CVE Database

Comprehensive vulnerability intelligence with advanced analytics

9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Lunna lunna allows PHP Local File Inclusion.This issue affects Lunna: from n/a through

Published: Dec 18, 2025
Modified: Jan 06, 2026
EPSS: 0.06%
View Details
9.8

Deserialization of Untrusted Data vulnerability in BoldThemes DentiCare denticare allows Object Injection.This issue affects DentiCare: from n/a through < 1.4.3.

Published: Dec 18, 2025
Modified: Dec 18, 2025
EPSS: 0.05%
View Details
9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes EasyEat easyeat allows PHP Local File Inclusion.This issue affects EasyEat: from n/a through

Published: Dec 18, 2025
Modified: Dec 18, 2025
EPSS: 0.15%
View Details
9.0

Memory Corruption when a corrupted ELF image with an oversized file size is read into a buffer without authentication.

Published: Dec 18, 2025
Modified: Dec 23, 2025
Product: qualcomm sa8770p_firmware
EPSS: 0.02%
View Details
9.1

Zerobyte is a backup automation tool Zerobyte versions prior to 0.18.5 and 0.19.0 contain an authentication bypass vulnerability where authentication middleware is not properly applied to API endpoints. This results in certain API endpoints being accessible without valid session credentials. This is dangerous for those who have exposed Zerobyte to…

Published: Dec 17, 2025
Modified: Dec 18, 2025
EPSS: 0.09%
View Details
9.8

PHPJabbers Simple CMS 5.0 contains a SQL injection vulnerability in the 'column' parameter that allows remote attackers to manipulate database queries. Attackers can inject crafted SQL payloads through the 'column' parameter in the index.php endpoint to potentially extract or modify database information.

Published: Dec 17, 2025
Modified: Dec 24, 2025
Product: phpjabbers simple_cms
EPSS: 0.22%
View Details
9.8

UliCMS 2023.1 contains a privilege escalation vulnerability that allows unauthenticated attackers to create administrative accounts through the UserController endpoint. Attackers can send a crafted POST request to /dist/admin/index.php with specific parameters to generate a new admin user with full system access.

Published: Dec 17, 2025
Modified: Dec 18, 2025
Product: ulicms ulicms
EPSS: 0.11%
View Details
9.8

TinyWebGallery v2.5 contains a remote code execution vulnerability in the admin upload functionality that allows unauthenticated attackers to upload malicious PHP files. Attackers can upload .phar files with embedded system commands to execute arbitrary code on the server by accessing the uploaded file's URL.

Published: Dec 17, 2025
Modified: Dec 24, 2025
Product: tinywebgallery tinywebgallery
EPSS: 1.28%
View Details
9.8

SitemagicCMS 4.4.3 contains a remote code execution vulnerability that allows attackers to upload malicious PHP files to the files/images directory. Attackers can upload a .phar file with system command execution payload to compromise the web application and execute arbitrary system commands.

Published: Dec 17, 2025
Modified: Dec 31, 2025
Product: sitemagic sitemagic_cms
EPSS: 0.33%
View Details
9.8

UliCMS 2023.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through mass assignment in the UserController. Attackers can send a crafted POST request to the admin index.php endpoint with specific parameters to generate an administrative account with full system access.

Published: Dec 17, 2025
Modified: Dec 24, 2025
Product: ulicms ulicms
EPSS: 0.98%
View Details
9.1

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.20.0, a vulnerability exists in FreeRDP’s certificate handling code on Windows platforms. The function `freerdp_certificate_data_hash_ uses` the Microsoft-specific `_snprintf` function to format certificate cache filenames without guaranteeing NUL termination when truncation occurs. According to Microsoft documentation, `_snprintf`…

Published: Dec 17, 2025
Modified: Jan 02, 2026
Product: freerdp freerdp
EPSS: 0.05%
View Details
9.6

ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability in ChurchCRM's Event Attendee Editor allows authenticated users to execute arbitrary SQL commands, leading to complete database compromise, administrative credential theft, and potential system takeover. The vulnerability enables attackers to extract sensitive member data,…

Published: Dec 17, 2025
Modified: Dec 18, 2025
Product: churchcrm churchcrm
EPSS: 0.04%
View Details
9.9

ChurchCRM is an open-source church management system. Versions prior to 6.5.3 may disclose database information in an error message including the host, ip, username, and password. Version 6.5.3 fixes the issue.

Published: Dec 17, 2025
Modified: Dec 18, 2025
Product: churchcrm churchcrm
EPSS: 0.05%
View Details
9.1

ChurchCRM is an open-source church management system. In versions prior to 6.5.3, the Database Restore functionality does not validate the content or file extension of uploaded files. As a result, an attacker can upload a web shell file and subsequently upload a .htaccess file to enable direct access to it.…

Published: Dec 17, 2025
Modified: Dec 18, 2025
Product: churchcrm churchcrm
EPSS: 0.16%
View Details
9.8

An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*. An incomplete configuration (agent authentication) in DriveLock tenant allows attackers to impersonate any DriveLock agent on the network against the DES (DriveLock Enterprise Service).

Published: Dec 17, 2025
Modified: Dec 18, 2025
EPSS: 0.07%
View Details
9.8

An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 before 25.1.6. Users with the "Manage roles and permissions" privilege can promote themselves or other DOC users to the Supervisor role through an API call. This privilege is included by default in the Administrator role. This…

Published: Dec 17, 2025
Modified: Jan 02, 2026
EPSS: 0.06%
View Details
9.8

This issue was addressed with improved URL validation. This issue is fixed in macOS Tahoe 26.2, Safari 26.2. On a Mac with Lockdown Mode enabled, web content opened via a file URL may be able to use Web APIs that should be restricted.

Published: Dec 17, 2025
Modified: Dec 18, 2025
EPSS: 0.05%
View Details
9.8

A configuration issue was addressed with additional restrictions. This issue is fixed in visionOS 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2. Photos in the Hidden Photos Album may be viewed without authentication.

Published: Dec 17, 2025
Modified: Dec 18, 2025
EPSS: 0.11%
View Details
9.6

An issue was discovered in 25.1.2 before 25.1.5. A Cross Site Scripting (XSS) issue in DriveLock Operations Center allows for session takeover over a network.

Published: Dec 17, 2025
Modified: Jan 02, 2026
Product: drivelock drivelock
EPSS: 0.05%
View Details
9.9

An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulate privileged processes to gain more privileges on Windows computers.

Published: Dec 17, 2025
Modified: Jan 02, 2026
EPSS: 0.04%
View Details
9.8

A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remote attackers to cause denial of service and possibly code execution by sending a post request with a crafted payload (field `serviceName`) to /goform/AdvSetMacMtuWan.

Published: Dec 17, 2025
Modified: Jan 02, 2026
Product: tenda ac10_firmware
EPSS: 0.22%
View Details
9.1

AVideo versions prior to 20.1 with the ImageGallery plugin enabled is vulnerable to unauthenticated file upload and deletion. Plugin endpoints responsible for managing gallery images fail to enforce authentication checks and do not validate ownership, allowing unauthenticated attackers to upload or delete images associated with any image-based video.

Published: Dec 17, 2025
Modified: Dec 19, 2025
EPSS: 0.15%
View Details
10.0

ChurchCRM is an open-source church management system. Prior to version 5.21.0, a pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard allows unauthenticated attackers to inject arbitrary PHP code during the initial installation process, leading to complete server compromise. The vulnerability exists in `setup/routes/setup.php` where user input from the setup…

Published: Dec 17, 2025
Modified: Dec 18, 2025
Product: churchcrm churchcrm
EPSS: 0.26%
View Details
9.8

An Insecure Direct Object Reference (IDOR) in Pagekit CMS v1.0.18 allows attackers to escalate privileges.

Published: Dec 17, 2025
Modified: Jan 02, 2026
Product: pagekit pagekit
EPSS: 0.06%
View Details