CVE Database

Comprehensive vulnerability intelligence with advanced analytics

8.2

VIAVIWEB Wallpaper Admin 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating login credentials. Attackers can exploit the login page by injecting 'admin' or 1=1-- - payload to gain unauthorized access to the administrative interface.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.06%
View Details
7.5

Owlfiles File Manager 12.0.1 contains a path traversal vulnerability in its built-in HTTP server that allows attackers to access system directories. Attackers can exploit the vulnerability by crafting GET requests with directory traversal sequences to access restricted system directories on the device.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.22%
View Details
8.4

CoolerMaster MasterPlus 1.8.5 contains an unquoted service path vulnerability in the MPService that allows local attackers to execute code with elevated system privileges. Attackers can drop a malicious executable in the service path and trigger code execution during service startup or system reboot.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.01%
View Details
8.8

4images 1.9 contains a remote command execution vulnerability that allows authenticated administrators to inject reverse shell code through template editing functionality. Attackers can save malicious code in the template and execute arbitrary commands by accessing a specific categories.php endpoint with a crafted cat_id parameter.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.23%
View Details
8.2

Senayan Library Management System 9.0.0 contains a SQL injection vulnerability in the 'class' parameter that allows attackers to inject malicious SQL queries. Attackers can exploit the vulnerability by submitting crafted payloads to manipulate database queries and potentially extract sensitive information.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.04%
View Details
8.4

Splashtop 8.71.12001.0 contains an unquoted service path vulnerability in the Splashtop Software Updater Service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Splashtop\Splashtop Software Updater\ to inject malicious executables and escalate privileges.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.01%
View Details
7.5

CuteEditor for PHP (now referred to as Rich Text Editor) 6.6 contains a directory traversal vulnerability in the browse template feature that allows attackers to write files to arbitrary web root directories. Attackers can exploit the ServerMapPath() function by renaming uploaded HTML files using directory traversal sequences to write files…

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.19%
View Details
8.8

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Prior to 2.3.1.2, There is a heap-based buffer overflow in SIccCalcOp::Describe() at IccProfLib/IccMpeCalc.cpp. This vulnerability affects users of the iccDEV library who process ICC color profiles.…

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.04%
View Details
7.8

Substance3D - Modeler versions 1.22.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.03%
View Details
7.8

Substance3D - Modeler versions 1.22.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.03%
View Details
7.8

A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking Virtual Intranet Access (VIA) client. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.01%
View Details
8.2

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono’s JWK/JWKS JWT verification middleware allowed the algorithm specified in the JWT header to influence signature verification when the selected JWK did not explicitly define an algorithm. This could…

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.02%
View Details
8.2

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono’s JWK/JWKS JWT verification middleware allowed the JWT header’s alg value to influence signature verification when the selected JWK did not explicitly specify an algorithm. This could enable JWT…

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.02%
View Details
7.8

Substance3D - Designer versions 15.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Published: Jan 13, 2026
Modified: Jan 14, 2026
Product: adobe substance_3d_designer
EPSS: 0.03%
View Details
7.8

Substance3D - Sampler versions 5.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.03%
View Details
7.8

Substance3D - Painter versions 11.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.03%
View Details
7.8

Substance3D - Stager versions 3.1.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.03%
View Details
7.2

Arbitrary file upload vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to upload arbitrary files as a privilege user and execute arbitrary commands on the underlying operating system.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.05%
View Details
7.2

Authenticated arbitrary file write vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to create or modify arbitrary files and execute arbitrary commands as a privileged user on the underlying operating system.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.05%
View Details
7.2

An improper input handling vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor with valid credentials to trigger unintended behavior on the affected system.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.04%
View Details
7.2

Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.13%
View Details
7.2

Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.13%
View Details
7.2

Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.13%
View Details
7.2

A stack overflow vulnerability exists in the AOS-10 web-based management interface of a Mobility Gateway. Successful exploitation could allow an authenticated malicious actor to execute arbitrary code as a privileged user on the underlying operating system.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.06%
View Details