CVE Database

Comprehensive vulnerability intelligence with advanced analytics

9.1

Intermediate register values of secure workloads can be exfiltrated in workloads scheduled from applications running in the non-secure environment of a platform.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.02%
View Details
9.8

phpgurukul News Portal Project V4.1 has File Upload Vulnerability via upload.php, which enables the upload of files of any format to the server without identity authentication.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.03%
View Details
9.8

phpgurukul News Portal Project V4.1 is vulnerable to SQL Injection in check_availablity.php.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.01%
View Details
9.1

phpgurukul News Portal Project V4.1 has an Arbitrary File Deletion Vulnerability in remove_file.php. The parameter file can cause any file to be deleted.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.03%
View Details
9.8

An arbitrary file upload vulnerability in the /utils/uploadFile component of Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows attackers to execute arbitrary code via uploading a crafted PDF file.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.02%
View Details
9.0

A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration (SSH keys, tokens, etc.) from other users' Developer Workspace containers, via an unauthenticated JSON-RPC / websocket API exposed on TCP port 3333.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.28%
View Details
9.8

Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 147.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.04%
View Details
9.8

Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox < 147 and Firefox ESR < 140.7.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.04%
View Details
10.0

Sandbox escape in the Messaging System component. This vulnerability affects Firefox < 147.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.06%
View Details
9.8

Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability affects Firefox < 147, Firefox ESR < 115.32, and Firefox ESR < 140.7.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.04%
View Details
9.1

Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper filter configurations.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.14%
View Details
10.0

Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an unauthenticated remote attacker to circumvent authentication and impersonate a legitimate user. Successful exploitation requires that the attacker has learned the identity of a legitimate user.

Published: Jan 13, 2026
Modified: Jan 13, 2026
EPSS: 0.17%
View Details
9.1

The E-xact | Hosted Payment | WordPress plugin through 2.0 is vulnerable to arbitrary file deletion due to insufficient file path validation. This makes it possible for unauthenticated attackers to delete arbitrary files on the server.

Published: Jan 13, 2026
Modified: Jan 13, 2026
EPSS: 0.06%
View Details
9.8

The Dreamer Blog WordPress theme through 1.2 is vulnerable to arbitrary installations due to a missing capability check.

Published: Jan 13, 2026
Modified: Jan 13, 2026
EPSS: 0.04%
View Details
9.9

Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Premise (Financials General Ledger), an authenticated user could execute crafted SQL queries to read, modify, and delete backend database data. This leads to a high impact on the confidentiality, integrity, and availability of the application.

Published: Jan 13, 2026
Modified: Jan 13, 2026
EPSS: 0.05%
View Details
9.6

Due to the usage of vulnerable third party component in SAP Wily Introscope Enterprise Manager (WorkStation), an unauthenticated attacker could create a malicious JNLP (Java Network Launch Protocol) file accessible by a public facing URL. When a victim clicks on the URL the accessed Wily Introscope Server could execute OS…

Published: Jan 13, 2026
Modified: Jan 13, 2026
EPSS: 0.09%
View Details
9.1

SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk…

Published: Jan 13, 2026
Modified: Jan 13, 2026
EPSS: 0.04%
View Details
9.1

SAP Landscape Transformation allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system…

Published: Jan 13, 2026
Modified: Jan 13, 2026
EPSS: 0.04%
View Details
9.6

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.93, the server uses the Origin value from the request headers as the email link baseUrl without validation. If an attacker controls the Origin, password reset / email verification links in emails can be generated pointing…

Published: Jan 12, 2026
Modified: Jan 13, 2026
EPSS: 0.03%
View Details
9.4

Multiple SQL Injection vulnerabilities exist in AbhishekMali21 GYM-MANAGEMENT-SYSTEM 1.0 via the 'name' parameter in (1) member_search.php, (2) trainer_search.php, and (3) gym_search.php, and via the 'id' parameter in (4) payment_search.php. An unauthenticated remote attacker can exploit these issues to inject malicious SQL commands, leading to unauthorized data extraction, authentication bypass, or…

Published: Jan 12, 2026
Modified: Jan 13, 2026
EPSS: 0.09%
View Details
9.8

Buffer Overflow in the ippprint (Internet Printing Protocol) service in Sagemcom F@st 3686 MAGYAR_4.121.0 allows remote attacker to execute arbitrary code by sending a crafted HTTP request.

Published: Jan 12, 2026
Modified: Jan 13, 2026
EPSS: 1.24%
View Details
9.8

Multiple SQL Injection vulnerabilities exist in amansuryawanshi Gym-Management-System-PHP 1.0 via the 'name', 'email', and 'comment' parameters in (1) submit_contact.php, the 'username' and 'pass_key' parameters in (2) secure_login.php, and the 'login_id', 'pwfield', and 'login_key' parameters in (3) change_s_pwd.php. An unauthenticated or authenticated attacker can exploit these issues to bypass authentication, execute…

Published: Jan 12, 2026
Modified: Jan 13, 2026
EPSS: 0.06%
View Details
9.8

Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE (Remote Code Execution). The application receives a reverse shell (php) into imagem of the user enabling RCE.

Published: Jan 12, 2026
Modified: Jan 13, 2026
EPSS: 0.26%
View Details
9.1

A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the rname, rcollage, rnumber, rgender and rpassword parameters in a POST HTTP request.

Published: Jan 12, 2026
Modified: Jan 13, 2026
EPSS: 0.05%
View Details