CVE-2024-30225 | CRITICAL | 10.0 | 0.00683 | 40.24 | No | No | 2024-03-28 | 2026-04-28 | euvd | Deserialization of Untrusted Data vulnerability in WPENGINE, INC. WP Migrate.This issue affects WP Migrate: from n/a through 2.6.10.Deserialization of Untrusted Data vulnerability in WPENGINE, INC. WP Migrate.This issue affects WP Migrate: from n/a through 2.6.10. |
CVE-2026-40342 | CRITICAL | 10.0 | 0.00692 | 40.24 | No | No | 2026-04-17 | 2026-04-22 | euvd | Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin l…Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-supplied engine name into a filesystem path without filtering path separators or .. components. An authenticated user with CREATE FUNCTION privileges can use a crafted ENGINE name to load an arbitrary shared library from anywhere on the filesystem via path traversal. The library's initialization code executes immediately during loading, before Firebird validates the module, achieving code execution as the server's OS account. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14. |
CVE-2026-57624 | CRITICAL | 10.0 | 0.00677 | 40.24 | No | No | 2026-07-02 | 2026-07-02 | euvd | Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions. |
CVE-2025-34070 | CRITICAL | 10.0 | 0.00691 | 40.24 | No | No | 2025-07-02 | 2026-02-26 | euvd | A missing authentication vulnerability in the GFIAgent component of GFI Kerio Control 9.4.5 allows unauthenticated remote attackers to perfo…A missing authentication vulnerability in the GFIAgent component of GFI Kerio Control 9.4.5 allows unauthenticated remote attackers to perform privileged operations. The GFIAgent service, responsible for integration with GFI AppManager, exposes HTTP services on ports 7995 and 7996 without proper authentication. The /proxy handler on port 7996 allows arbitrary forwarding to administrative endpoints when provided with an Appliance UUID, which itself can be retrieved from port 7995. This results in a complete authentication bypass, permitting access to sensitive administrative APIs. |
CVE-2024-23653 | CRITICAL | 9.8 | 0.02983 | 40.24 | No | No | 2024-01-31 | 2024-08-23 | euvd | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In addition to runnin…BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In addition to running containers as build steps, BuildKit also provides APIs for running interactive containers based on built images. It was possible to use these APIs to ask BuildKit to run a container with elevated privileges. Normally, running such containers is only allowed if special `security.insecure` entitlement is enabled both by buildkitd configuration and allowed by the user initializing the build request. The issue has been fixed in v0.12.5 . Avoid using BuildKit frontends from untrusted sources. |
CVE-2026-48330 | CRITICAL | 10.0 | 0.00679 | 40.24 | No | No | 2026-08-03 | 2026-08-05 | euvd, nvd | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerab…Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary SQL commands, potentially gaining elevated access or control over the application. Exploitation of this issue does not require user interaction. Scope is changed. |
CVE-2021-23377 | CRITICAL | 9.8 | 0.02972 | 40.24 | No | No | 2021-04-18 | 2024-09-17 | euvd | This affects all versions of package onion-oled-js. If attacker-controlled user input is given to the scroll function, it is possible for an…This affects all versions of package onion-oled-js. If attacker-controlled user input is given to the scroll function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization. |
CVE-2019-9884 | CRITICAL | 9.8 | 0.0296 | 40.24 | No | No | 2019-07-25 | 2024-09-17 | euvd | eClass platform < ip.2.5.10.2.1 allows an attacker to use GETS method to request /admin page to bypass the password validation and access ma…eClass platform < ip.2.5.10.2.1 allows an attacker to use GETS method to request /admin page to bypass the password validation and access management page. |
CVE-2023-25054 | CRITICAL | 10.0 | 0.00681 | 40.24 | No | No | 2023-12-29 | 2026-04-28 | euvd | Improper Control of Generation of Code ('Code Injection') vulnerability in David F. Carr RSVPMaker.This issue affects RSVPMaker: from n/a th…Improper Control of Generation of Code ('Code Injection') vulnerability in David F. Carr RSVPMaker.This issue affects RSVPMaker: from n/a through 10.6.6. |
CVE-2023-25960 | CRITICAL | 10.0 | 0.0069 | 40.24 | No | No | 2023-11-03 | 2026-04-28 | euvd | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zendrop Zendrop – Global Dropshipping …Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zendrop Zendrop – Global Dropshipping zendrop-dropshipping-and-fulfillment allows SQL Injection.This issue affects Zendrop – Global Dropshipping: from n/a through 1.0.0. |
CVE-2025-58384 | CRITICAL | 10.0 | 0.00678 | 40.24 | No | No | 2025-09-26 | 2025-09-26 | euvd | In DOXENSE WATCHDOC before 6.1.1.5332, Deserialization of Untrusted Data can lead to remote code execution through the .NET Remoting library…In DOXENSE WATCHDOC before 6.1.1.5332, Deserialization of Untrusted Data can lead to remote code execution through the .NET Remoting library in the Watchdoc administration interface. |
CVE-2018-3865 | CRITICAL | 9.9 | 0.01827 | 40.24 | No | No | 2018-09-20 | 2024-09-17 | euvd | An exploitable buffer overflow vulnerability exists in the Samsung WifiScan handler of video-core's HTTP server of Samsung SmartThings Hub S…An exploitable buffer overflow vulnerability exists in the Samsung WifiScan handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The strcpy overflows the destination buffer, which has a size of 40 bytes. An attacker can send an arbitrarily long "cameraIp" value in order to exploit this vulnerability. |
CVE-2025-34394 | CRITICAL | 10.0 | 0.00691 | 40.24 | No | No | 2025-12-10 | 2026-05-14 | euvd | Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting service that is insuffi…Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting service that is insufficiently protected against deserialization of arbitrary types. This can lead to remote code execution. |
CVE-2014-125123 | CRITICAL | 10.0 | 0.00696 | 40.24 | No | No | 2025-07-31 | 2026-05-15 | euvd | An unauthenticated SQL injection vulnerability exists in the Kloxo web hosting control panel (developed by LXCenter) prior to version 6.1.12…An unauthenticated SQL injection vulnerability exists in the Kloxo web hosting control panel (developed by LXCenter) prior to version 6.1.12. The flaw resides in the login-name parameter passed to lbin/webcommand.php, which fails to properly sanitize input, allowing an attacker to extract the administrator’s password from the backend database. After recovering valid credentials, the attacker can authenticate to the Kloxo control panel and leverage the Command Center feature (display.php) to execute arbitrary operating system commands as root on the underlying host system. This vulnerability was reported to be exploited in the wild in January 2014. |
CVE-2025-56819 | CRITICAL | 9.8 | 0.02983 | 40.24 | No | No | 2025-09-24 | 2025-09-24 | euvd | An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter.An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter. |
CVE-2024-27767 | CRITICAL | 10.0 | 0.0069 | 40.24 | No | No | 2024-03-18 | 2024-08-02 | euvd | CWE-287: Improper Authentication may allow Authentication BypassCWE-287: Improper Authentication may allow Authentication Bypass |
CVE-2024-2013 | CRITICAL | 10.0 | 0.0068 | 40.24 | No | No | 2024-06-11 | 2024-08-01 | euvd | An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server /
API Gateway component that if exploited allows attackers withou…An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server /
API Gateway component that if exploited allows attackers without
any access to interact with the services and the post-authentication
attack surface. |
CVE-2023-22814 | CRITICAL | 10.0 | 0.00687 | 40.24 | No | No | 2023-06-30 | 2024-11-26 | euvd | An authentication bypass issue via spoofing was discovered in the token-based authentication mechanism that could allow an attacker to carry…An authentication bypass issue via spoofing was discovered in the token-based authentication mechanism that could allow an attacker to carry out an impersonation attack.
This issue affects My Cloud OS 5 devices: before 5.26.202. |
CVE-2025-34217 | CRITICAL | 10.0 | 0.00697 | 40.24 | No | No | 2025-09-30 | 2025-11-17 | euvd | Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) contain an undocumented 'printerlogic' use…Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) contain an undocumented 'printerlogic' user with a hardcoded SSH public key in '~/.ssh/authorized_keys' and a sudoers rule granting the printerlogic_ssh group 'NOPASSWD: ALL'. Possession of the matching private key gives an attacker root access to the appliance. |
CVE-2025-66203 | CRITICAL | 10.0 | 0.00698 | 40.24 | No | No | 2025-12-26 | 2025-12-29 | euvd | StreamVault is a video download integration solution. Prior to version 251126, a Remote Code Execution (RCE) vulnerability exists in the str…StreamVault is a video download integration solution. Prior to version 251126, a Remote Code Execution (RCE) vulnerability exists in the stream-vault application (SpiritApplication). The application allows administrators to configure yt-dlp arguments via the /admin/api/saveConfig endpoint without sufficient validation. These arguments are stored globally and subsequently used in YtDlpUtil.java when constructing the command line to execute yt-dlp. This issue has been patched in version 251126. |
CVE-2026-25632 | CRITICAL | 10.0 | 0.00695 | 40.24 | No | Yes | 2026-02-06 | 2026-02-06 | euvd, packetstorm | EPyT-Flow is a Python package designed for the easy generation of hydraulic and water quality scenario data of water distribution networks. …EPyT-Flow is a Python package designed for the easy generation of hydraulic and water quality scenario data of water distribution networks. Prior to 0.16.1, EPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is present, the deserializer dynamically imports an attacker-specified module/class and instantiates it with attacker-supplied arguments. This allows invoking dangerous classes such as subprocess.Popen, which can lead to OS command execution during JSON parsing. This also affects the loading of JSON files. This vulnerability is fixed in 0.16.1. |
CVE-2024-25096 | CRITICAL | 10.0 | 0.00681 | 40.24 | No | No | 2024-04-03 | 2026-04-28 | euvd | Improper Control of Generation of Code ('Code Injection') vulnerability in Canto Inc. Canto allows Code Injection.This issue affects Canto: …Improper Control of Generation of Code ('Code Injection') vulnerability in Canto Inc. Canto allows Code Injection.This issue affects Canto: from n/a through 3.0.7. |
CVE-2025-30411 | CRITICAL | 10.0 | 0.00691 | 40.24 | No | No | 2026-02-20 | 2026-02-26 | euvd | Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Li…Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800. |
CVE-2026-25893 | CRITICAL | 10.0 | 0.00678 | 40.24 | No | No | 2026-02-09 | 2026-02-11 | euvd | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vulnerability in FUXA al…FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to gain administrative access via the heartbeat refresh API and execute arbitrary code on the server. This issue has been patched in FUXA version 1.2.10. |
CVE-2026-37541 | CRITICAL | 10.0 | 0.00678 | 40.24 | No | No | 2026-05-01 | 2026-05-07 | euvd | Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_gvret.cpp, the length field in GVRET binary …Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_gvret.cpp, the length field in GVRET binary data is not properly validated, allowing remote attackers to cause a denial of service or possibly execute arbitrary code via crafted GVRET frames. |
CVE-2024-44148 | CRITICAL | 10.0 | 0.00678 | 40.24 | No | No | 2024-09-16 | 2026-04-02 | euvd | This issue was addressed with improved validation of file attributes. This issue is fixed in macOS Sequoia 15. An app may be able to break o…This issue was addressed with improved validation of file attributes. This issue is fixed in macOS Sequoia 15. An app may be able to break out of its sandbox. |
CVE-2024-9643 | CRITICAL | 9.8 | 0.0298 | 40.24 | No | No | 2025-02-04 | 2025-11-22 | euvd | The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials in the administrative…The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials in the administrative web server. An attacker with knowledge of the credentials can gain administrative access via crafted HTTP requests. This issue appears similar to CVE-2023-32645. |
CVE-2024-38513 | CRITICAL | 10.0 | 0.00686 | 40.24 | No | No | 2024-07-01 | 2024-08-02 | euvd | Fiber is an Express-inspired web framework written in Go A vulnerability present in versions prior to 2.52.5 is a session middleware issue i…Fiber is an Express-inspired web framework written in Go A vulnerability present in versions prior to 2.52.5 is a session middleware issue in GoFiber versions 2 and above. This vulnerability allows users to supply their own session_id value, resulting in the creation of a session with that key. If a website relies on the mere presence of a session for security purposes, this can lead to significant security risks, including unauthorized access and session fixation attacks. All users utilizing GoFiber's session middleware in the affected versions are impacted. The issue has been addressed in version 2.52.5. Users are strongly encouraged to upgrade to version 2.52.5 or higher to mitigate this vulnerability. Users who are unable to upgrade immediately can apply the following workarounds to reduce the risk: Either implement additional validation to ensure session IDs are not supplied by the user and are securely generated by the server, or regularly rotate session IDs and enforce strict session expiration policies. |
CVE-2025-34060 | CRITICAL | 10.0 | 0.00689 | 40.24 | No | No | 2025-07-01 | 2025-07-01 | euvd | A PHP objection injection vulnerability exists in the Monero Project’s Laravel-based forum software due to unsafe handling of untrusted inpu…A PHP objection injection vulnerability exists in the Monero Project’s Laravel-based forum software due to unsafe handling of untrusted input in the /get/image/ endpoint. The application passes a user-supplied link parameter directly to file_get_contents() without validation. MIME type checks using PHP’s finfo can be bypassed via crafted stream filter chains that prepend spoofed headers, allowing access to internal Laravel configuration files. An attacker can extract the APP_KEY from config/app.php, forge encrypted cookies, and trigger unsafe unserialize() calls, leading to reliable remote code execution. |
CVE-2026-58275 | CRITICAL | 10.0 | 0.00684 | 40.24 | No | No | 2026-07-24 | 2026-08-14 | euvd, nvd | Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. |
CVE-2025-42890 | CRITICAL | 10.0 | 0.00686 | 40.24 | No | No | 2025-11-11 | 2026-02-26 | euvd | SQL Anywhere Monitor (Non-GUI) baked credentials into the code,exposing the resources or functionality to unintended users and providing att…SQL Anywhere Monitor (Non-GUI) baked credentials into the code,exposing the resources or functionality to unintended users and providing attackers with the possibility of arbitrary code execution.This could cause high impact on confidentiality integrity and availability of the system. |
CVE-2025-34393 | CRITICAL | 10.0 | 0.00691 | 40.24 | No | No | 2025-12-10 | 2026-05-14 | euvd | Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not correctly verify the name of an attack…Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not correctly verify the name of an attacker-controlled WSDL service, leading to insecure reflection. This can result in remote code execution through either invocation of arbitrary methods or deserialization of untrusted types. |
CVE-2021-27076 | HIGH | 8.8 | 0.14387 | 40.24 | No | No | 2021-03-11 | 2024-11-19 | euvd | Microsoft SharePoint Server Remote Code Execution VulnerabilityMicrosoft SharePoint Server Remote Code Execution Vulnerability |
CVE-2024-48966 | CRITICAL | 10.0 | 0.00676 | 40.24 | No | No | 2024-11-14 | 2024-11-15 | euvd | The software tools used by service personnel to test & calibrate the ventilator do not support user authentication. An attacker with access …The software tools used by service personnel to test & calibrate the ventilator do not support user authentication. An attacker with access to the Service PC where the tools are installed could obtain diagnostic information through the test tool or manipulate the ventilator's settings and embedded software via the calibration tool, without having to authenticate to either tool. This could result in unauthorized disclosure of information and/or have unintended impacts on device settings and performance. |
CVE-2026-3587 | CRITICAL | 10.0 | 0.00679 | 40.24 | No | No | 2026-03-23 | 2026-03-24 | euvd | An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface, leading to full compr…An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface, leading to full compromise of the device. |
CVE-2025-34256 | CRITICAL | 10.0 | 0.00681 | 40.24 | No | No | 2025-12-05 | 2026-08-14 | euvd | Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product uses a static HS512 H…Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product uses a static HS512 HMAC secret for signing EIRMMToken JWTs across all installations. The server accepts forged JWTs that need only contain a valid email claim, allowing a remote unauthenticated attacker to generate arbitrary tokens and impersonate any DeviceOn account, including the root super admin. Successful exploitation permits full administrative control of the DeviceOn instance and can be leveraged to execute code on managed agents through DeviceOn’s remote management features. |
CVE-2023-52218 | CRITICAL | 10.0 | 0.00645 | 40.23 | No | No | 2024-01-08 | 2026-04-28 | euvd | Deserialization of Untrusted Data vulnerability in Anton Bond Woocommerce Tranzila Payment Gateway.This issue affects Woocommerce Tranzila P…Deserialization of Untrusted Data vulnerability in Anton Bond Woocommerce Tranzila Payment Gateway.This issue affects Woocommerce Tranzila Payment Gateway: from n/a through 1.0.8. |
CVE-2023-52181 | CRITICAL | 10.0 | 0.00646 | 40.23 | No | No | 2023-12-31 | 2026-04-28 | euvd | Deserialization of Untrusted Data vulnerability in Presslabs Theme per user.This issue affects Theme per user: from n/a through 1.0.1.Deserialization of Untrusted Data vulnerability in Presslabs Theme per user.This issue affects Theme per user: from n/a through 1.0.1. |
CVE-2023-51438 | CRITICAL | 10.0 | 0.00646 | 40.23 | No | No | 2024-01-09 | 2025-05-22 | euvd | A vulnerability has been identified in SIMATIC IPC1047E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC…A vulnerability has been identified in SIMATIC IPC1047E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC647E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC847E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows). In default installations of maxView Storage Manager where Redfish® server is configured for remote system management, a vulnerability has been identified that can provide unauthorized access. |
CVE-2010-0820 | HIGH | 8.8 | 0.14361 | 40.23 | No | No | 2010-09-15 | 2024-10-17 | euvd | Heap-based buffer overflow in the Local Security Authority Subsystem Service (LSASS), as used in Active Directory in Microsoft Windows Serve…Heap-based buffer overflow in the Local Security Authority Subsystem Service (LSASS), as used in Active Directory in Microsoft Windows Server 2003 SP2 and Windows Server 2008 Gold, SP2, and R2; Active Directory Application Mode (ADAM) in Windows XP SP2 and SP3 and Windows Server 2003 SP2; and Active Directory Lightweight Directory Service (AD LDS) in Windows Vista SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, allows remote authenticated users to execute arbitrary code via malformed LDAP messages, aka "LSASS Heap Overflow Vulnerability." |
CVE-2025-49013 | CRITICAL | 10.0 | 0.00662 | 40.23 | No | No | 2025-06-09 | 2025-06-09 | euvd | WilderForge is a Wildermyth coremodding API. A critical vulnerability has been identified in multiple projects across the WilderForge organi…WilderForge is a Wildermyth coremodding API. A critical vulnerability has been identified in multiple projects across the WilderForge organization. The issue arises from unsafe usage of `${{ github.event.review.body }}` and other user controlled variables directly inside shell script contexts in GitHub Actions workflows. This introduces a code injection vulnerability: a malicious actor submitting a crafted pull request review containing shell metacharacters or commands could execute arbitrary shell code on the GitHub Actions runner. This can lead to arbitrary command execution with the permissions of the workflow, potentially compromising CI infrastructure, secrets, and build outputs. Developers who maintain or contribute to the repos WilderForge/WilderForge, WilderForge/ExampleMod, WilderForge/WilderWorkspace, WilderForge/WildermythGameProvider, WilderForge/AutoSplitter, WilderForge/SpASM, WilderForge/thrixlvault, WilderForge/MassHash, and/or WilderForge/DLC_Disabler; as well as users who fork any of the above repositories and reuse affected GitHub Actions workflows, are affected. End users of any the above software and users who only install pre-built releases or artifacts are not affected. This vulnerability does not impact runtime behavior of the software or compiled outputs unless those outputs were produced during exploitation of this vulnerability. A current workaround is to disable GitHub Actions in affected repositories, or remove the affected workflows. |
CVE-2024-54214 | CRITICAL | 10.0 | 0.00671 | 40.23 | No | No | 2024-12-06 | 2026-04-28 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in roninwp Revy revy allows Upload a Web Shell to a Web Server.This issue affe…Unrestricted Upload of File with Dangerous Type vulnerability in roninwp Revy revy allows Upload a Web Shell to a Web Server.This issue affects Revy: from n/a through <= 1.18. |
CVE-2026-10580 | CRITICAL | 9.8 | 0.02948 | 40.23 | No | No | 2026-06-05 | 2026-06-06 | euvd | The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover …The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to and including 1.9.4. This is due to a logic conflation in HippooPermissions::get_user_permissions(), which returns the same null sentinel for both administrators and unauthenticated visitors — a value that HippooPermissions::has_role_access() unconditionally interprets as full administrator access — causing override_extension_permission_callback() to assign __return_true as the permission callback for every WordPress and WooCommerce REST route cloned under /wc-hippoo/v1/ext/ by HippooControllerWithAuth::re_register_external_routes(), while the block_unauthorized_access() pre-dispatch guard fails to block unauthenticated users for the same reason. This makes it possible for unauthenticated attackers to invoke any core REST endpoint without credentials — most critically, sending a POST request to /wc-hippoo/v1/ext/wp/v2/users/<id> with a {"password":"<new_password>"} body to reset the password of any WordPress user, including the site administrator, and gain full administrative control of the site. |
CVE-2026-2577 | CRITICAL | 10.0 | 0.00645 | 40.23 | No | No | 2026-02-16 | 2026-02-17 | euvd | The WhatsApp bridge component in Nanobot binds the WebSocket server to all network interfaces (0.0.0.0) on port 3001 by default and does not…The WhatsApp bridge component in Nanobot binds the WebSocket server to all network interfaces (0.0.0.0) on port 3001 by default and does not require authentication for incoming connections. An unauthenticated remote attacker with network access to the bridge can connect to the WebSocket server to hijack the WhatsApp session. This allows the attacker to send messages on behalf of the user, intercept all incoming messages and media in real-time, and capture authentication QR codes. |
CVE-2024-3820 | CRITICAL | 10.0 | 0.00657 | 40.23 | No | No | 2024-06-01 | 2026-04-08 | euvd | The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to SQL Injection via the 'i…The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to SQL Injection via the 'id_key' parameter of the wdt_delete_table_row AJAX action in all versions up to, and including, 6.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Please note this only affects the premium version of the plugin. |
CVE-2018-3903 | CRITICAL | 9.9 | 0.01804 | 40.23 | No | No | 2018-08-23 | 2024-09-17 | euvd | On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process incorrectly extracts fields from a user…On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process incorrectly extracts fields from a user-controlled JSON payload, leading to a buffer overflow on the stack. An attacker can send an HTTP request to trigger this vulnerability. The memcpy call overflows the destination buffer, which has a size of 512 bytes. An attacker can send an arbitrarily long "url" value in order to overwrite the saved-PC with 0x42424242. |
CVE-2018-3894 | CRITICAL | 9.9 | 0.01804 | 40.23 | No | No | 2018-09-21 | 2024-09-17 | euvd | An exploitable buffer overflow vulnerability exists in the /cameras/XXXX/clips handler of video-core's HTTP server of Samsung SmartThings Hu…An exploitable buffer overflow vulnerability exists in the /cameras/XXXX/clips handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The strncpy call overflows the destination buffer, which has a size of 52 bytes. An attacker can send an arbitrarily long "startTime" value in order to exploit this vulnerability. |
CVE-2025-48200 | CRITICAL | 10.0 | 0.00664 | 40.23 | No | No | 2025-05-21 | 2025-05-22 | euvd | The sr_feuser_register extension through 12.4.8 for TYPO3 allows Remote Code Execution.The sr_feuser_register extension through 12.4.8 for TYPO3 allows Remote Code Execution. |
CVE-2025-9118 | CRITICAL | 10.0 | 0.00648 | 40.23 | No | No | 2025-08-25 | 2025-08-25 | euvd | A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker to read and write f…A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker to read and write files in other customers' repositories via a maliciously crafted package.json file. |
CVE-2026-56191 | CRITICAL | 10.0 | 0.00667 | 40.23 | No | No | 2026-07-24 | 2026-08-14 | euvd, nvd | Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. |