CVE Database

Comprehensive vulnerability intelligence with advanced analytics

9.8

Bagisto is an open source laravel eCommerce platform. In versions on the 2.3 branch prior to 2.3.10, API routes remain active even after initial installation is complete. The underlying API endpoints (`/install/api/*`) are directly accessible and exploitable without any authentication. An attacker can bypass the Ib installer entirely by calling…

Published: Jan 02, 2026
Modified: Jan 08, 2026
Product: webkul bagisto
EPSS: 0.29%
View Details
9.8

gpsd before commit dc966aa contains a heap-based out-of-bounds write vulnerability in the drivers/driver_nmea2000.c file. The hnd_129540 function, which handles NMEA2000 PGN 129540 (GNSS Satellites in View) packets, fails to validate the user-supplied satellite count against the size of the skyview array (184 elements). This allows an attacker to write beyond…

Published: Jan 02, 2026
Modified: Jan 12, 2026
Product: gpsd_project gpsd
EPSS: 0.09%
View Details
9.8

SQL injection in gosaliajainam/online-movie-booking 5.5 in movie_details.php allows attackers to gain sensitive information.

Published: Jan 02, 2026
Modified: Jan 12, 2026
Product: gosaliajainam online-movie-booking
EPSS: 0.04%
View Details
9.8

The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.24. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords,…

Published: Jan 02, 2026
Modified: Jan 02, 2026
EPSS: 0.09%
View Details
9.1

Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 expose two features that can be chained together to steal JWT authentication tokens without any prior authentication. The attack combines WebSocket-based request enumeration with unauthenticated polling of access request status.…

Published: Jan 01, 2026
Modified: Jan 06, 2026
Product: signalk signal_k_server
EPSS: 0.12%
View Details
9.6

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the internal state (`restoreFilePath`) of the server via the `/skServer/validateBackup` endpoint. This allows the attacker to hijack the administrator's "Restore" functionality to overwrite critical server…

Published: Jan 01, 2026
Modified: Jan 06, 2026
EPSS: 0.16%
View Details
9.1

Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule in the database. The value is then passed to a NodeVM value to execute as code. Without sanitization, it leads to a Remote Code Execution. Version 0.99.49 fixes…

Published: Dec 31, 2025
Modified: Jan 13, 2026
EPSS: 0.52%
View Details
9.8

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecure key generation algorithm in the API key and beta (assistant/agent share auth) token generation process allows these tokens to be mutually derivable. Specifically, both tokens are generated using the same `URLSafeTimedSerializer` with…

Published: Dec 31, 2025
Modified: Jan 06, 2026
Product: infiniflow ragflow
EPSS: 0.06%
View Details
9.8

libcoap versions up to and including 4.3.5, prior to commit 30db3ea, contain a stack-based buffer overflow in address resolution when attacker-controlled hostname data is copied into a fixed 256-byte stack buffer without proper bounds checking. A remote attacker can trigger a crash and potentially achieve remote code execution depending on…

Published: Dec 31, 2025
Modified: Jan 14, 2026
Product: libcoap libcoap
EPSS: 0.28%
View Details
9.8

Ksenia Security Lares 4.0 Home Automation version 1.6 contains a critical security flaw that exposes the alarm system PIN in the 'basisInfo' XML file after authentication. Attackers can retrieve the PIN from the server response to bypass security measures and disable the alarm system without additional authentication.

Published: Dec 30, 2025
Modified: Jan 13, 2026
Product: kseniasecurity lares_firmware
EPSS: 0.12%
View Details
9.8

Anevia Flamingo XL 3.2.9 contains a restricted shell vulnerability that allows remote attackers to escape the sandboxed environment through the traceroute command. Attackers can exploit the traceroute command to inject shell commands and gain full root access to the device by bypassing the restricted login environment.

Published: Dec 30, 2025
Modified: Jan 14, 2026
Product: ateme flamingo_xl_firmware
EPSS: 0.11%
View Details
9.8

Akuvox Smart Intercom S539 contains an unauthenticated vulnerability that allows remote attackers to access live video streams by requesting the video.cgi endpoint on port 8080. Attackers can retrieve video stream data without authentication by directly accessing the specified endpoint on affected Akuvox doorphone and intercom devices.

Published: Dec 30, 2025
Modified: Jan 13, 2026
Product: akuvox x912_firmware
EPSS: 0.19%
View Details
9.8

JM-DATA ONU JF511-TV version 1.0.67 uses default credentials that allow attackers to gain unauthorized access to the device with administrative privileges.

Published: Dec 30, 2025
Modified: Dec 31, 2025
EPSS: 0.07%
View Details
9.8

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the username parameter. Attackers can exploit index.php and login.php scripts by injecting arbitrary shell commands through the HTTP POST 'username' parameter to execute system commands.

Published: Dec 30, 2025
Modified: Jan 13, 2026
Product: sound4 pulse_firmware
EPSS: 1.31%
View Details
9.8

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive system files. Attackers can exploit the vulnerability by manipulating the 'file' GET parameter to disclose arbitrary files on the affected device.

Published: Dec 30, 2025
Modified: Jan 13, 2026
Product: sound4 pulse_firmware
EPSS: 0.23%
View Details
9.8

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated vulnerability that allows remote attackers to access live radio stream information through webplay or ffmpeg scripts. Attackers can exploit the vulnerability by calling specific web scripts to disclose radio stream details without requiring authentication.

Published: Dec 30, 2025
Modified: Jan 13, 2026
Product: sound4 pulse_firmware
EPSS: 0.50%
View Details
9.8

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains a network vulnerability that allows unauthenticated attackers to send ICMP signals to arbitrary hosts through network command scripts. Attackers can abuse ping.php, traceroute.php, and dns.php to generate network flooding attacks targeting external hosts.

Published: Dec 30, 2025
Modified: Jan 13, 2026
Product: sound4 pulse_firmware
EPSS: 0.68%
View Details
9.8

MiniDVBLinux 5.4 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands as root through the 'command' GET parameter. Attackers can exploit the /tpl/commands.sh endpoint by sending malicious command values to gain root-level system access.

Published: Dec 30, 2025
Modified: Jan 12, 2026
Product: minidvblinux minidvblinux
EPSS: 0.98%
View Details
9.8

An issue was discovered in matio 1.5.28. A heap-based memory corruption can occur in Mat_VarCreateStruct() when the nfields value does not match the actual number of strings in the fields array. This leads to out-of-bounds reads and invalid memory frees during cleanup, potentially causing a segmentation fault or heap corruption.

Published: Dec 30, 2025
Modified: Jan 09, 2026
Product: matio_project matio
EPSS: 0.05%
View Details
9.1

Authentication Bypass in fosrl/pangolin v1.6.2 and before allows attackers to access Pangolin resource via Insecure Default Configuration

Published: Dec 30, 2025
Modified: Jan 07, 2026
EPSS: 0.07%
View Details
9.8

RustFS is a distributed object storage system built in Rust. In versions prior to 1.0.0-alpha.78, RustFS implements gRPC authentication using a hardcoded static token `"rustfs rpc"` that is publicly exposed in the source code repository, hardcoded on both client and server sides, non-configurable with no mechanism for token rotation, and…

Published: Dec 30, 2025
Modified: Jan 05, 2026
EPSS: 3.14%
View Details
9.8

JD Cloud NAS routers AX1800 (4.3.1.r4308 and earlier), AX3000 (4.3.1.r4318 and earlier), AX6600 (4.5.1.r4533 and earlier), BE6500 (4.4.1.r4308 and earlier), ER1 (4.5.1.r4518 and earlier), and ER2 (4.5.1.r4518 and earlier) contain an unauthorized remote command execution vulnerability.

Published: Dec 30, 2025
Modified: Jan 09, 2026
EPSS: 0.41%
View Details
9.6

Cross-Site Request Forgery (CSRF) vulnerability in ConoHa by GMO WING WordPress Migrator allows Upload a Web Shell to a Web Server.This issue affects WING WordPress Migrator: from n/a through 1.1.9.

Published: Dec 30, 2025
Modified: Dec 31, 2025
EPSS: 0.02%
View Details
9.8

A vulnerability was determined in Tenda W6-S 1.0.0.4(510). This impacts an unknown function of the file /bin/httpd of the component R7websSsecurityHandler. Executing manipulation of the argument Cookie can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

Published: Dec 30, 2025
Modified: Jan 02, 2026
Product: tenda w6-s_firmware
EPSS: 0.18%
View Details