentication tokens and challenge-response nonces. This allows attackers to predict valid session tokens, leading to account takeover through persistent session hijacking. The remember-me tokens provide permanent…

Published: Dec 27, 2025
Modified: Dec 31, 2025
Product: freshrss freshrss
EPSS: 0.06%
View Details
9.9

StreamVault is a video download integration solution. Prior to version 251126, a Remote Code Execution (RCE) vulnerability exists in the stream-vault application (SpiritApplication). The application allows administrators to configure yt-dlp arguments via the /admin/api/saveConfig endpoint without sufficient validation. These arguments are stored globally and subsequently used in YtDlpUtil.java when constructing…

Published: Dec 27, 2025
Modified: Dec 29, 2025
EPSS: 0.29%
View Details
9.9

n8n is an open source workflow automation platform. From version 1.0.0 to before 2.0.0, a sandbox bypass vulnerability exists in the Python Code Node that uses Pyodide. An authenticated user with permission to create or modify workflows can exploit this vulnerability to execute arbitrary commands on the host system running…

Published: Dec 26, 2025
Modified: Jan 05, 2026
Product: n8n n8n
EPSS: 0.10%
View Details
9.8

Time-based blind SQL Injection vulnerability in Cloudlog v2.6.15 at the endpoint /index.php/logbookadvanced/search in the qsoresults parameter.

Published: Dec 26, 2025
Modified: Dec 31, 2025
Product: magicbug cloudlog
EPSS: 0.04%
View Details
9.8

IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application.

Published: Dec 26, 2025
Modified: Dec 31, 2025
Product: ibm api_connect
EPSS: 0.37%
View Details
9.8

Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered a vulnerability in camera video analytics that Improper input validation. This vulnerability could allow an attacker to execute specific commands on the user's host PC.The manufacturer has released patch firmware for…

Published: Dec 26, 2025
Modified: Jan 07, 2026
Product: hanwhavision pnm-9322vqp_firmware
EPSS: 0.10%
View Details
9.8

Telenium Online Web Application is vulnerable due to a Perl script that is called to load the login page. Due to improper input validation, an attacker can inject arbitrary Perl code through a crafted HTTP request, leading to remote code execution on the server.

Published: Dec 24, 2025
Modified: Dec 29, 2025
EPSS: 1.23%
View Details
9.1

Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload with resultant code execution.

Published: Dec 24, 2025
Modified: Jan 02, 2026
EPSS: 0.46%
View Details
9.8

devolo dLAN 500 AV Wireless+ 3.1.0-1 contains an authentication bypass vulnerability that allows attackers to enable hidden services through the htmlmgr CGI script. Attackers can enable telnet and remote shell services, reboot the device, and gain root access without a password by manipulating system configuration parameters.

Published: Dec 24, 2025
Modified: Dec 29, 2025
EPSS: 0.10%
View Details
9.8

FaceSentry Access Control System 6.4.8 contains a critical authentication vulnerability with hard-coded SSH credentials for the wwwuser account. Attackers can leverage the insecure sudoers configuration to escalate privileges and gain root access by executing sudo commands without authentication.

Published: Dec 24, 2025
Modified: Dec 31, 2025
Product: iwt facesentry_access_control_system_firmware
EPSS: 0.27%
View Details
9.8

Rifatron 5brid DVR contains an unauthenticated vulnerability in the animate.cgi script that allows unauthorized access to live video streams. Attackers can exploit the Mobile Web Viewer module by specifying channel numbers to retrieve sequential video snapshots without authentication.

Published: Dec 24, 2025
Modified: Dec 29, 2025
EPSS: 0.10%
View Details
9.8

V-SOL GPON/EPON OLT Platform v2.03 contains a privilege escalation vulnerability that allows normal users to gain administrative access by manipulating the user role parameter. Attackers can send a crafted HTTP POST request to the user management endpoint with 'user_role_mod' set to integer value '1' to elevate their privileges.

Published: Dec 24, 2025
Modified: Dec 29, 2025
EPSS: 0.10%
View Details
9.8

iSeeQ Hybrid DVR WH-H4 1.03R contains an unauthenticated vulnerability in the get_jpeg script that allows unauthorized access to live video streams. Attackers can retrieve video snapshots from specific camera channels by sending requests to the /cgi-bin/get_jpeg endpoint without authentication.

Published: Dec 24, 2025
Modified: Dec 29, 2025
EPSS: 0.11%
View Details
9.8

Smartwares HOME easy 1.0.9 contains an authentication bypass vulnerability that allows unauthenticated attackers to access administrative web pages by disabling JavaScript. Attackers can navigate to multiple administrative endpoints and to bypass client-side validation and access sensitive system information.

Published: Dec 24, 2025
Modified: Dec 29, 2025
EPSS: 0.21%
View Details
9.8

GNU Barcode 0.99 contains a buffer overflow vulnerability in its code 93 encoding process that allows attackers to trigger memory corruption. Attackers can exploit boundary errors during input file processing to potentially execute arbitrary code on the affected system.

Published: Dec 24, 2025
Modified: Dec 29, 2025
EPSS: 0.07%
View Details
9.8

NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft malicious XML files with DTD parameter entities to retrieve arbitrary system files through an out-of-band channel attack.

Published: Dec 24, 2025
Modified: Dec 29, 2025
EPSS: 0.04%
View Details
9.8

FLIR AX8 Thermal Camera 1.32.16 contains hard-coded SSH and web panel credentials that cannot be changed through normal camera operations. Attackers can exploit these persistent credentials to gain unauthorized shell access and login to multiple camera interfaces using predefined username and password combinations.

Published: Dec 24, 2025
Modified: Jan 05, 2026
Product: flir flir_ax8_firmware
EPSS: 0.13%
View Details
9.8

Anviz AIM CrossChex Standard 4.3.6.0 contains a CSV injection vulnerability that allows attackers to execute commands by inserting malicious formulas in user import fields. Attackers can craft payloads in fields like 'Name', 'Gender', or 'Position' to trigger Excel macro execution when importing user data.

Published: Dec 24, 2025
Modified: Dec 29, 2025
EPSS: 0.08%
View Details
9.8

Synaccess netBooter NP-02x/NP-08x 6.8 contains an authentication bypass vulnerability in the webNewAcct.cgi script that allows unauthenticated attackers to create admin user accounts. Attackers can exploit the missing control check by sending crafted POST requests to create administrative accounts and gain unauthorized control over power supply management.

Published: Dec 24, 2025
Modified: Dec 29, 2025
EPSS: 0.23%
View Details
9.1

Server-Side Request Forgery (SSRF) vulnerability in Yannick Lefebvre Link Library link-library allows Server Side Request Forgery.This issue affects Link Library: from n/a through

Published: Dec 24, 2025
Modified: Dec 29, 2025
EPSS: 0.04%
View Details
9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks Integration for Contact Form 7 HubSpot cf7-hubspot allows Blind SQL Injection.This issue affects Integration for Contact Form 7 HubSpot: from n/a through

Published: Dec 24, 2025
Modified: Dec 29, 2025
EPSS: 0.04%
View Details
9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in captivateaudio Captivate Sync captivatesync-trade allows Blind SQL Injection.This issue affects Captivate Sync: from n/a through

Published: Dec 24, 2025
Modified: Dec 29, 2025
EPSS: 0.04%
View Details
9.8

Missing Authorization vulnerability in JayBee Twitch Player ttv-easy-embed-player allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Twitch Player: from n/a through

Published: Dec 24, 2025
Modified: Dec 29, 2025
EPSS: 0.05%
View Details