CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| Exploit 22d ago | 9.3 | CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter is passed unvalidated into the git show argv without an --end-of-options sentinel, so a value beginning with --output= is interpreted as a git flag. Because the tool is registered as auto-approved and advertised as read-only, an attacker (via a malicious repository combined with prompt injection) can cause an unprompted arbitrary file write at the privilege of the invoking user, targeting sensitive files such as ~/.ssh/authorized_keys, ~/.bashrc, or ~/.gitconfig. Fixed in 0.8.64 by adding rev validation. |
| Exploit 22d ago | 9.8 | Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution. |
| Exploit 22d ago | 9.3 | MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a redirect URL or protocol correctly, resulting in an open redirect and reflected JavaScript code injection. contact.php accepts the redirect target from the from HTTP parameter in $mybb->input['from'] or the Referer HTTP header in $_SERVER['HTTP_REFERER'] and passes it to redirect() without sufficient verification. A javascript: URI becomes the target of the `Click here if you don't want to wait any longer` link because $force_redirect is true, allowing script execution when a victim selects the link. This issue is fixed in version 1.8.40. |
| Exploit 22d ago | 9.8 | MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not properly escape user-supplied database configuration values written to the configuration file, resulting in PHP code injection and remote code execution when the installer is available. install/index.php processes the values with addcslashes(), but the $characters argument added in MyBB 1.8.13 does not include the backslash character, allowing crafted input to escape the generated PHP string. The uniquely identifying implementation details include introduced in MyBB 1.8.13. This issue is fixed in version 1.8.40. |
| 22d ago | 9.6 | A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL when a HashiCorp Vault Secret Lookup credential with kubernetes_role authentication is tested. An authenticated attacker with credential-creation privileges can exfiltrate the service account token, gaining Kubernetes API access to the control plane namespaces with full pod CRUD and secret read permissions, including database credentials and the Django SECRET_KEY. |
| Exploit 22d ago | 10 | A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the argument Server results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be used. |
| 22d ago | 9.3 | Unauthenticated SQL Injection in Readabler < 2.0.18 versions. |
| 22d ago | 9.8 | Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions. |
| 22d ago | 9.8 | Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions. |
| 22d ago | 9.1 | Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions. |
| 22d ago | 9.8 | Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions. |
| 22d ago | 9.8 | Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions. |
| 22d ago | 9.8 | Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions. |
| 22d ago | 9.3 | Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions. |
| 22d ago | 9.3 | Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions. |
| Exploit 22d ago | 10 | Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions. |
| 22d ago | 9.8 | Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions. |
| 22d ago | 9.3 | Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions. |
| 22d ago | 9.3 | Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions. |
| 22d ago | 9.9 | Unrestricted Upload of File with Dangerous Type vulnerability in EDGE22 Studios Ltd. GP Premium allows Remote Code Inclusion. This issue affects GP Premium: from n/a through 2.5.5. |
| Exploit 22d ago | 9.8 | Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without verifying genuine internal Promise resolver records, causing deserialization side effects with plugins enabled and potentially unintended server-side invocation or remote code execution when downstream frameworks register callable wrappers. This issue is fixed in version 1.5.3. |
| 22d ago | 9.9 | Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions. |
| 22d ago | 9.8 | Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. |
| 22d ago | 9.9 | Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions. |
| Exploit 22d ago | 9.9 | Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions. |
| 22d ago | 9.6 | Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions. |
| 22d ago | 10 | Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 140.15, and Thunderbird 153.2. |
| Exploit 22d ago | 9.6 | A security vulnerability has been detected in TRENDnet TEW-WLC100P 12.07b01. Affected by this vulnerability is an unknown functionality of the file /sbin/netifd of the component DHCP blobmsg Handler. The manipulation leads to stack-based buffer overflow. The attack must be carried out from within the local network. The exploit has been disclosed publicly and may be used. |
| Exploit 22d ago | 9.8 | Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. |
| Exploit 22d ago | 9.8 | Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154 and Thunderbird 154. |