CVE Database

Comprehensive vulnerability intelligence with advanced analytics

9.1

TOTOLINK A3300R V17.0.0cu.557_B20221024 and N200RE V9.3.5u.6448_B20240521 and V9.3.5u.6437_B20230519 are vulnerable to Incorrect Access Control. Attackers can send payloads to the interface without logging in (remote).

Published: Dec 15, 2025
Modified: Dec 17, 2025
Product: totolink a3300r_firmware
EPSS: 0.08%
View Details
9.8

Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, and time-based blind SQL injection techniques to steal information from the database.

Published: Dec 15, 2025
Modified: Dec 18, 2025
Product: phpjabbers bus_reservation_system
EPSS: 0.04%
View Details
9.8

GOM Player 2.3.90.5360 contains a buffer overflow vulnerability in the equalizer preset name input field that allows attackers to crash the application. Attackers can overwrite the preset name with 260 'A' characters to trigger a buffer overflow and cause application instability.

Published: Dec 15, 2025
Modified: Dec 18, 2025
Product: gomlab gom_player
EPSS: 0.04%
View Details
9.8

Soosyze 2.0.0 contains a file upload vulnerability that allows attackers to upload arbitrary HTML files with embedded PHP code to the application. Attackers can exploit the broken file upload mechanism to potentially view sensitive file paths and execute malicious PHP scripts on the server.

Published: Dec 15, 2025
Modified: Dec 30, 2025
Product: soosyze soosyze
EPSS: 0.13%
View Details
9.8

MooreThreads torch_musa through all versions contains an unsafe deserialization vulnerability in torch_musa.utils.compare_tool. The compare_for_single_op() and nan_inf_track_for_single_op() functions use pickle.load() on user-controlled file paths without validation, allowing arbitrary code execution. An attacker can craft a malicious pickle file that executes arbitrary Python code when loaded, enabling remote code execution with the…

Published: Dec 15, 2025
Modified: Jan 07, 2026
EPSS: 0.37%
View Details
9.1

In grav

Published: Dec 15, 2025
Modified: Dec 17, 2025
EPSS: 0.04%
View Details
9.1

A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom Resources (CRs) that trick the system into granting them elevated permissions in other namespaces, including privileged namespaces. An authenticated attacker can then use these elevated permissions to create privileged workloads that run on master nodes, effectively giving…

Published: Dec 15, 2025
Modified: Dec 24, 2025
EPSS: 0.07%
View Details
9.8

The Fox LMS – WordPress LMS Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.5.1. This is due to the plugin not properly validating the 'role' parameter when creating new users via the `/fox-lms/v1/payments/create-order` REST API endpoint. This makes it possible for…

Published: Dec 15, 2025
Modified: Dec 15, 2025
EPSS: 0.13%
View Details
9.8

A security vulnerability has been detected in Shiguangwu sgwbox N3 2.0.25. Affected by this issue is some unknown functionality of the file /usr/sbin/http_eshell_server of the component WIRELESSCFGGET Interface. The manipulation of the argument params leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed…

Published: Dec 15, 2025
Modified: Dec 30, 2025
EPSS: 0.15%
View Details
9.8

A weakness has been identified in Shiguangwu sgwbox N3 2.0.25. Affected by this vulnerability is an unknown functionality of the file /usr/sbin/http_eshell_server of the component WIREDCFGGET Interface. Executing manipulation of the argument params can lead to buffer overflow. The attack may be launched remotely. The exploit has been made available…

Published: Dec 15, 2025
Modified: Jan 09, 2026
EPSS: 0.15%
View Details
9.8

A security flaw has been discovered in Shiguangwu sgwbox N3 2.0.25. Affected is an unknown function of the file /usr/sbin/http_eshell_server of the component DOCKER Feature. Performing manipulation of the argument params results in command injection. The attack may be initiated remotely. The exploit has been released to the public and…

Published: Dec 15, 2025
Modified: Jan 09, 2026
EPSS: 0.81%
View Details
9.8

A vulnerability was identified in Shiguangwu sgwbox N3 2.0.25. This impacts an unknown function of the file /usr/sbin/http_eshell_server of the component NETREBOOT Interface. Such manipulation leads to command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about…

Published: Dec 15, 2025
Modified: Dec 31, 2025
EPSS: 0.81%
View Details
9.8

A vulnerability was determined in Shiguangwu sgwbox N3 2.0.25. This affects an unknown function of the component SHARESERVER Feature. This manipulation of the argument params causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about…

Published: Dec 15, 2025
Modified: Jan 09, 2026
EPSS: 0.81%
View Details
9.8

A security flaw has been discovered in Tenda WH450 1.0.0.18. Impacted is an unknown function of the file /goform/DhcpListClient of the component HTTP Request Handler. The manipulation of the argument page results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public…

Published: Dec 14, 2025
Modified: Dec 22, 2025
Product: tenda wh450_firmware
EPSS: 0.10%
View Details
9.8

The SWD debug interface on the Growatt ShineLan-X communication dongle is available by default, allowing an attacker to attain debug access to the device and to extracting secrets or domains from within the device

Published: Dec 13, 2025
Modified: Jan 14, 2026
EPSS: 0.06%
View Details
9.8

Growatt ShineLan-X communication dongle has an undocumented backup account with undocumented credentials which allows significant level access to the device, such as allowing any attacker to access the Setting Center. This means that this is effectively backdoor for all devices utilizing a Growatt ShineLan-X communication dongle.

Published: Dec 13, 2025
Modified: Jan 14, 2026
EPSS: 0.07%
View Details
9.8

ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish an insecure FTP connection with the server. This may allow an attacker to replace legitimate files being deployed to devices with their own malicious versions, since the firmware signature verification is not enforced.

Published: Dec 13, 2025
Modified: Jan 14, 2026
EPSS: 0.07%
View Details
9.8

The JAY Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.01. This is due to incorrect authentication checking in the 'jay_login_register_process_switch_back' function with the 'jay_login_register_process_switch_back' cookie value. This makes it possible for unauthenticated attackers to log in as any existing user…

Published: Dec 13, 2025
Modified: Dec 15, 2025
EPSS: 0.42%
View Details
9.8

The Export WP Page to Static HTML & PDF plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.4 through publicly exposed cookies.txt files containing authentication cookies. This makes it possible for unauthenticated attackers to cookies that may have been injected into the…

Published: Dec 13, 2025
Modified: Dec 15, 2025
EPSS: 0.26%
View Details
9.8

The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to SQL Injection via the ‘analytic_id’ parameter in all versions up to, and including, 3.0.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…

Published: Dec 13, 2025
Modified: Dec 15, 2025
EPSS: 0.09%
View Details
9.8

Dormakaba Saflok System 6000 contains a predictable key generation algorithm that allows attackers to derive card access keys from a 32-bit unique identifier. Attackers can exploit the deterministic key generation process by calculating valid access keys using a simple mathematical transformation of the card's unique identifier.

Published: Dec 12, 2025
Modified: Dec 15, 2025
EPSS: 0.07%
View Details
9.8

PCMan FTP Server 2.0 contains a buffer overflow vulnerability in the 'pwd' command that allows remote attackers to execute arbitrary code. Attackers can send a specially crafted payload during the FTP login process to overwrite memory and potentially gain system access.

Published: Dec 12, 2025
Modified: Dec 15, 2025
EPSS: 0.26%
View Details
9.8

Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute arbitrary system commands. Attackers can inject malicious commands into the 'run command' input field during PDF export to achieve remote code execution.

Published: Dec 12, 2025
Modified: Dec 15, 2025
EPSS: 0.59%
View Details
9.1

Plesk 18.0 has Incorrect Access Control.

Published: Dec 12, 2025
Modified: Jan 06, 2026
EPSS: 0.05%
View Details