CVE Database

Comprehensive vulnerability intelligence with advanced analytics

10.0

n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker to access files on the underlying server through execution of certain form-based workflows. A vulnerable workflow could grant access to an unauthenticated remote attacker, resulting in exposure of sensitive information stored on…

Published: Jan 08, 2026
Modified: Jan 12, 2026
EPSS: 2.96%
View Details
9.8

V-SOL GPON/EPON OLT Platform v2.03 contains an open redirect vulnerability in the script that allows attackers to manipulate the 'parent' GET parameter. Attackers can craft malicious links that redirect logged-in users to arbitrary websites by exploiting improper input validation in the redirect mechanism.

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.06%
View Details
9.8

NREL BEopt 2.8.0.0 contains a DLL hijacking vulnerability that allows attackers to load arbitrary libraries by tricking users into opening application files from remote shares. Attackers can exploit insecure library loading of sdl2.dll and libegl.dll by placing malicious libraries on WebDAV or SMB shares to execute unauthorized code.

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.06%
View Details
9.8

FLIR Thermal Camera PT-Series firmware version 8.0.0.64 contains multiple unauthenticated remote command injection vulnerabilities in the controllerFlirSystem.php script. Attackers can execute arbitrary system commands as root by exploiting unsanitized POST parameters in the execFlirSystem() function through shell_exec() calls. Exploitation evidence was observed by the Shadowserver Foundation on 2026-01-06 (UTC).

Published: Jan 08, 2026
Modified: Jan 08, 2026
EPSS: 0.44%
View Details
9.1

LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 is prone to a server-side request forgery (SSRF) vulnerability due to missing restrictions of the Actions feature in the default configuration. LibreChat enables users to configure agents with predefined instructions and actions that can interact with remote services via OpenAPI…

Published: Jan 07, 2026
Modified: Jan 08, 2026
EPSS: 0.09%
View Details
9.8

Panda3D versions up to and including 1.10.16 egg-mkfont contains a stack-based buffer overflow vulnerability due to use of an unbounded sprintf() call with attacker-controlled input. When constructing glyph filenames, egg-mkfont formats a user-supplied glyph pattern (-gp) into a fixed-size stack buffer without length validation. Supplying an excessively long glyph pattern…

Published: Jan 07, 2026
Modified: Jan 12, 2026
EPSS: 0.08%
View Details
9.8

zlib versions up to and including 1.3.1.2 contain a global buffer overflow in the untgz utility. The TGZfname() function copies an attacker-supplied archive name from argv[] into a fixed-size 1024-byte static global buffer using an unbounded strcpy() call without length validation. Supplying an archive name longer than 1024 bytes results…

Published: Jan 07, 2026
Modified: Jan 14, 2026
EPSS: 0.11%
View Details
9.3

The Tarkov Data Manager is a tool to manage the Tarkov item data. Prior to 02 January 2025, a reflected Cross Site Scripting (XSS) vulnerability in the toast notification system allows any attacker to execute arbitrary JavaScript in the context of a victim's browser session by crafting a malicious URL.…

Published: Jan 07, 2026
Modified: Jan 08, 2026
EPSS: 0.04%
View Details
9.8

The Tarkov Data Manager is a tool to manage the Tarkov item data. Prior to 02 January 2025, an authentication bypass vulnerability in the login endpoint allows any unauthenticated user to gain full admin access to the Tarkov Data Manager admin panel by exploiting a JavaScript prototype property access vulnerability,…

Published: Jan 07, 2026
Modified: Jan 08, 2026
EPSS: 0.32%
View Details
10.0

A command injection vulnerability in the execute_command function of terminal-controller-mcp 0.1.7 allows attackers to execute arbitrary commands via a crafted input.

Published: Jan 07, 2026
Modified: Jan 08, 2026
EPSS: 0.35%
View Details
9.6

A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling attackers…

Published: Jan 07, 2026
Modified: Jan 08, 2026
EPSS: 0.15%
View Details
9.8

Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This issue affects DZS Video Gallery: from n/a through 12.37.

Published: Jan 07, 2026
Modified: Jan 08, 2026
EPSS: 0.05%
View Details
9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla WPCHURCH allows Blind SQL Injection.This issue affects WPCHURCH: from n/a through 2.7.0.

Published: Jan 07, 2026
Modified: Jan 08, 2026
EPSS: 0.04%
View Details
9.1

The Uniffle HTTP client is configured to trust all SSL certificates and disables hostname verification by default. This insecure configuration exposes all REST API communication between the Uniffle CLI/client and the Uniffle Coordinator service to potential Man-in-the-Middle (MITM) attacks. This issue affects all versions from before 0.10.0. Users are recommended…

Published: Jan 07, 2026
Modified: Jan 08, 2026
EPSS: 0.02%
View Details
9.8

The Optional Email plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.3.11. This is due to the plugin not restricting its 'random_password' filter to registration contexts, allowing the filter to affect password reset key generation. This makes it possible for…

Published: Jan 07, 2026
Modified: Jan 08, 2026
EPSS: 0.10%
View Details
9.8

A vulnerability was detected in TRENDnet TEW-713RE 1.02. The impacted element is an unknown function of the file /goformX/formFSrvX. The manipulation of the argument SZCMD results in os command injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was…

Published: Jan 07, 2026
Modified: Jan 08, 2026
EPSS: 0.22%
View Details
9.9

Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Sidepane WordPress Theme, Themify Themify Newsy, Themify Themify Folo, Themify Themify Edmin, Themify Bloggie, Themify Photobox, Themify Wigi, Themify Rezo, Themify Slide allows Upload a Web Shell to a Web Server.This issue affects Themify Sidepane WordPress Theme: from n/a…

Published: Jan 06, 2026
Modified: Jan 08, 2026
EPSS: 0.11%
View Details
9.8

wolfSSH’s key exchange state machine can be manipulated to leak the client’s password in the clear, trick the client to send a bogus signature, or trick the client into skipping user authentication. This affects client applications with wolfSSH version 1.4.21 and earlier. Users of wolfSSH must update or apply the…

Published: Jan 06, 2026
Modified: Jan 12, 2026
Product: wolfssh wolfssh
EPSS: 0.07%
View Details
9.8

Blue Access Cobalt v02.000.195 suffers from an authentication bypass vulnerability, which allows an attacker to selectively proxy requests in order to operate functionality on the web application without the need to authenticate with legitimate credentials.

Published: Jan 06, 2026
Modified: Jan 08, 2026
EPSS: 0.10%
View Details
9.8

Missing Authorization vulnerability in Sfwebservice InWave Jobs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects InWave Jobs: from n/a through 3.5.8.

Published: Jan 06, 2026
Modified: Jan 08, 2026
EPSS: 0.05%
View Details
9.8

An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1. The vulnerability stems from the device's insufficient cookie verification, allowing an attacker to directly request the configuration file address and download the core configuration file without logging into the device management backend. By reading the…

Published: Jan 06, 2026
Modified: Jan 08, 2026
EPSS: 0.06%
View Details
9.8

An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point, there is a misconfiguration vulnerability about vsftpd. Through this vulnerability, all files uploaded anonymously via the FTP protocol is automatically owned by the root user and remote attackers could gain root-level control over the devices.

Published: Jan 06, 2026
Modified: Jan 08, 2026
EPSS: 0.14%
View Details
9.8

Arteco Web Client DVR/NVR contains a session hijacking vulnerability with insufficient session ID complexity that allows remote attackers to bypass authentication. Attackers can brute force session IDs within a specific numeric range to obtain valid sessions and access live camera streams without authorization.

Published: Jan 06, 2026
Modified: Jan 08, 2026
EPSS: 0.62%
View Details
9.8

Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization controls. Attackers can access hidden system resources like '/#/content-creation' by manipulating client-side access restrictions.

Published: Jan 06, 2026
Modified: Jan 08, 2026
EPSS: 0.09%
View Details