CVE Database

Comprehensive vulnerability intelligence with advanced analytics

5.9

Outray openSource ngrok alternative. Prior to 0.1.5, this vulnerability allows a user i.e a free plan user to get more than the desired subdomains due to lack of db transaction lock mechanisms in main/apps/web/src/routes/api/$orgSlug/subdomains/index.ts. This vulnerability is fixed in 0.1.5.

Published: Jan 14, 2026
EPSS: 0.04%
View Details
7.5

Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the serverName parameter of the sub_65A28 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

Published: Jan 14, 2026
Modified: Jan 14, 2026
EPSS: 0.04%
View Details
7.5

Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the serviceName parameter of the sub_65A28 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

Published: Jan 14, 2026
Modified: Jan 14, 2026
EPSS: 0.04%
View Details
8.4

An insecure authentication mechanism in the safe_exec.sh startup script of Blurams Flare Camera version 24.1114.151.929 and earlier allows an attacker with physical access to the device to execute arbitrary commands with root privileges, if file /opt/images/public_key.der is not present in the file system. The vulnerability can be triggered by providing…

Published: Jan 14, 2026
Modified: Jan 14, 2026
EPSS: 0.06%
View Details
6.1

A stored cross-site scripting (XSS) vulnerability exists in pH7Software pH7-Social-Dating-CMS 17.9.1 in the user profile Description field.

Published: Jan 14, 2026
Modified: Jan 14, 2026
EPSS: 0.03%
View Details

html2pdf.js converts any webpage or element into a printable PDF entirely client-side. Prior to 0.14.0, html2pdf.js contains a cross-site scripting (XSS) vulnerability when given a text source rather than an element. This text is not sufficiently sanitized before being attached to the DOM, allowing malicious scripts to be run on…

Published: Jan 14, 2026
EPSS: 0.05%
View Details

BlackSheep is an asynchronous web framework to build event based web applications with Python. Prior to 2.4.6, the HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create…

Published: Jan 14, 2026
EPSS: 0.05%
View Details

Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode with Allowlist mode enabled, certain shell built-ins can still be executed without appearing in the allowlist and without requiring user approval. This allows an attacker via indirect or…

Published: Jan 14, 2026
EPSS: 0.05%
View Details
6.1

AliasVault is a privacy-first password manager with built-in email aliasing. AliasVault Android versions 0.24.0 through 0.25.2 contained an issue in how passkey requests from Android apps were validated. Under certain local conditions, a malicious app could attempt to obtain a passkey response for a site it was not authorized to…

Published: Jan 14, 2026
EPSS: 0.01%
View Details

Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. This vulnerability is fixed in 5.15.2.

Published: Jan 14, 2026
EPSS: 0.05%
View Details
9.8

FreeImage 3.18.0 contains a Use After Free in PluginTARGA.cpp;loadRLE().

Published: Jan 14, 2026
EPSS: 0.04%
View Details
6.5

Paessler PRTG Network Monitor before 25.4.114 allows Denial-of-Service (DoS) by an authenticated attacker via the Notification Contacts functionality.

Published: Jan 14, 2026
Modified: Jan 14, 2026
EPSS: 0.04%
View Details
5.4

Paessler PRTG Network Monitor before 25.4.114 allows XSS by an unauthenticated attacker via the filter parameter.

Published: Jan 14, 2026
Modified: Jan 14, 2026
EPSS: 0.07%
View Details
6.1

Paessler PRTG Network Monitor before 25.4.114 allows XSS by an unauthenticated attacker via the tag parameter.

Published: Jan 14, 2026
Modified: Jan 14, 2026
EPSS: 0.07%
View Details
6.1

A vulnerability in the boot process of Blurams Flare Camera version 24.1114.151.929 and earlier allows a physically proximate attacker to hijack the boot mechanism and gain a bootloader shell via the UART interface. This is achieved by inducing a read error from the SPI flash memory during the boot, by…

Published: Jan 14, 2026
Modified: Jan 14, 2026
EPSS: 0.01%
View Details
5.5

Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attacks against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of…

Published: Jan 14, 2026
EPSS: 0.03%
View Details
6.5

A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-factor authentication requirements. Successful exploitation could allow an attacker to create an admin user account without the necessary multi-factor authentication, thereby compromising the integrity of secured access to the system.

Published: Jan 14, 2026
EPSS: 0.05%
View Details
7.2

Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially leading to unauthorized data access or data manipulation.

Published: Jan 14, 2026
EPSS: 0.07%
View Details
7.2

Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially leading to unauthorized data access or data manipulation.

Published: Jan 14, 2026
EPSS: 0.07%
View Details
7.2

Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially leading to unauthorized data access or data manipulation.

Published: Jan 14, 2026
EPSS: 0.07%
View Details

TinyOS versions up to and including 2.1.2 contain a global buffer overflow vulnerability in the printfUART formatted output implementation used within the ZigBee / IEEE 802.15.4 networking stack. The implementation formats output into a fixed-size global buffer and concatenates strings for %s format specifiers using strcat() without verifying remaining buffer…

Published: Jan 14, 2026
Modified: Jan 14, 2026
EPSS: 0.02%
View Details
4.6

An issue in AIRTH SMART HOME AQI MONITOR Bootloader v.1.005 allows a physically proximate attacker to obtain sensitive information via the UART port of the BK7231N controller (Wi-Fi and BLE module) on the device is open to access

Published: Jan 14, 2026
Modified: Jan 14, 2026
EPSS: 0.02%
View Details
6.5

A flaw was found in vsftpd. This vulnerability allows a denial of service (DoS) via an integer overflow in the ls command parameter parsing, triggered by a remote, authenticated attacker sending a crafted STAT command with a specific byte sequence.

Published: Jan 14, 2026
Modified: Jan 14, 2026
EPSS: 0.15%
View Details

Outray openSource ngrok alternative. Prior to 0.1.5, a TOCTOU race condition vulnerability allows a user to exceed the set number of active tunnels in their subscription plan. This vulnerability is fixed in 0.1.5.

Published: Jan 14, 2026
Modified: Jan 14, 2026
EPSS: 0.04%
View Details