CVE Database

Comprehensive vulnerability intelligence with advanced analytics

9.8

Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code.

Published: Dec 18, 2025
Modified: Dec 30, 2025
EPSS: 0.05%
View Details
9.8

Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Tuturn allows Authentication Abuse.This issue affects Tuturn: from n/a before 3.6.

Published: Dec 18, 2025
Modified: Dec 19, 2025
EPSS: 0.07%
View Details
9.8

A weakness has been identified in Tenda WH450 1.0.0.18. Affected is an unknown function of the file /goform/onSSIDChange of the component HTTP Request Handler. This manipulation of the argument ssid_index causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made available to the…

Published: Dec 18, 2025
Modified: Dec 24, 2025
Product: tenda wh450_firmware
EPSS: 0.15%
View Details
9.8

A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring authentication, enabling remote attackers to perform unauthorized model management operations.

Published: Dec 18, 2025
Modified: Dec 30, 2025
EPSS: 0.58%
View Details
9.1

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint. The endpoint implements an overly permissive CORS policy that reflects arbitrary Origin headers and sets Access-Control-Allow-Credentials: true, allowing any external domain to make authenticated cross-origin requests.

Published: Dec 18, 2025
Modified: Dec 30, 2025
Product: langgenius dify
EPSS: 0.02%
View Details
9.1

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup endpoint. The endpoint implements an insecure CORS policy that reflects any Origin header and enables Access-Control-Allow-Credentials: true, permitting arbitrary external domains to make authenticated requests.

Published: Dec 18, 2025
Modified: Dec 30, 2025
Product: langgenius dify
EPSS: 0.02%
View Details
9.8

A security flaw has been discovered in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/wirelessRestart of the component HTTP Request Handler. The manipulation of the argument GO results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been released to the…

Published: Dec 18, 2025
Modified: Dec 24, 2025
Product: tenda wh450_firmware
EPSS: 0.15%
View Details
9.8

Use-after-free in the Disability Access APIs component. This vulnerability affects Firefox < 146.0.1.

Published: Dec 18, 2025
Modified: Dec 30, 2025
Product: mozilla firefox
EPSS: 0.06%
View Details
9.1

Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters Hotel Booking Lite motopress-hotel-booking-lite allows Remote Code Inclusion.This issue affects Hotel Booking Lite: from n/a through

Published: Dec 18, 2025
Modified: Dec 18, 2025
EPSS: 0.06%
View Details
9.0

Unrestricted Upload of File with Dangerous Type vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Path Traversal.This issue affects WP Webhooks: from n/a through

Published: Dec 18, 2025
Modified: Dec 18, 2025
EPSS: 0.04%
View Details
9.9

Unrestricted Upload of File with Dangerous Type vulnerability in StylemixThemes Motors motors allows Using Malicious Files.This issue affects Motors: from n/a through

Published: Dec 18, 2025
Modified: Dec 18, 2025
EPSS: 0.05%
View Details
9.8

Deserialization of Untrusted Data vulnerability in BoldThemes Codiqa codiqa allows Object Injection.This issue affects Codiqa: from n/a through < 1.2.8.

Published: Dec 18, 2025
Modified: Dec 18, 2025
EPSS: 0.05%
View Details
9.8

Unrestricted Upload of File with Dangerous Type vulnerability in RedefiningTheWeb WordPress Contact Form 7 PDF, Google Sheet & Database rtwwcfp-wordpress-contact-form-7-pdf allows Using Malicious Files.This issue affects WordPress Contact Form 7 PDF, Google Sheet & Database: from n/a through

Published: Dec 18, 2025
Modified: Dec 18, 2025
EPSS: 0.06%
View Details
9.8

Deserialization of Untrusted Data vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Object Injection.This issue affects Client Invoicing by Sprout Invoices: from n/a through

Published: Dec 18, 2025
Modified: Dec 18, 2025
EPSS: 0.05%
View Details
9.8

Deserialization of Untrusted Data vulnerability in TieLabs Jannah jannah allows Object Injection.This issue affects Jannah: from n/a through

Published: Dec 18, 2025
Modified: Dec 18, 2025
EPSS: 0.05%
View Details
9.8

Incorrect Privilege Assignment vulnerability in PenciDesign Soledad soledad allows Privilege Escalation.This issue affects Soledad: from n/a through

Published: Dec 18, 2025
Modified: Dec 18, 2025
EPSS: 0.05%
View Details
9.8

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Salesforce gf-salesforce-crmperks allows Object Injection.This issue affects WP Gravity Forms Salesforce: from n/a through

Published: Dec 18, 2025
Modified: Dec 31, 2025
EPSS: 0.05%
View Details
9.8

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms HubSpot gf-hubspot allows Object Injection.This issue affects WP Gravity Forms HubSpot: from n/a through

Published: Dec 18, 2025
Modified: Dec 31, 2025
EPSS: 0.24%
View Details
9.8

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Constant Contact Plugin gf-constant-contact allows Object Injection.This issue affects WP Gravity Forms Constant Contact Plugin: from n/a through

Published: Dec 18, 2025
Modified: Dec 31, 2025
EPSS: 0.05%
View Details
9.8

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Zoho CRM and Bigin gf-zoho allows Object Injection.This issue affects WP Gravity Forms Zoho CRM and Bigin: from n/a through

Published: Dec 18, 2025
Modified: Dec 31, 2025
EPSS: 0.05%
View Details
9.8

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Insightly gf-insightly allows Object Injection.This issue affects WP Gravity Forms Insightly: from n/a through

Published: Dec 18, 2025
Modified: Dec 31, 2025
EPSS: 0.05%
View Details
9.8

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk allows Object Injection.This issue affects WP Gravity Forms FreshDesk Plugin: from n/a through

Published: Dec 18, 2025
Modified: Dec 31, 2025
EPSS: 0.05%
View Details
9.4

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mmetrodw tPlayer tplayer-html5-audio-player-with-playlist allows SQL Injection.This issue affects tPlayer: from n/a through

Published: Dec 18, 2025
Modified: Dec 18, 2025
EPSS: 0.04%
View Details
9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartcms Advance Seat Reservation Management for WooCommerce scw-seat-reservation allows SQL Injection.This issue affects Advance Seat Reservation Management for WooCommerce: from n/a through

Published: Dec 18, 2025
Modified: Dec 18, 2025
EPSS: 0.03%
View Details