CVE Database

Comprehensive vulnerability intelligence with advanced analytics

9.9

An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute arbitrary code via uploading a crafted PHP file.

Published: Dec 17, 2025
Modified: Jan 02, 2026
Product: pagekit pagekit
EPSS: 0.09%
View Details
10.0

An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without completing certain protocol authorization checks.

Published: Dec 17, 2025
Modified: Dec 18, 2025
EPSS: 0.02%
View Details
9.8

Netaxis API Orchestrator (APIO) before 0.19.3 allows server side template injection (SSTI).

Published: Dec 17, 2025
Modified: Jan 05, 2026
EPSS: 0.06%
View Details
9.8

Edge3 Worker RPC RCE on Airflow 2. This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you installed and configured it on Airflow 2. The Edge3 provider support in Airflow 2 has been always development-only and not officially released, however if you installed and configured Edge3…

Published: Dec 17, 2025
Modified: Dec 22, 2025
EPSS: 0.30%
View Details
9.9

An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authenticated attacker to perform remote code execution via Server Side Template Injection.

Published: Dec 17, 2025
Modified: Dec 23, 2025
Product: craftycontrol crafty_controller
EPSS: 0.07%
View Details
9.8

Meltytech Shotcut 25.10.31 is vulnerable to Buffer Overflow. A memory access violation occurs when processing MLT project files with manipulated width and height parameters. By setting these values to extremely large numbers, the application attempts to allocate excessive memory during image processing, triggering a buffer overflow in the mlt_image_fill_white function.

Published: Dec 16, 2025
Modified: Jan 07, 2026
Product: meltytech shotcut
EPSS: 0.06%
View Details
9.9

The Open edX Platform is a learning management platform. Prior to commit 05d0d0936daf82c476617257aa6c35f0cd4ca060, CourseLimitedStaffRole users are able to access and edit courses in studio if they are granted the role on an org rather than on a course, and CourseLimitedStaffRole users are able to list courses they have the role…

Published: Dec 16, 2025
Modified: Dec 18, 2025
EPSS: 0.04%
View Details
9.8

Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorrectly formed SMC call to UEFI-MM MMCommunicate service that could result in an out-of-bounds write within the UEFI-MM Secure Partition context.

Published: Dec 16, 2025
Modified: Jan 13, 2026
EPSS: 0.05%
View Details
9.8

Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorrectly formed SMC call to UEFI-MM PCIe driver that could result in an out-of-bounds write within PCIe driver’s S-EL0 address space.

Published: Dec 16, 2025
Modified: Jan 13, 2026
EPSS: 0.05%
View Details
9.8

Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the text-substitution API. Because some interpolators could trigger actions like executing commands or accessing external resources, an attacker could potentially achieve remote code execution. This vulnerability has been fully addressed…

Published: Dec 16, 2025
Modified: Dec 23, 2025
Product: claris filemaker_server
EPSS: 0.33%
View Details
9.0

NVIDIA Isaac Lab contains a deserialization vulnerability. A successful exploit of this vulnerability might lead to code execution.

Published: Dec 16, 2025
Modified: Dec 18, 2025
EPSS: 0.05%
View Details
10.0

A Path Traversal vulnerability in the Allsky WebUI version v2024.12.06_06 allows an unauthenticated remote attacker to achieve arbitrary command execution. By sending a crafted HTTP request to the /html/execute.php endpoint with a malicious payload in the id parameter, an attacker can execute arbitrary commands on the underlying operating system, leading…

Published: Dec 16, 2025
Modified: Dec 31, 2025
Product: allskyteam allsky
EPSS: 1.06%
View Details
9.8

Mercury D196G d196gv1-cn-up_2020-01-09_11.21.44 is vulnerable to Buffer Overflow in the function sub_404CAEDC via the parameter password.

Published: Dec 16, 2025
Modified: Dec 22, 2025
Product: mercurycom d196g_firmware
EPSS: 0.06%
View Details
9.8

Mercury D196G d196gv1-cn-up_2020-01-09_11.21.44 is vulnerable to Buffer Overflow in the function sub_404CAEDC via the parameter fac_password.

Published: Dec 16, 2025
Modified: Dec 22, 2025
Product: mercurycom d196g_firmware
EPSS: 0.05%
View Details
9.8

PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows attackers to inject XML in the episode upload form. Attackers can manipulate the 'shortdesc' parameter to trigger external HTTP requests to arbitrary endpoints during podcast episode creation.

Published: Dec 16, 2025
Modified: Dec 30, 2025
Product: podcastgenerator podcast_generator
EPSS: 0.11%
View Details
9.8

PimpMyLog 1.7.14 contains an improper access control vulnerability that allows remote attackers to create admin accounts without authorization through the configuration endpoint. Attackers can exploit the unsanitized username field to inject malicious JavaScript, create a hidden backdoor account, and potentially access sensitive server-side log information and environmental variables.

Published: Dec 16, 2025
Modified: Dec 30, 2025
Product: potsky pimp_my_log
EPSS: 0.37%
View Details
9.8

phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by exploiting loose type comparison in password hash validation. Attackers can craft specific password hashes beginning with 0e or 00e to bypass authentication and upload malicious PHP files to the server.

Published: Dec 16, 2025
Modified: Dec 18, 2025
EPSS: 0.12%
View Details
9.1

When using the attachment interaction functionality, Blue Mail 1.140.103 and below saves documents to a file system without a Mark-of-the-Web tag, which allows attackers to bypass the built-in file protection mechanisms of both Windows OS and third-party software.

Published: Dec 16, 2025
Modified: Dec 31, 2025
Product: blixhq bluemail
EPSS: 0.07%
View Details
9.1

When using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system without a Mark-of-the-Web tag, which allows attackers to bypass the built-in file protection mechanisms of both Windows OS and third-party software.

Published: Dec 16, 2025
Modified: Dec 31, 2025
Product: canarymail canary_mail
EPSS: 0.07%
View Details
9.1

Missing Authorization vulnerability in yaadsarig Yaad Sarig Payment Gateway For WC yaad-sarig-payment-gateway-for-wc allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Yaad Sarig Payment Gateway For WC: from n/a through

Published: Dec 16, 2025
Modified: Dec 16, 2025
EPSS: 0.04%
View Details
9.8

An SQL injection vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3297 build 20251024 and later QuTS hero h5.2.7.3297 build 20251024 and…

Published: Dec 16, 2025
Modified: Dec 17, 2025
Product: qnap quts_hero
EPSS: 0.11%
View Details
9.8

An authentication bypass by spoofing vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to access resources which are not otherwise accessible without proper authentication. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3297 build 20251024 and…

Published: Dec 16, 2025
Modified: Dec 17, 2025
Product: qnap quts_hero
EPSS: 0.53%
View Details
9.6

DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to version 0.5.3, a security vulnerability exists in the Mermaid diagram rendering component that allows arbitrary JavaScript execution. Due to the exposure of the Electron IPC renderer to the DOM, this Cross-Site Scripting (XSS) flaw…

Published: Dec 16, 2025
Modified: Jan 02, 2026
Product: thinkinai deepchat
EPSS: 0.16%
View Details
9.8

Weblate is a web based localization tool. In versions prior to 5.15, it was possible to accept an invitation opened by a different user. Version 5.15. contains a patch. As a workaround, avoid leaving one's Weblate sessions with an invitation opened unattended.

Published: Dec 15, 2025
Modified: Dec 18, 2025
EPSS: 0.01%
View Details