CVE Database

Comprehensive vulnerability intelligence with advanced analytics

9.8

Missing Authorization vulnerability in Aruba.it Dev Aruba HiSpeed Cache aruba-hispeed-cache allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Aruba HiSpeed Cache: from n/a through < 3.0.3.

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.05%
View Details
9.8

Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injection.This issue affects Newsletters: from n/a through

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.05%
View Details
9.8

Unrestricted Upload of File with Dangerous Type vulnerability in contentstudio Contentstudio contentstudio allows Upload a Web Shell to a Web Server.This issue affects Contentstudio: from n/a through

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.06%
View Details
9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RiceTheme Felan Framework felan-framework allows SQL Injection.This issue affects Felan Framework: from n/a through

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.04%
View Details
9.8

Authentication Bypass Using an Alternate Path or Channel vulnerability in RiceTheme Felan Framework felan-framework allows Authentication Abuse.This issue affects Felan Framework: from n/a through

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.07%
View Details
9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AmentoTech Workreap (theme's plugin) workreap allows SQL Injection.This issue affects Workreap (theme's plugin): from n/a through

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.04%
View Details
9.1

Server-Side Request Forgery (SSRF) vulnerability in _nK nK Themes Helper nk-themes-helper allows Server Side Request Forgery.This issue affects nK Themes Helper: from n/a through

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.04%
View Details
9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vanquish WooCommerce Orders & Customers Exporter woocommerce-orders-ei allows SQL Injection.This issue affects WooCommerce Orders & Customers Exporter: from n/a through

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.04%
View Details
9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in QantumThemes Typify typify allows PHP Local File Inclusion.This issue affects Typify: from n/a through

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.15%
View Details
9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Mitech mitech allows PHP Local File Inclusion.This issue affects Mitech: from n/a through

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.15%
View Details
9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Moody tm-moody allows PHP Local File Inclusion.This issue affects Moody: from n/a through

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.15%
View Details
9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TMRW-studio Atlas atlas allows PHP Local File Inclusion.This issue affects Atlas: from n/a through

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.15%
View Details
9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in THEMELOGI Navian navian allows PHP Local File Inclusion.This issue affects Navian: from n/a through

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.15%
View Details
9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Brook - Agency Business Creative brook allows PHP Local File Inclusion.This issue affects Brook - Agency Business Creative: from n/a through

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.15%
View Details
9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove AeroLand aeroland allows PHP Local File Inclusion.This issue affects AeroLand: from n/a through

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.15%
View Details
9.8

Missing Authorization vulnerability in Kaira Blockons blockons allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Blockons: from n/a through

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.05%
View Details
9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in brandexponents Oshine oshin allows PHP Local File Inclusion.This issue affects Oshine: from n/a through

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.15%
View Details
9.8

Missing Authorization vulnerability in sizam REHub Framework rehub-framework allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects REHub Framework: from n/a through

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.05%
View Details
9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes OchaHouse ochahouse allows PHP Local File Inclusion.This issue affects OchaHouse: from n/a through

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.15%
View Details
9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magentech Rozy - Flower Shop rozy allows PHP Local File Inclusion.This issue affects Rozy - Flower Shop: from n/a through

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.15%
View Details
9.8

The WP Cost Estimation plugin for WordPress is vulnerable to arbitrary file uploads and deletion due to missing file type validation in the lfb_upload_form and lfb_removeFile AJAX actions in versions up to, and including, 9.642. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites…

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.27%
View Details
9.1

Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below is vulnerable to a critical authentication bypass when REVERSE_PROXY_AUTH is enabled. The application blindly trusts HTTP headers for user authentication without verifying the request originated from a trusted reverse proxy. An attacker can impersonate any user, including…

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.09%
View Details
9.9

n8n is an open source workflow automation platform. In versions 0.121.2 and below, an authenticated attacker may be able to execute malicious code using the n8n service. This could result in full compromise and can impact both self-hosted and n8n Cloud instances. This issue is fixed in version 1.121.3. Administrators…

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.05%
View Details
9.8

ClipBucket v5 is an open source video sharing platform. Versions 5.5.2-#187 and below allow an attacker to perform Blind SQL Injection through the add comment section within a channel. When adding a comment within a channel, there is a POST request to the /actions/ajax.php endpoint. The obj_id parameter within the…

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.04%
View Details