CVE Database

Comprehensive vulnerability intelligence with advanced analytics

9.8

NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure and data tampering.

Published: Dec 23, 2025
Modified: Jan 15, 2026
Product: nvidia isaac_launchable
EPSS: 0.08%
View Details
9.8

NVIDIA Isaac Launchable contains a vulnerability where an attacker could exploit a hard-coded credential issue. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, and data tampering.

Published: Dec 23, 2025
Modified: Jan 15, 2026
Product: nvidia isaac_launchable
EPSS: 0.07%
View Details
9.8

linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus.

Published: Dec 23, 2025
Modified: Jan 06, 2026
Product: linksys e5600_firmware
EPSS: 0.29%
View Details
9.8

Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter.

Published: Dec 23, 2025
Modified: Jan 06, 2026
Product: linksys e5600_firmware
EPSS: 0.29%
View Details
10.0

SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the createTable function in SqlUtil.java.

Published: Dec 23, 2025
Modified: Jan 06, 2026
Product: ruoyi ruoyi
EPSS: 0.32%
View Details
10.0

Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certificate checks and execute commands with System privileges.

Published: Dec 23, 2025
Modified: Jan 06, 2026
Product: eclipse cyclone_data_distribution_service
EPSS: 0.09%
View Details
10.0

eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure communications and connections.

Published: Dec 23, 2025
Modified: Jan 02, 2026
Product: eprosima fast_dds
EPSS: 0.04%
View Details
9.8

Netgear EX8000 V1.0.0.126 was discovered to contain a command injection vulnerability via the switch_status function.

Published: Dec 23, 2025
Modified: Jan 02, 2026
Product: netgear ex8000_firmware
EPSS: 0.49%
View Details
9.8

The PhastPress plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read via null byte injection in all versions up to, and including, 3.7. This is due to a discrepancy between the extension validation in `getExtensionForURL()` which operates on URL-decoded paths, and `appendNormalized()` which strips everything after a null byte…

Published: Dec 23, 2025
Modified: Dec 23, 2025
EPSS: 0.07%
View Details
9.8

net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd daemon can cause a buffer overflow and the daemon to crash. This issue has been patched in versions 5.9.5 and 5.10.pre2.

Published: Dec 23, 2025
Modified: Jan 09, 2026
EPSS: 0.04%
View Details
9.8

Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated remote attackers to access sensitive device information and live video streams. The ONVIF implementation fails to enforce authentication on 31 critical endpoints, enabling direct unauthorized video stream access.

Published: Dec 22, 2025
Modified: Jan 05, 2026
Product: xiongmaitech xm530v200_x6-weq_8m_firmware
EPSS: 1.86%
View Details
9.8

ProjectSend r1605 contains a remote code execution vulnerability that allows attackers to upload malicious files by manipulating file extensions. Attackers can upload shell scripts with disguised extensions through the upload.process.php endpoint to execute arbitrary commands on the server.

Published: Dec 22, 2025
Modified: Dec 26, 2025
Product: projectsend projectsend
EPSS: 0.30%
View Details
9.8

Screen SFT DAB 600/C Firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting IP address session binding. Attackers can reuse the same IP address and issue unauthorized requests to the userManager API to remove user accounts without proper authentication.

Published: Dec 22, 2025
Modified: Dec 26, 2025
Product: dbbroadcast sft_dab_600\/c_firmware
EPSS: 0.24%
View Details
9.8

SOUND4 LinkAndShare Transmitter 1.1.2 contains a format string vulnerability that allows attackers to trigger memory stack overflows through maliciously crafted environment variables. Attackers can manipulate the username environment variable with format string payloads to potentially execute arbitrary code and crash the application.

Published: Dec 22, 2025
Modified: Dec 31, 2025
Product: sound4 linkandshare_transmitter
EPSS: 0.09%
View Details
9.8

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands through the 'password' parameter. Attackers can exploit the login.php and index.php scripts by injecting shell commands via the 'password' POST parameter to execute commands with web server privileges.

Published: Dec 22, 2025
Modified: Jan 13, 2026
Product: sound4 pulse_firmware
EPSS: 2.20%
View Details
9.8

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access hidden system resources. Attackers can exploit the vulnerability by manipulating user-supplied input to execute privileged functionalities without proper authentication.

Published: Dec 22, 2025
Modified: Jan 13, 2026
Product: sound4 pulse_firmware
EPSS: 0.37%
View Details
9.8

ClipBucket 5.5.2 is affected by an improper access control issue where the product is shipped or deployed with hardcoded default administrative credentials. An unauthenticated remote attacker can log in to the administrative panel using these default credentials, resulting in full administrative control of the application.

Published: Dec 22, 2025
Modified: Jan 02, 2026
Product: oxygenz clipbucket
EPSS: 0.26%
View Details
9.6

Iframe injection vulnerability in airc.pt/solucoes-servicos.solucoes MyNET v.26.06 and before allows a remote attacker to execute arbitrary code via the src parameter.

Published: Dec 22, 2025
Modified: Jan 02, 2026
EPSS: 0.16%
View Details
10.0

An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system administrator who is implementing Umbraco CMS in…

Published: Dec 22, 2025
Modified: Jan 08, 2026
Product: umbraco umbraco_cms
EPSS: 0.09%
View Details
9.6

An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.

Published: Dec 22, 2025
Modified: Jan 02, 2026
Product: frappe erpnext
EPSS: 0.05%
View Details
9.8

Missing Authentication for Critical Function vulnerability in Sharp Display Solutions Media Player MP-01 All Verisons allows a attacker may access to the web interface of the affected product without authentication and change settings or perform other operations, and deliver content from the authoring software to the affected product without authentication.

Published: Dec 22, 2025
Modified: Jan 15, 2026
EPSS: 0.08%
View Details
9.8

Improper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may create and run unauthorized firmware.

Published: Dec 22, 2025
Modified: Jan 15, 2026
Product: sharp np-cr5450h_firmware
EPSS: 0.03%
View Details
9.8

Stack-based Buffer Overflow vulnerability in Sharp Display Solutions projectors allows a attacker may execute arbitrary commands and programs.

Published: Dec 22, 2025
Modified: Jan 15, 2026
Product: sharp np-cr5450h_firmware
EPSS: 0.07%
View Details
9.8

Stack-based Buffer Overflow vulnerability in Sharp Display Solutions projectors allows a attacker may execute arbitrary commands and programs.

Published: Dec 22, 2025
Modified: Jan 15, 2026
Product: sharp np-cr5450h_firmware
EPSS: 0.07%
View Details