CVE Database

Comprehensive vulnerability intelligence with advanced analytics

4.4

The Makesweat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'makesweat_clubid' setting in all versions up to, and including, 0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages…

Published: Jan 14, 2026
Modified: Jan 14, 2026
EPSS: 0.03%
View Details
6.4

The SpiceForms Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'spiceforms' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to…

Published: Jan 14, 2026
Modified: Jan 14, 2026
EPSS: 0.03%
View Details
6.8

The VSCode extension for Spring CLI are vulnerable to command injection, resulting in command execution on the users machine.

Published: Jan 14, 2026
Modified: Jan 14, 2026
EPSS: 0.03%
View Details
6.1

Permission verification bypass vulnerability in the media library module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Published: Jan 14, 2026
Modified: Jan 15, 2026
Product: huawei emui
EPSS: 0.01%
View Details
6.8

Multi-thread race condition vulnerability in the thermal management module. Impact: Successful exploitation of this vulnerability may affect availability.

Published: Jan 14, 2026
Modified: Jan 15, 2026
Product: huawei harmonyos
EPSS: 0.01%
View Details
7.8

Double free vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability may affect the input function.

Published: Jan 14, 2026
Modified: Jan 15, 2026
Product: huawei harmonyos
EPSS: 0.01%
View Details
5.7

Vulnerability of improper permission control in the print module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Published: Jan 14, 2026
Modified: Jan 15, 2026
Product: huawei harmonyos
EPSS: 0.01%
View Details
5.1

Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Published: Jan 14, 2026
Modified: Jan 15, 2026
Product: huawei harmonyos
EPSS: 0.01%
View Details
4.7

Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Published: Jan 14, 2026
Modified: Jan 15, 2026
Product: huawei harmonyos
EPSS: 0.01%
View Details
6.2

Data verification vulnerability in the HiView module. Impact: Successful exploitation of this vulnerability may affect availability.

Published: Jan 14, 2026
Modified: Jan 15, 2026
Product: huawei harmonyos
EPSS: 0.01%
View Details
5.7

Man-in-the-middle attack vulnerability in the Clone module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Published: Jan 14, 2026
Modified: Jan 15, 2026
Product: huawei emui
EPSS: 0.01%
View Details
5.1

Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulnerability may affect availability.

Published: Jan 14, 2026
Modified: Jan 15, 2026
Product: huawei harmonyos
EPSS: 0.01%
View Details
5.1

Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulnerability may affect availability.

Published: Jan 14, 2026
Modified: Jan 15, 2026
Product: huawei harmonyos
EPSS: 0.01%
View Details
8.4

Multi-thread race condition vulnerability in the video framework module. Impact: Successful exploitation of this vulnerability may affect availability.

Published: Jan 14, 2026
Modified: Jan 15, 2026
Product: huawei harmonyos
EPSS: 0.01%
View Details
6.2

Permission verification bypass vulnerability in the media library module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Published: Jan 14, 2026
Modified: Jan 15, 2026
Product: huawei emui
EPSS: 0.01%
View Details
8.0

Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerability may affect availability.

Published: Jan 14, 2026
Modified: Jan 15, 2026
Product: huawei harmonyos
EPSS: 0.01%
View Details
8.4

Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerability may affect availability.

Published: Jan 14, 2026
Modified: Jan 15, 2026
Product: huawei harmonyos
EPSS: 0.01%
View Details
8.0

Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerability may affect availability.

Published: Jan 14, 2026
Modified: Jan 15, 2026
Product: huawei harmonyos
EPSS: 0.01%
View Details
8.0

Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerability may affect availability.

Published: Jan 14, 2026
Modified: Jan 15, 2026
Product: huawei harmonyos
EPSS: 0.01%
View Details
7.8

The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-mode application may be able to cause a buffer overflow.

Published: Jan 14, 2026
Modified: Jan 14, 2026
EPSS: 0.01%
View Details
7.8

The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-mode application may be able to cause a buffer overflow.

Published: Jan 14, 2026
Modified: Jan 14, 2026
EPSS: 0.01%
View Details
7.8

The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-mode application may be able to cause a buffer overflow.

Published: Jan 14, 2026
Modified: Jan 14, 2026
EPSS: 0.01%
View Details
7.8

The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-mode application may be able to cause a buffer overflow.

Published: Jan 14, 2026
Modified: Jan 14, 2026
EPSS: 0.01%
View Details
10.0

Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.7.0, there is a critical sandbox escape vulnerability in enclave-vm that allows untrusted, sandboxed JavaScript code to execute arbitrary code in the host Node.js runtime. When a tool invocation fails, enclave-vm exposes a host-side Error…

Published: Jan 14, 2026
Modified: Jan 14, 2026
EPSS: 0.10%
View Details