CVE Feed

    Dashboard / CVE

    8.5
    High

    CVE-2022-50901

    Last Modified: 5 Mar 2026

    Wondershare Dr.Fone 11.4.9 contains an unquoted service path vulnerability in the DFWSIDService that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Wondershare\Wondershare Dr.Fone\ to inject malicious executables that would run with LocalSystem privileges.

    Published: 13 Jan 2026
    8.5
    High

    CVE-2022-50900

    Last Modified: 5 Mar 2026

    Wondershare Dr.Fone 12.0.18 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated system privileges. Attackers can exploit the misconfigured service path to insert malicious code that will be executed with LocalSystem permissions during service startup.

    Published: 13 Jan 2026
    8.7
    High

    CVE-2022-50899

    Last Modified: 7 Apr 2026

    Geonetwork 3.10 through 4.2.0 contains an XML external entity vulnerability in PDF rendering that allows attackers to retrieve arbitrary files from the server. Attackers can exploit the insecure XML parser by crafting a malicious XML document with external entity references to read system files through the baseURL parameter in PDF creation requests.

    Published: 13 Jan 2026
    8.6
    High

    CVE-2022-50898

    Last Modified: 29 Jan 2026

    NanoCMS 0.4 contains an authenticated file upload vulnerability that allows remote code execution through unvalidated page content creation. Authenticated attackers can upload PHP files with arbitrary code to the server's pages directory by exploiting the page creation mechanism without proper input sanitization.

    Published: 13 Jan 2026
    8.7
    High

    CVE-2022-50897

    Last Modified: 5 Mar 2026

    mPDF 7.0 contains a local file inclusion vulnerability that allows attackers to read arbitrary system files by manipulating annotation file parameters. Attackers can generate URL-encoded or base64 payloads to include local files through crafted annotation content with file path specifications.

    Published: 13 Jan 2026
    8.8
    High

    CVE-2022-50895

    Last Modified: 7 Apr 2026

    Aero CMS 0.0.1 contains a SQL injection vulnerability in the author parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, time-based, and UNION query techniques to extract sensitive database information and potentially compromise the system.

    Published: 13 Jan 2026
    5.1
    Medium

    CVE-2022-50891

    Last Modified: 7 Apr 2026

    Owlfiles File Manager 12.0.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the path parameter in HTTP server endpoints. Attackers can craft URLs targeting the download and list endpoints with embedded script tags to execute arbitrary JavaScript in users' browsers.

    Published: 13 Jan 2026
    8.7
    High

    CVE-2022-50890

    Last Modified: 7 Apr 2026

    Owlfiles File Manager 12.0.1 contains a path traversal vulnerability in its built-in HTTP server that allows attackers to access system directories. Attackers can exploit the vulnerability by crafting GET requests with directory traversal sequences to access restricted system directories on the device.

    Published: 13 Jan 2026
    8.5
    High

    CVE-2022-50808

    Last Modified: 15 Apr 2026

    CoolerMaster MasterPlus 1.8.5 contains an unquoted service path vulnerability in the MPService that allows local attackers to execute code with elevated system privileges. Attackers can drop a malicious executable in the service path and trigger code execution during service startup or system reboot.

    Published: 13 Jan 2026
    Unknown

    CVE-2022-50807

    Last Modified: 14 Jan 2026

    This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.

    Published: 13 Jan 2026
    8.6
    High

    CVE-2022-50806

    Last Modified: 7 Apr 2026

    4images 1.9 contains a remote command execution vulnerability that allows authenticated administrators to inject reverse shell code through template editing functionality. Attackers can save malicious code in the template and execute arbitrary commands by accessing a specific categories.php endpoint with a crafted cat_id parameter.

    Published: 13 Jan 2026
    8.8
    High

    CVE-2022-50805

    Last Modified: 15 Apr 2026

    Senayan Library Management System 9.0.0 contains a SQL injection vulnerability in the 'class' parameter that allows attackers to inject malicious SQL queries. Attackers can exploit the vulnerability by submitting crafted payloads to manipulate database queries and potentially extract sensitive information.

    Published: 13 Jan 2026
    8.5
    High

    CVE-2022-50693

    Last Modified: 15 Apr 2026

    Splashtop 8.71.12001.0 contains an unquoted service path vulnerability in the Splashtop Software Updater Service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Splashtop\Splashtop Software Updater\ to inject malicious executables and escalate privileges.

    Published: 13 Jan 2026
    5.3
    Medium

    CVE-2021-47751

    Last Modified: 28 Jul 2026

    CuteEditor for PHP (now referred to as Rich Text Editor) 6.6 contains a directory traversal vulnerability in the browse template feature that allows attackers to write files to arbitrary web root directories. Attackers can exploit the ServerMapPath() function by renaming uploaded HTML files using directory traversal sequences to write files outside the intended template directory.

    Published: 13 Jan 2026
    8.7
    High

    CVE-2021-47749

    Last Modified: 5 Mar 2026

    YouPHPTube <= 7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to access arbitrary files by manipulating the 'lang' parameter in GET requests. Attackers can exploit the path traversal flaw in locale/function.php to include and view PHP files outside the intended directory by using directory traversal sequences.

    Published: 13 Jan 2026
    9.3
    Critical

    CVE-2020-36911

    Last Modified: 5 Mar 2026

    Covenant 0.1.3 - 0.5 contains a remote code execution vulnerability that allows attackers to craft malicious JWT tokens with administrative privileges. Attackers can generate forged tokens with admin roles and upload custom DLL payloads to execute arbitrary commands on the target system.

    Published: 13 Jan 2026
    10
    Critical

    CVE-2026-23478

    Last Modified: 18 Apr 2026

    Cal.com is open-source scheduling software. From 3.1.6 to before 6.0.7, there is a vulnerability in a custom NextAuth JWT callback that allows attackers to gain full authenticated access to any user's account by supplying a target email address via session.update(). This vulnerability is fixed in 6.0.7.

    Published: 13 Jan 2026
    4.3
    Medium

    CVE-2025-68658

    Last Modified: 21 Jan 2026

    Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. opensourcepos 3.4.0 and 3.4.1 has a stored XSS vulnerability exists in the Configuration (Information) functionality. An authenticated user with the permission “Configuration: Change OSPOS's Configuration” can inject a malicious JavaScript payload into the Company Name field when updating Information in Configuration. The malicious payload is stored and later triggered when a user accesses /sales/complete. First select Sales, and choose New Item to create an item, then click on Completed . Due to insufficient input validation and output encoding, the payload is rendered and executed in the user’s browser, resulting in a stored XSS vulnerability. This vulnerability is fixed in 3.4.2.

    Published: 13 Jan 2026
    5.7
    Medium

    CVE-2025-68947

    Last Modified: 15 Apr 2026

    NSecsoft 'NSecKrnl' is a Windows driver that allows a local, authenticated attacker to terminate processes owned by other users, including SYSTEM and Protected Processes by issuing crafted IOCTL requests to the driver.

    Published: 13 Jan 2026
    6.5
    Medium

    CVE-2026-0543

    Last Modified: 18 Apr 2026

    Improper Input Validation (CWE-20) in Kibana's Email Connector can allow an attacker to cause an Excessive Allocation (CAPEC-130) through a specially crafted email address parameter. This requires an attacker to have authenticated access with view-level privileges sufficient to execute connector actions. The application attempts to process specially crafted email format, resulting in complete service unavailability for all users until manual restart is performed.

    Published: 13 Jan 2026
    6.5
    Medium

    CVE-2026-0531

    Last Modified: 18 Apr 2026

    Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-130) via a specially crafted bulk retrieval request. This requires an attacker to have low-level privileges equivalent to the viewer role, which grants read access to agent policies. The crafted request can cause the application to perform redundant database retrieval operations that immediately consume memory until the server crashes and becomes unavailable to all users.

    Published: 13 Jan 2026
    6.5
    Medium

    CVE-2026-0530

    Last Modified: 18 Apr 2026

    Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-130) via a specially crafted request. This causes the application to perform redundant processing operations that continuously consume system resources until service degradation or complete unavailability occurs.

    Published: 13 Jan 2026
    6.5
    Medium

    CVE-2026-0528

    Last Modified: 18 Apr 2026

    Improper Validation of Array Index (CWE-129) exists in Metricbeat can allow an attacker to cause a Denial of Service through Input Data Manipulation (CAPEC-153) via specially crafted, malformed payloads sent to the Graphite server metricset or Zookeeper server metricset. Additionally, Improper Input Validation (CWE-20) exists in the Prometheus helper module that can allow an attacker to cause a Denial of Service through Input Data Manipulation (CAPEC-153) via specially crafted, malformed metric data.

    Published: 13 Jan 2026
    8.7
    High

    CVE-2026-22871

    Last Modified: 18 Apr 2026

    GuardDog is a CLI tool to identify malicious PyPI packages. Prior to 2.7.1, there is a path traversal vulnerability exists in GuardDog's safe_extract() function that allows malicious PyPI packages to write arbitrary files outside the intended extraction directory, leading to Arbitrary File Overwrite and Remote Code Execution on systems running GuardDog. This vulnerability is fixed in 2.7.1.

    Published: 13 Jan 2026
    7.1
    High

    CVE-2026-22870

    Last Modified: 18 Apr 2026

    GuardDog is a CLI tool to identify malicious PyPI packages. Prior to 2.7.1, GuardDog's safe_extract() function does not validate decompressed file sizes when extracting ZIP archives (wheels, eggs), allowing attackers to cause denial of service through zip bombs. A malicious package can consume gigabytes of disk space from a few megabytes of compressed data. This vulnerability is fixed in 2.7.1.

    Published: 13 Jan 2026
    5.1
    Medium

    CVE-2025-15056

    Last Modified: 20 Apr 2026

    A lack of data validation vulnerability in the HTML export feature in Quill in allows Cross-Site Scripting (XSS). This issue affects Quill: 2.0.3.

    Published: 13 Jan 2026
    8.9
    High

    CVE-2026-22869

    Last Modified: 18 Apr 2026

    Eigent is a multi-agent Workforce. A critical security vulnerability in the CI workflow (.github/workflows/ci.yml) allows arbitrary code execution from fork pull requests with repository write permissions. The vulnerable workflow uses pull_request_target trigger combined with checkout of untrusted PR code. An attacker can exploit this to steal credentials, post comments, push code, or create releases.

    Published: 13 Jan 2026
    7.1
    High

    CVE-2026-22868

    Last Modified: 18 Apr 2026

    go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced to shutdown/crash using a specially crafted message. This vulnerability is fixed in 1.16.8.

    Published: 13 Jan 2026
    7.1
    High

    CVE-2026-22862

    Last Modified: 18 Apr 2026

    go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced to shutdown/crash using a specially crafted message. This vulnerability is fixed in 1.16.8.

    Published: 13 Jan 2026
    8.8
    High

    CVE-2026-22861

    Last Modified: 18 Apr 2026

    iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Prior to 2.3.1.2, There is a heap-based buffer overflow in SIccCalcOp::Describe() at IccProfLib/IccMpeCalc.cpp. This vulnerability affects users of the iccDEV library who process ICC color profiles. The vulnerability is fixed in 2.3.1.2.

    Published: 13 Jan 2026
    5.5
    Medium

    CVE-2026-21301

    Last Modified: 18 Apr 2026

    Substance3D - Modeler versions 1.22.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-21299

    Last Modified: 18 Apr 2026

    Substance3D - Modeler versions 1.22.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-21298

    Last Modified: 18 Apr 2026

    Substance3D - Modeler versions 1.22.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Jan 2026
    5.5
    Medium

    CVE-2026-21300

    Last Modified: 18 Apr 2026

    Substance3D - Modeler versions 1.22.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Jan 2026
    5.5
    Medium

    CVE-2026-21303

    Last Modified: 18 Apr 2026

    Substance3D - Modeler versions 1.22.4 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Jan 2026
    5.5
    Medium

    CVE-2026-21302

    Last Modified: 18 Apr 2026

    Substance3D - Modeler versions 1.22.4 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2025-37186

    Last Modified: 15 Apr 2026

    A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking Virtual Intranet Access (VIA) client. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges.

    Published: 13 Jan 2026
    5.3
    Medium

    CVE-2025-37179

    Last Modified: 23 Jan 2026

    Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data buffers. Due to insufficient validation of maximum buffer size values, the process may attempt to read beyond the intended memory region. Under specific conditions, this can result in a crash of the affected process and a potential denial-of-service of the compromised process.

    Published: 13 Jan 2026
    5.3
    Medium

    CVE-2025-37178

    Last Modified: 23 Jan 2026

    Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data buffers. Due to insufficient validation of maximum buffer size values, the process may attempt to read beyond the intended memory region. Under specific conditions, this can result in a crash of the affected process and a potential denial-of-service of the compromised process.

    Published: 13 Jan 2026
    6.5
    Medium

    CVE-2025-37177

    Last Modified: 23 Jan 2026

    An arbitrary file deletion vulnerability has been identified in the command-line interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation of this vulnerability could allow an authenticated remote malicious actor to delete arbitrary files within the affected system.

    Published: 13 Jan 2026
    6.5
    Medium

    CVE-2025-37176

    Last Modified: 26 Feb 2026

    A command injection vulnerability in AOS-8 allows an authenticated privileged user to alter a package header to inject shell commands, potentially affecting the execution of internal operations. Successful exploit could allow an authenticated malicious actor to execute commands with the privileges of the impacted mechanism.

    Published: 13 Jan 2026
    7.2
    High

    CVE-2025-37175

    Last Modified: 26 Feb 2026

    Arbitrary file upload vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to upload arbitrary files as a privilege user and execute arbitrary commands on the underlying operating system.

    Published: 13 Jan 2026
    5.5
    Medium

    CVE-2026-21308

    Last Modified: 18 Apr 2026

    Substance3D - Designer versions 15.0.3 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-21307

    Last Modified: 18 Apr 2026

    Substance3D - Designer versions 15.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Jan 2026
    7.2
    High

    CVE-2025-37174

    Last Modified: 26 Feb 2026

    Authenticated arbitrary file write vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to create or modify arbitrary files and execute arbitrary commands as a privileged user on the underlying operating system.

    Published: 13 Jan 2026
    7.2
    High

    CVE-2025-37173

    Last Modified: 26 Feb 2026

    An improper input handling vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor with valid credentials to trigger unintended behavior on the affected system.

    Published: 13 Jan 2026
    7.2
    High

    CVE-2025-37172

    Last Modified: 26 Feb 2026

    Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.

    Published: 13 Jan 2026
    7.2
    High

    CVE-2025-37171

    Last Modified: 26 Feb 2026

    Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.

    Published: 13 Jan 2026
    7.2
    High

    CVE-2025-37170

    Last Modified: 26 Feb 2026

    Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.

    Published: 13 Jan 2026
    7.2
    High

    CVE-2025-37169

    Last Modified: 26 Feb 2026

    A stack overflow vulnerability exists in the AOS-10 web-based management interface of a Mobility Gateway. Successful exploitation could allow an authenticated malicious actor to execute arbitrary code as a privileged user on the underlying operating system.

    Published: 13 Jan 2026