CVE Database

Comprehensive vulnerability intelligence with advanced analytics

9.8

Enterprise Cloud Database developed by Ragic has a Hard-coded Cryptographic Key vulnerability, allowing unauthenticated remote attackers to exploit the fixed key to generate verification information and log into the system as any user.

Published: Dec 22, 2025
Modified: Dec 23, 2025
EPSS: 0.11%
View Details
9.8

A vulnerability has been found in Tenda WH450 1.0.0.18. This issue affects some unknown processing of the file /goform/SafeUrlFilter. The manipulation of the argument page leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

Published: Dec 22, 2025
Modified: Dec 30, 2025
Product: tenda wh450_firmware
EPSS: 0.09%
View Details
9.8

A security vulnerability has been detected in Tenda WH450 1.0.0.18. Affected by this issue is some unknown functionality of the file /goform/L7Im of the component HTTP Request Handler. Such manipulation of the argument page leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed…

Published: Dec 22, 2025
Modified: Dec 30, 2025
Product: tenda wh450_firmware
EPSS: 0.09%
View Details
9.8

A weakness has been identified in Tenda WH450 1.0.0.18. Affected by this vulnerability is an unknown functionality of the file /goform/CheckTools of the component HTTP Request Handler. This manipulation of the argument ipaddress causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to…

Published: Dec 22, 2025
Modified: Dec 30, 2025
Product: tenda wh450_firmware
EPSS: 0.09%
View Details
9.8

The Flex Store Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.0. This is due to the 'fsUserHandle::signup' and the 'fsSellerRole::add_role_seller' functions not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the…

Published: Dec 20, 2025
Modified: Dec 23, 2025
EPSS: 0.10%
View Details
9.8

The File Uploader for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the callback function for the 'add-image-data' REST API endpoint in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to upload arbitrary files to…

Published: Dec 20, 2025
Modified: Dec 23, 2025
EPSS: 0.20%
View Details
9.9

n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their workflow expression evaluation system. Under certain conditions, expressions supplied by authenticated users during workflow configuration may be evaluated in an execution…

Published: Dec 19, 2025
Modified: Jan 02, 2026
Product: n8n n8n
EPSS: 63.49%
View Details
9.8

FileZilla Client 3.63.1 contains a DLL hijacking vulnerability that allows attackers to execute malicious code by placing a crafted TextShaping.dll in the application directory. Attackers can generate a reverse shell payload using msfvenom and replace the missing DLL to achieve remote code execution when the application launches.

Published: Dec 19, 2025
Modified: Dec 23, 2025
EPSS: 0.22%
View Details
9.8

Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executing a crafted PHP script that captures and writes session cookie information to a file, enabling potential session hijacking.

Published: Dec 19, 2025
Modified: Dec 23, 2025
EPSS: 0.05%
View Details
9.8

Ever Gauzy v0.281.9 contains a JWT authentication vulnerability that allows attackers to exploit weak HMAC secret key implementation. Attackers can leverage the exposed JWT token to authenticate and gain unauthorized access with administrative permissions.

Published: Dec 19, 2025
Modified: Dec 23, 2025
EPSS: 0.04%
View Details
9.8

InnovaStudio WYSIWYG Editor 5.4 contains an unrestricted file upload vulnerability that allows attackers to bypass file extension restrictions through filename manipulation. Attackers can upload malicious ASP shells by using null byte techniques and alternate file extensions to circumvent upload controls in the asset manager.

Published: Dec 19, 2025
Modified: Dec 23, 2025
EPSS: 0.05%
View Details
9.8

Lilac-Reloaded for Nagios 2.0.8 contains a remote code execution vulnerability in the autodiscovery feature that allows attackers to inject arbitrary commands. Attackers can exploit the lack of input filtering in the nmap_binary parameter to execute a reverse shell by sending a crafted POST request to the autodiscovery endpoint.

Published: Dec 19, 2025
Modified: Dec 23, 2025
EPSS: 0.32%
View Details
9.8

A vulnerability has been found in TOTOLINK T10 4.1.8cu.5083_B20200521. This affects the function sprintf of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument loginAuthUrl leads to stack-based buffer overflow. The attack may be performed from remote.

Published: Dec 19, 2025
Modified: Dec 30, 2025
Product: totolink t10_firmware
EPSS: 0.27%
View Details
9.6

Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. A critical Stored Cross-Site Scripting (XSS) vulnerability exists in versions prior to 0.11.1 in the Mermaid diagram rendering component. The application allows the execution of arbitrary JavaScript via `javascript:`. An attacker can exploit this to inject…

Published: Dec 19, 2025
Modified: Jan 02, 2026
Product: openagentplatform dive
EPSS: 0.16%
View Details
9.8

An issue in GT Edge AI Community Edition Versions before v2.0.12 allows attackers to execute arbitrary code via injecting a crafted JSON payload into the Prompt window.

Published: Dec 19, 2025
Modified: Jan 05, 2026
EPSS: 0.10%
View Details
9.8

Galette is a membership management web application for non profit organizations. Prior to version 1.2.0, while updating any existing account with a self forged POST request, one can gain higher privileges. Version 1.2.0 fixes the issue.

Published: Dec 19, 2025
Modified: Jan 05, 2026
Product: galette galette
EPSS: 0.05%
View Details
9.1

Glutton V1 service endpoints were exposed without any authentication on Gotham stacks, this could have allowed users that did not have any permission to hit glutton backend directly and read/update/delete data. The affected service has been patched and automatically deployed to all Apollo-managed Gotham Instances

Published: Dec 19, 2025
Modified: Dec 19, 2025
EPSS: 0.05%
View Details
9.1

Improper Restriction of Excessive Authentication Attempts vulnerability in Restajet Information Technologies Inc. Online Food Delivery System allows Password Recovery Exploitation.This issue affects Online Food Delivery System: through 19122025.

Published: Dec 19, 2025
Modified: Jan 12, 2026
Product: restajet online_food_delivery_system
EPSS: 0.05%
View Details
9.1

Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of its behavior. Version 5.15.1 fixes the issue.

Published: Dec 18, 2025
Modified: Jan 02, 2026
Product: weblate weblate
EPSS: 0.20%
View Details
10.0

Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.

Published: Dec 18, 2025
Modified: Jan 06, 2026
Product: microsoft partner_center
EPSS: 0.09%
View Details
10.0

Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network.

Published: Dec 18, 2025
Modified: Jan 15, 2026
Product: microsoft azure_container_apps
EPSS: 0.10%
View Details
9.9

Custom Question Answering Elevation of Privilege Vulnerability

Published: Dec 18, 2025
Modified: Dec 19, 2025
EPSS: 0.06%
View Details
9.1

Genymobile/scrcpy versions up to and including 3.3.3, prior to commit 3e40b24, contain a buffer overflow vulnerability in the sc_device_msg_deserialize() function. A compromised device can send crafted messages that cause out-of-bounds reads, which may result in memory corruption or a denial-of-service condition. This vulnerability may allow further exploitation on the host…

Published: Dec 18, 2025
Modified: Jan 03, 2026
EPSS: 0.04%
View Details
9.8

EasyPHP Webserver 14.1 contains an OS command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by injecting malicious payloads through the app_service_control parameter. Attackers can send POST requests to /index.php?zone=settings with crafted app_service_control values to execute commands with administrative privileges.

Published: Dec 18, 2025
Modified: Dec 26, 2025
Product: easyphp webserver
EPSS: 55.34%
View Details