CVE Database

Comprehensive vulnerability intelligence with advanced analytics

9.6

Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior to 2.4.24, the DFIR-IRIS datastore file management system has a vulnerability where mass assignment of the file_local_name field combined with path trust in the delete operation enables authenticated users to delete arbitrary filesystem paths.…

Published: Jan 12, 2026
Modified: Jan 13, 2026
EPSS: 0.06%
View Details
9.1

LibreChat is a ChatGPT clone with additional features. Prior to v0.8.2-rc2, LibreChat's MCP stdio transport accepts arbitrary commands without validation, allowing any authenticated user to execute shell commands as root inside the container through a single API request. This vulnerability is fixed in v0.8.2-rc2.

Published: Jan 12, 2026
Modified: Jan 13, 2026
EPSS: 0.04%
View Details
10.0

A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the user password and execute a full account takeover via a replay attack.

Published: Jan 12, 2026
Modified: Jan 13, 2026
EPSS: 0.04%
View Details
9.8

An issue in Automai BotManager v.25.2.0 allows a remote attacker to execute arbitrary code via the BotManager.exe component

Published: Jan 12, 2026
Modified: Jan 13, 2026
EPSS: 0.25%
View Details
9.9

An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges

Published: Jan 12, 2026
Modified: Jan 13, 2026
EPSS: 0.10%
View Details
9.8

D3D Wi-Fi Home Security System ZX-G12 v2.1.1 is vulnerable to RF replay attacks on the 433 MHz sensor communication channel. The system does not implement rolling codes, message authentication, or anti-replay protection, allowing an attacker within RF range to record valid alarm/control frames and replay them to trigger false alarms.

Published: Jan 12, 2026
Modified: Jan 13, 2026
EPSS: 0.09%
View Details
9.8

Information Exposure Through Query Strings in GET Request vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Session Hijacking.This issue affects DX NetOps Spectrum: 24.3.8 and earlier.

Published: Jan 12, 2026
Modified: Jan 14, 2026
EPSS: 0.04%
View Details
9.8

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows OS Command Injection.This issue affects DX NetOps Spectrum: 23.3.6 and earlier.

Published: Jan 12, 2026
Modified: Jan 14, 2026
EPSS: 0.59%
View Details
10.0

Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet.

Published: Jan 12, 2026
Modified: Jan 13, 2026
EPSS: 0.08%
View Details
9.9

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, there is a command injection vulnerability that allows authenticated users to inject stdio_config.command/args into MCP stdio settings, causing the server to execute subprocesses using these injected values. This issue has been patched in…

Published: Jan 10, 2026
Modified: Jan 13, 2026
EPSS: 0.25%
View Details
10.0

XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.5, users with the right to view the Calendar.JSONService page (including guest users) can exploit a SQL injection vulnerability by accessing database info or starting a DoS attack. This issue has been patched in version…

Published: Jan 10, 2026
Modified: Jan 13, 2026
EPSS: 0.03%
View Details
9.1

React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version 2.17.2, and @remix-run/node prior to version 2.17.2, if createFileSessionStorage() is being used from @react-router/node (or @remix-run/node/@remix-run/deno in Remix v2) with an unsigned cookie, it is possible for an attacker to cause the session…

Published: Jan 10, 2026
Modified: Jan 13, 2026
EPSS: 0.06%
View Details
9.1

OpenProject is an open-source, web-based project management software. A Local File Read (LFR) vulnerability exists in the work package PDF export functionality of OpenProject prior to version 16.6.4. By uploading a specially crafted SVG file (disguised as a PNG) as a work package attachment, an attacker can exploit the backend…

Published: Jan 10, 2026
Modified: Jan 14, 2026
Product: openproject openproject
EPSS: 0.03%
View Details
9.8

A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the function WriterHandle.getCmd of the file /isomp-protocol/protocol/getCmd. This manipulation of the argument sessionPath causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.…

Published: Jan 09, 2026
Modified: Jan 13, 2026
EPSS: 0.15%
View Details
9.8

Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux allows Leverage Executable Code in Non-Executable Files.This issue affects Uni2TS: through 1.2.0.

Published: Jan 09, 2026
Modified: Jan 13, 2026
EPSS: 0.05%
View Details
9.8

A vulnerability was found in Sangfor Operation and Maintenance Management System up to 3.0.8. This issue affects some unknown processing of the file /isomp-protocol/protocol/getHis of the component HTTP POST Request Handler. The manipulation of the argument sessionPath results in os command injection. The attack may be launched remotely. The exploit…

Published: Jan 09, 2026
Modified: Jan 13, 2026
EPSS: 0.15%
View Details
9.8

EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the system() function without proper sanitization. An attacker can exploit this by injecting malicious commands into the pppUserName field, allowing arbitrary code execution.

Published: Jan 09, 2026
Modified: Jan 13, 2026
EPSS: 0.24%
View Details
9.8

A Command Injection Vulnerability has been discovered in the DHCP daemon service of D-Link DIR895LA1 v102b07. The vulnerability exists in the lease renewal processing logic where the DHCP hostname parameter is directly concatenated into a system command without proper sanitization. When a DHCP client renews an existing lease with a…

Published: Jan 09, 2026
Modified: Jan 13, 2026
EPSS: 0.27%
View Details
9.8

BeeS Software Solutions BET Portal contains an SQL injection vulnerability in the login functionality of affected sites. The vulnerability enables arbitrary SQL commands to be executed on the backend database.

Published: Jan 09, 2026
Modified: Jan 13, 2026
EPSS: 0.03%
View Details
9.8

Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as an administrator. While it is possible to set up such a password, a user is not informed about such a need. The vendor has not replied to the CNA. Possibly…

Published: Jan 09, 2026
Modified: Jan 14, 2026
Product: vivotek ip7137_firmware
EPSS: 0.04%
View Details
10.0

Remote Code Execution vulnerability that allows unauthenticated attackers to inject arbitrary commands into the hostname of the device.

Published: Jan 09, 2026
Modified: Jan 13, 2026
EPSS: 0.22%
View Details
10.0

This vulnerability allows authenticated attackers to execute commands via the hostname of the device.

Published: Jan 09, 2026
Modified: Jan 13, 2026
EPSS: 0.06%
View Details
9.1

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to missing authorization to unauthorized data modification and deletion due to a missing capability check on the 'delete_object' function in all versions up to, and including, 3.28.25. This makes it possible for unauthenticated attackers to delete arbitrary posts, pages, products,…

Published: Jan 09, 2026
Modified: Jan 13, 2026
EPSS: 0.07%
View Details
10.0

Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain public methods of that class. Depending on the behavior of those methods, there may be JNDI…

Published: Jan 09, 2026
Modified: Jan 13, 2026
EPSS: 0.06%
View Details