CVE Database

Comprehensive vulnerability intelligence with advanced analytics

9.8

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.28.25. This is due to insufficient validation of user-supplied role values in the 'validate_value', 'pre_update_value', and 'get_fields_display' functions. This makes it possible for unauthenticated attackers to register as administrators and…

Published: Jan 09, 2026
Modified: Jan 13, 2026
EPSS: 0.04%
View Details
9.4

KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is logged in, endpoints such as /cgi-bin/system-tool accept unauthenticated requests with empty or invalid session values. This design flaw lets attackers piggyback on another user's active session to retrieve sensitive configuration data or execute privileged…

Published: Jan 08, 2026
Modified: Jan 13, 2026
EPSS: 0.11%
View Details
9.1

An issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/goform/setWan, /goform/setLan, /goform/wirelessBasic) that do not enforce authentication. A remote unauthenticated attacker can modify WAN, LAN, and wireless settings directly, leading to privilege escalation and denial of service.

Published: Jan 08, 2026
Modified: Jan 13, 2026
EPSS: 0.18%
View Details
9.4

The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLExpress expressions, but it does not filter user input, allowing attackers to use the File class to perform arbitrary file reading and writing.

Published: Jan 08, 2026
Modified: Jan 13, 2026
EPSS: 0.06%
View Details
9.8

JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The application passes the attacker-supplied JDBC URL directly to the H2 driver, allowing the use of certain directives to execute arbitrary Java code. A different vulnerability than CVE-2025-10770.

Published: Jan 08, 2026
Modified: Jan 13, 2026
EPSS: 0.38%
View Details
9.8

Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote code execution.

Published: Jan 08, 2026
Modified: Jan 13, 2026
EPSS: 0.26%
View Details
9.8

OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predictable values of 'formid', and download or delete all user-uploaded files, or upload new files.

Published: Jan 08, 2026
Modified: Jan 13, 2026
EPSS: 0.07%
View Details
9.8

An issue was discovered in Nitro PDF Pro for Windows before 14.42.0.34. In certain cases, it displays signer information from a non-verified PDF field rather than from the verified certificate subject. This could allow a document to present inconsistent signer details. The display logic was updated to ensure signer information…

Published: Jan 08, 2026
Modified: Jan 13, 2026
EPSS: 0.02%
View Details
9.8

SQL Injection is present on the hfInventoryDistFormID parameter in the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34. Unsanitized user input is incorporated directly into SQL queries without proper parameterization or escaping. This vulnerability allows remote attackers to execute arbitrary SQL commands

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.10%
View Details
9.1

There is an issue on the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34 that enables remote attacker to create financial discrepancies by purchasing items with a negative quantity. This vulnerability is possible due to reliance on client-side input validation controls.

Published: Jan 08, 2026
Modified: Jan 13, 2026
EPSS: 0.05%
View Details
9.8

indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in master/review_action.php via the proId parameter.

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.04%
View Details
9.0

This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.

Published: Jan 08, 2026
Modified: Jan 14, 2026
EPSS: 0.30%
View Details
9.0

This vulnerability allows a Backup or Tape Operator to write files as root.

Published: Jan 08, 2026
Modified: Jan 14, 2026
EPSS: 0.05%
View Details
9.0

This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter.

Published: Jan 08, 2026
Modified: Jan 14, 2026
EPSS: 0.30%
View Details
9.1

An issue was discovered in the AppConnector component version 10.10.0.183 and earlier of enaio 10.10, in the AppConnector component version 11.0.0.183 and earlier of enaio 11.0, and in the AppConnctor component version 11.10.0.183 and earlier of enaio 11.10. The vulnerability allows authenticated remote attackers to inject arbitrary SMTP commands via…

Published: Jan 08, 2026
Modified: Jan 09, 2026
EPSS: 0.17%
View Details
9.4

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions up to and including 1.5.0, the application checks the validity of the username but appears to skip, misinterpret, or incorrectly validate the password when the provided username matches a known system…

Published: Jan 08, 2026
Modified: Jan 12, 2026
EPSS: 0.05%
View Details
9.3

The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 4.22.0 and 3.3.8, the current rule 922110 has a bug when processing multipart requests with multiple parts. When the first rule in a chain iterates over…

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.04%
View Details
9.8

A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a key executable, leading to execution of attacker-supplied code under the context of SYSTEM on affected installations.

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.20%
View Details
9.8

Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login password  if they are using the 1.5.x or 1.6.x interactive installer to either create a new cluster or add new hosts to an existing cluster. The environment is not affected if the PXE boot mechanism is utilized along…

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.06%
View Details
9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in themesuite Automotive Listings automotive allows Blind SQL Injection.This issue affects Automotive Listings: from n/a through

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.04%
View Details
9.8

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Corpkit corpkit allows Upload a Web Shell to a Web Server.This issue affects Corpkit: from n/a through

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.06%
View Details
9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VanKarWai Lobo lobo allows Blind SQL Injection.This issue affects Lobo: from n/a through < 2.8.6.

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.04%
View Details
9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Neo Ocular neoocular allows PHP Local File Inclusion.This issue affects Neo Ocular: from n/a through < 1.2.

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.15%
View Details
9.8

Authentication Bypass Using an Alternate Path or Channel vulnerability in Arraytics Timetics timetics allows Authentication Abuse.This issue affects Timetics: from n/a through

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.07%
View Details