CVE Database

Comprehensive vulnerability intelligence with advanced analytics

9.8

Arteco Web Client DVR/NVR contains a session hijacking vulnerability with insufficient session ID complexity that allows remote attackers to bypass authentication. Attackers can brute force session IDs within a specific numeric range to obtain valid sessions and access live camera streams without authorization.

Published: Jan 06, 2026
Modified: Jan 08, 2026
EPSS: 0.62%
View Details
9.8

Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization controls. Attackers can access hidden system resources like '/#/content-creation' by manipulating client-side access restrictions.

Published: Jan 06, 2026
Modified: Jan 08, 2026
EPSS: 0.09%
View Details
9.8

Plexus anblick Digital Signage Management 3.1.13 contains an open redirect vulnerability in the 'PantallaLogin' script that allows attackers to manipulate the 'pagina' GET parameter. Attackers can craft malicious links that redirect users to arbitrary websites by exploiting improper input validation in the parameter.

Published: Jan 06, 2026
Modified: Jan 08, 2026
EPSS: 0.06%
View Details
9.8

The FS Registration Password plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.1. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary…

Published: Jan 06, 2026
Modified: Jan 08, 2026
EPSS: 0.09%
View Details
9.8

The AS Password Field In Default Registration Form plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated…

Published: Jan 06, 2026
Modified: Jan 08, 2026
EPSS: 0.10%
View Details
9.8

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below contain a Use After Free vulnerability in the CIccXform::Create() function, where it deletes the hint. This issue is fixed in version 2.3.1.1.

Published: Jan 06, 2026
Modified: Jan 12, 2026
EPSS: 0.12%
View Details
9.8

Insufficient Verification of Data Authenticity vulnerability in TECNO Mobile com.Afmobi.Boomplayer allows Authentication Bypass.This issue affects com.Afmobi.Boomplayer: 7.4.63.

Published: Jan 06, 2026
Modified: Jan 08, 2026
EPSS: 0.02%
View Details
9.8

Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium libsodium

Published: Jan 06, 2026
Modified: Jan 08, 2026
EPSS: 0.05%
View Details
9.1

Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, unauthenticated users can trigger database backup operations via specific admin actions, potentially leading to resource exhaustion or information disclosure. Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.…

Published: Jan 05, 2026
Modified: Jan 12, 2026
Product: craftcms craft_cms
EPSS: 0.11%
View Details
9.9

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions prior to and including v4.0.0-beta.434, low privileged users are able to see the private key of the root user on the Coolify instance. This allows them to ssh to the server and authenticate as…

Published: Jan 05, 2026
Modified: Jan 12, 2026
Product: coollabs coolify
EPSS: 0.05%
View Details
9.6

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.445, parameters coming from docker-compose.yaml are not sanitized when used in commands. If a victim user creates an application from an attacker repository (using build pack "docker compose"), the attacker can execute commands on…

Published: Jan 05, 2026
Modified: Jan 12, 2026
Product: coollabs coolify
EPSS: 0.06%
View Details
9.1

An issue in Passy v.1.6.3 allows a remote authenticated attacker to execute arbitrary commands via a crafted HTTP request using a specific payload injection.

Published: Jan 05, 2026
Modified: Jan 08, 2026
EPSS: 0.30%
View Details
9.1

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The lack of a length check leads to out-of-bounds writes via malformed NAS packets.

Published: Jan 05, 2026
Modified: Jan 09, 2026
Product: samsung exynos_w920_firmware
EPSS: 0.05%
View Details
9.9

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, the Git Repository field during project creation is vulnerable to command injection. User input is not properly sanitized, allowing attackers to inject arbitrary shell commands that execute on the underlying server during the…

Published: Jan 05, 2026
Modified: Jan 12, 2026
Product: coollabs coolify
EPSS: 0.22%
View Details
9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Waituk Entrada allows SQL Injection.This issue affects Entrada: from n/a through 5.7.7.

Published: Jan 05, 2026
Modified: Jan 08, 2026
EPSS: 0.04%
View Details
9.8

WHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An attacker within range can pair with the device and issue movement commands, override speed restrictions, and manipulate configuration profiles without any credentials or user interaction.

Published: Jan 05, 2026
Modified: Jan 08, 2026
EPSS: 0.11%
View Details
9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring (Awie export modules) allows SQL Injection to unauthenticated user. This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.3, from 24.04.0 before 24.04.3.

Published: Jan 05, 2026
Modified: Jan 08, 2026
EPSS: 0.03%
View Details
9.8

Missing Authentication for Critical Function vulnerability in Centreon Infra Monitoring centreon-awie (Awie import module) allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.3, from 24.04.0 before 24.04.3.

Published: Jan 05, 2026
Modified: Jan 08, 2026
EPSS: 0.04%
View Details
9.1

Unrestricted Upload of File with Dangerous Type vulnerability in Meow Apps Media File Renamer allows Using Malicious Files.This issue affects Media File Renamer: from n/a through 5.7.7.

Published: Jan 05, 2026
Modified: Jan 08, 2026
EPSS: 0.10%
View Details
9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infility Infility Global allows SQL Injection.This issue affects Infility Global: from n/a through 2.14.48.

Published: Jan 05, 2026
Modified: Jan 08, 2026
EPSS: 0.04%
View Details
9.9

Unrestricted Upload of File with Dangerous Type vulnerability in Themify Shopo allows Upload a Web Shell to a Web Server.This issue affects Shopo: from n/a through 1.1.4.

Published: Jan 05, 2026
Modified: Jan 08, 2026
EPSS: 0.03%
View Details
9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Amazon Native Shopping Recommendations allows SQL Injection.This issue affects Amazon Native Shopping Recommendations: from n/a through 1.3.

Published: Jan 05, 2026
Modified: Jan 08, 2026
EPSS: 0.02%
View Details
9.8

Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via type parameter, which can lead to remote code execution or another exploitation. Version 2.3.10 fixes the issue.

Published: Jan 02, 2026
Modified: Jan 08, 2026
Product: webkul bagisto
EPSS: 0.31%
View Details
9.8

Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection. When a normal customer orders any product, in the `add address` step they can inject a value to run in admin view. The issue can lead to remote code execution. Version 2.3.10…

Published: Jan 02, 2026
Modified: Jan 08, 2026
Product: webkul bagisto
EPSS: 0.36%
View Details