CVE Database

Comprehensive vulnerability intelligence with advanced analytics

9.8

Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover.

Published: Dec 12, 2025
Modified: Dec 19, 2025
EPSS: 0.10%
View Details
9.8

In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs because the system uses a fixed, immutable key for encryption instead of dynamically generating or securely configuring the key. Attackers may obtain this key through reverse engineering or code analysis, potentially…

Published: Dec 12, 2025
Modified: Dec 15, 2025
Product: apache streampark
EPSS: 0.05%
View Details
9.1

Insufficiently Protected Credentials vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is fixed in version 1.12.1. Users are encouraged to upgrade to version 1.13.0, the latest release.

Published: Dec 12, 2025
Modified: Dec 18, 2025
EPSS: 0.11%
View Details
9.8

Fireshare facilitates self-hosted media and link sharing. Versions 1.2.30 and below allow an authenticated user, or unauthenticated user if the Public Uploads setting is enabled, to craft a malicious filename when uploading a video file. The malicious filename is then concatenated directly into a shell command, which can be used…

Published: Dec 12, 2025
Modified: Dec 22, 2025
EPSS: 0.37%
View Details
9.8

Parse Server is an open source backend that can be deployed to any infrastructure that runs Node.js. In versions prior to 8.6.0-alpha.2, a GitHub CI workflow is triggered in a way that grants the GitHub Actions workflow elevated permissions, giving it access to GitHub secrets and write permissions which are…

Published: Dec 12, 2025
Modified: Dec 22, 2025
Product: parseplatform parse-server
EPSS: 0.07%
View Details
9.8

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'plupload_ajax_delete_file' function in all versions up to, and including, 1.1.7. This makes it possible for unauthenticated attackers to delete arbitrary files on the server.

Published: Dec 12, 2025
Modified: Dec 12, 2025
EPSS: 0.26%
View Details
9.8

The LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.2.29. This is due to the plugin not properly validating a user's identity via the 'wp-json/lazytasks/api/v1/user/role/edit/' REST API endpoint…

Published: Dec 12, 2025
Modified: Dec 12, 2025
EPSS: 0.14%
View Details
10.0

Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.16.6 and below, the SYSTEM-level service SbieSvc.exe exposes SbieIniServer::RC4Crypt to sandboxed processes. The handler adds a fixed header size to a caller-controlled value_len without overflow checking. A large value_len (e.g., 0xFFFFFFF0) wraps the allocation…

Published: Dec 11, 2025
Modified: Dec 22, 2025
Product: sandboxie-plus sandboxie
EPSS: 0.08%
View Details
9.8

xbtitFM 4.1.18 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries by injecting malicious SQL code through the msgid parameter. Attackers can send crafted requests to /shoutedit.php with EXTRACTVALUE functions to extract database names, user credentials, and password hashes from the underlying database.

Published: Dec 11, 2025
Modified: Dec 30, 2025
Product: xbtitfm xbtitfm
EPSS: 0.25%
View Details
9.8

Quick.CMS 6.7 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by manipulating the login form. Attackers can inject specific SQL payloads like ' or '1'='1 to gain unauthorized administrative access to the system.

Published: Dec 11, 2025
Modified: Dec 31, 2025
Product: opensolution quick_cms
EPSS: 0.85%
View Details
9.8

In AzeoTech DAQFactory release 20.7 (Build 2555), an Out-of-bounds Write vulnerability can be exploited by an attacker to cause the program to write data past the end of an allocated memory buffer. This can lead to arbitrary code execution or a system crash.

Published: Dec 11, 2025
Modified: Jan 02, 2026
Product: azeotech daqfactory
EPSS: 0.13%
View Details
9.1

In AzeoTech DAQFactory release 20.7 (Build 2555), an Out-of-bounds Read vulnerability can be exploited by an attacker to cause the program to read data past the end of an allocated buffer. This could allow an attacker to disclose information or cause a system crash.

Published: Dec 11, 2025
Modified: Jan 02, 2026
Product: azeotech daqfactory
EPSS: 0.07%
View Details
9.8

In AzeoTech DAQFactory release 20.7 (Build 2555), an Access of Uninitialized Pointer vulnerability can be exploited by an attacker which can lead to arbitrary code execution.

Published: Dec 11, 2025
Modified: Jan 02, 2026
Product: azeotech daqfactory
EPSS: 0.13%
View Details
9.8

In AudioDecoder::HandleProduceRequest of audio_decoder.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

Published: Dec 11, 2025
Modified: Jan 05, 2026
Product: google android
EPSS: 0.18%
View Details
9.8

A vulnerability was identified in UTT 进取 512W up to 3.1.7.7-171114. Affected is the function strcpy of the file /goform/formConfigFastDirectionW. The manipulation of the argument ssid leads to buffer overflow. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early…

Published: Dec 11, 2025
Modified: Jan 07, 2026
EPSS: 0.17%
View Details
9.8

A vulnerability was determined in UTT 进取 512W up to 3.1.7.7-171114. This impacts the function strcpy of the file /goform/formNatStaticMap of the component Endpoint. Executing manipulation of the argument NatBind can lead to buffer overflow. The attack can be launched remotely. The exploit has been publicly disclosed and may be…

Published: Dec 11, 2025
Modified: Jan 07, 2026
EPSS: 0.17%
View Details
9.1

pgAdmin versions up to 9.10 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. This issue allows attackers to inject and execute arbitrary commands on the server hosting pgAdmin, posing a critical risk to the integrity…

Published: Dec 11, 2025
Modified: Dec 19, 2025
EPSS: 0.14%
View Details
9.8

Several stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger these vulnerabilities.When Tag is 133

Published: Dec 11, 2025
Modified: Dec 17, 2025
EPSS: 0.10%
View Details
9.8

Several stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger these vulnerabilities.When Tag is 131

Published: Dec 11, 2025
Modified: Dec 17, 2025
EPSS: 0.10%
View Details
9.8

Several stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger these vulnerabilities.When Tag is 67

Published: Dec 11, 2025
Modified: Dec 17, 2025
EPSS: 0.10%
View Details
9.8

Several stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger these vulnerabilities.When Tag is 65

Published: Dec 11, 2025
Modified: Dec 17, 2025
EPSS: 0.10%
View Details
9.8

Several stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger these vulnerabilities.When Tag is 64

Published: Dec 11, 2025
Modified: Dec 17, 2025
EPSS: 0.10%
View Details
9.8

Several stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger these vulnerabilities.When Tag is 3

Published: Dec 11, 2025
Modified: Dec 17, 2025
EPSS: 0.10%
View Details
9.8

An arbitrary file rename vulnerability in the /admin/manager.php component of EasyImages 2.0 v2.8.6 and below allows attackers to execute arbitrary code via renaming a PHP file to a SVG format.

Published: Dec 11, 2025
Modified: Dec 19, 2025
EPSS: 0.09%
View Details