Critical · CVSS 9.8
Server-Side Template Injection (SSTI) was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code via the shippingAsBilling and firstname parameters in updateuserinfo.html file
Published Jan 7, 2025 · Updated Jul 7, 2026
Medium · CVSS 6.1
Open Redirect vulnerability in Pnetlab 5.3.11 allows an attacker to manipulate URLs to redirect users to arbitrary external websites via a crafted script
Published Jan 6, 2025 · Updated Jul 7, 2026
Medium · CVSS 4.1
Cross-Site Scripting (XSS) vulnerability in Pnetlab 5.3.11 allows an attacker to inject malicious scripts into a web page, which are executed in the context of the victim's browser.
Published Jan 6, 2025 · Updated Jul 7, 2026
High · CVSS 7.7
Path Traversal: '.../...//' vulnerability in reputeinfosystems ARForms allows Path Traversal.
This issue affects ARForms: from n/a before 7.0.2.
Published Dec 6, 2024 · Updated Jul 7, 2026
High · CVSS 7.5
This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. With large carefully-crafted input, this can result in catastrophic backtracking and cause a denial of service.
**Note:**
This package is EOL and will not receive any updates to address this issue. Users should migrate to [@angular/core](https://www.npmjs.com/package/@angular/core).
Published Feb 10, 2024 · Updated Jul 6, 2026
Medium · CVSS 4.8
The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user shares a username with a local user. This allows the provisioning process to overwrite existing roles of local users with roles assigned to the federated user.
Exploitation requires a federated identity provider (IDP) with silent JIT provisioning enabled and an attacker's knowledge of a local user's username. When these conditions are met, a malicious individual can leverage the JIT provisioning process to modify the roles of local users. The overwritten roles are limited to those defined within the federated IDP, typically granting minimal access rights unless explicitly configured otherwise by the federated IDP administrator.
Published Jul 4, 2026 · Updated Jul 6, 2026
High · CVSS 7.5
The Notifications for Forms & WordPress Actions WordPress plugin before 2.6 does not validate a user-supplied value before using it to build a server-side file inclusion path, allowing authenticated users with subscriber-level access and above to include and execute arbitrary local PHP files on the server.
Published Jul 6, 2026 · Updated Jul 6, 2026
High · CVSS 7.5
Pentaminds CuroVMS v2.0.1 was discovered to contain exposed sensitive information.
Published Dec 9, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.1
Pentaminds CuroVMS v2.0.1 was discovered to contain exposed credentials.
Published Dec 9, 2024 · Updated Jul 5, 2026
Medium · CVSS 6.4
fabricators Ltd Vanilla OS 2 Core image v1.1.0 was discovered to contain static keys for the SSH service, allowing attackers to possibly execute a man-in-the-middle attack during connections with other hosts.
Published Jan 13, 2026 · Updated Jul 5, 2026
High · CVSS 7.1
An issue in ETSI Open-Source MANO (OSM) 14.0.x before 14.0.3, 15.0.x before 15.0.2, 16.0.0, and 17.0.0 allows a remote authenticated attacker to escalate privileges via the /osm/admin/v1/users component.
Published Jul 25, 2025 · Updated Jul 5, 2026
Medium · CVSS 5.4
A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the image parameter under the Create/Modify article function.
Published Apr 21, 2025 · Updated Jul 5, 2026
High · CVSS 7.5
Bangkok Medical Software HOSxP XE v4.64.11.3 was discovered to contain a hardcoded IDEA Key-IV pair in the HOSxPXE4.exe and HOS-WIN32.INI components. This allows attackers to access sensitive information.
Published Jan 7, 2025 · Updated Jul 5, 2026
Medium · CVSS 4.7
Cross Site Scripting vulnerability in Audiocodes MP-202b v.4.4.3 allows a remote attacker to escalate privileges via the login page of the web interface.
Published Jan 2, 2025 · Updated Jul 5, 2026
Medium · CVSS 6.1
The mediapool feature of the Redaxo Core CMS application v 5.17.1 is vulnerable to Cross Site Scripting(XSS) which allows a remote attacker to escalate privileges
Published Nov 19, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.8
An Incorrect Access Control issue in SAMPMAX com.sampmax.homemax 2.1.2.7 allows a remote attacker to obtain sensitive information via the firmware update process.
Published Oct 11, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.1
An issue in GIANT MANUFACTURING CO., LTD RideLink (tw.giant.ridelink) 2.0.7 allows a remote attacker to obtain sensitive information via the firmware update process.
Published Oct 11, 2024 · Updated Jul 5, 2026
High · CVSS 7.5
LEDVANCE com.ledvance.smartplus.eu 2.1.10 allows a remote attacker to obtain sensitive information via the firmware update process.
Published Oct 11, 2024 · Updated Jul 5, 2026
High · CVSS 7.5
An issue in Shelly com.home.shelly 1.0.4 allows a remote attacker to obtain sensitive information via the firmware update process
Published Oct 11, 2024 · Updated Jul 5, 2026
High · CVSS 7.5
An issue in Plug n Play Camera com.ezset.delaney 1.2.0 allows a remote attacker to obtain sensitive information via the firmware update process.
Published Oct 11, 2024 · Updated Jul 5, 2026
High · CVSS 7.5
An issue in Fermax Asia Pacific Pte Ltd com.fermax.vida 2.4.6 allows a remote attacker to obtain sensitve information via the firmware update process.
Published Oct 11, 2024 · Updated Jul 5, 2026
High · CVSS 8.2
An issue in Plug n Play Camera com.wisdomcity.zwave 1.1.0 allows a remote attacker to obtain sensitive information via the firmware update process.
Published Oct 11, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.1
An issue in BURG-WCHTER KG de.burgwachter.keyapp.app 4.5.0 allows a remote attacker to obtain sensitve information via the firmware update process.
Published Oct 11, 2024 · Updated Jul 5, 2026
Medium · CVSS 5.3
A directory listing issue in the baserCMS plugin in D-ZERO CO., LTD. BurgerEditor and BurgerEditor Limited Edition before 2.25.1 allows remote attackers to obtain sensitive information by exposing a list of the uploaded files.
Published Oct 11, 2024 · Updated Jul 5, 2026
Medium · CVSS 6.1
A reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation v6.18.17 allows attackers to execute arbitrary JavaScript code in the web browser of a user via injecting a crafted payload into the dialog parameter at wrapper_dialog.php.
Published Oct 7, 2024 · Updated Jul 5, 2026
High · CVSS 8.8
SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application takes arbitrary value from "X-Forwarded-For" header and appends it to a SQL INSERT statement directly, leading to SQL Injection.
Published Oct 15, 2024 · Updated Jul 5, 2026
High · CVSS 7.5
An issue in the getcolor function in utils.py of xhtml2pdf v0.2.13 allows attackers to cause a Regular expression Denial of Service (ReDOS) via supplying a crafted string.
Published Oct 8, 2024 · Updated Jul 5, 2026
Medium · CVSS 5.3
User enumeration vulnerability in ORDAT FOSS-Online before v2.24.01 allows attackers to determine if an account exists in the application by comparing the server responses of the forgot password functionality.
Published Sep 12, 2024 · Updated Jul 5, 2026
Medium · CVSS 6.1
ORDAT FOSS-Online before version 2.24.01 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login page.
Published Sep 12, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.3
ORDAT FOSS-Online before v2.24.01 was discovered to contain a SQL injection vulnerability via the forgot password function.
Published Sep 12, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.1
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Sniffing Network Traffic attack due to the cleartext transmission of sensitive information.
Published Aug 2, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.6
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform SQL Injection due to improper neutralization of special elements used in an SQL command.
Published Aug 2, 2024 · Updated Jul 5, 2026
Medium · CVSS 6.8
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a local attacker to perform a Password Brute Forcing attack due to improper restriction of excessive authentication attempts.
Published Aug 2, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.8
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to expand control over the operating system from the database due to the execution of commands with unnecessary privileges.
Published Aug 2, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.8
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Traffic Injection attack due to improper verification of the source of a communication channel.
Published Aug 2, 2024 · Updated Jul 5, 2026
High · CVSS 7.5
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform unauthorized access using known operating system credentials due to hardcoded SQL user credentials in the client application.
Published Aug 2, 2024 · Updated Jul 5, 2026
High · CVSS 7.8
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a local attacker to perform an Authentication Bypass attack due to improperly implemented security checks for standard authentication mechanisms
Published Aug 2, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.1
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Drop Encryption Level attack due to the selection of a less-secure algorithm during negotiation.
Published Aug 2, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.8
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform command line execution through SQL Injection due to improper neutralization of special elements used in an OS command.
Published Aug 2, 2024 · Updated Jul 5, 2026
High · CVSS 7.5
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Rainbow Table Password cracking attack due to the use of one-way hashes without salts when storing user passwords.
Published Aug 2, 2024 · Updated Jul 5, 2026
Medium · CVSS 6.5
A stored cross-site scripting (XSS) vulnerability in Umbraco CMS v14.3.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. NOTE: This has been disputed by the vendor since this potential attack is only possible via authenticated users who have been manually allowed access to the CMS. There was a deliberate decision made not to apply HTML sanitization at the product level.
Published Jan 22, 2025 · Updated Jul 5, 2026
High · CVSS 7.7
Directory Traversal in /SASStudio/sasexec/sessions/{sessionID}/workspace/{InternalPath} in SAS Studio 9.4 allows remote attacker to access internal files by manipulating default path during file download. NOTE: this is disputed by the vendor because these filesystem paths are allowed for authorized users.
Published Oct 30, 2024 · Updated Jul 5, 2026
High · CVSS 8.8
Unrestricted file upload in /SASStudio/SASStudio/sasexec/{sessionID}/{InternalPath} in SAS Studio 9.4 allows remote attacker to upload malicious files. NOTE: this is disputed by the vendor because file upload is allowed for authorized users.
Published Oct 30, 2024 · Updated Jul 5, 2026
High · CVSS 8.8
SQL injection vulnerability in /SASStudio/sasexec/sessions/{sessionID}/sql in SAS Studio 9.4 allows remote attacker to execute arbitrary SQL commands via the POST body request. NOTE: this is disputed by the vendor because SQL statement execution is allowed for authorized users.
Published Oct 30, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.8
Ezviz Internet PT Camera CS-CV246 D15655150 allows an unauthenticated host to access its live video stream by crafting a set of RTSP packets with a specific set of URLs that can be used to redirect the camera feed. NOTE: the vendor's perspective is that the Anonymous120386 sample code can establish RTSP protocol communictaion, but cannot obtain video or audio data; thus, there is no risk.
Published Aug 23, 2024 · Updated Jul 5, 2026
Medium · CVSS 6.7
Micron Crucial MX500 Series Solid State Drives M3CR046 is vulnerable to Buffer Overflow, which can be triggered by sending specially crafted ATA packets from the host to the drive controller. NOTE: The supplier states that this vulnerability was fully remediated in December 2024 and that updated firmware is available through Crucial’s official support page.
Published Sep 4, 2024 · Updated Jul 5, 2026
Medium · CVSS 5.3
REDCap 14.3.13 allows an attacker to enumerate usernames due to an observable discrepancy between login attempts.
Published Jan 2, 2026 · Updated Jul 5, 2026
High · CVSS 8.3
FNT Command 13.4.0 is vulnerable to Directory Traversal.
Published Dec 15, 2025 · Updated Jul 5, 2026
High · CVSS 8.8
FNT Command 13.4.0 is vulnerable to Code Execution via the C Base Module.
Published Dec 15, 2025 · Updated Jul 5, 2026
Medium · CVSS 6.5
Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection while resetting the password. This vulnerability is specifically found within the "set_sys_adm" function of the "adm.cgi" binary, and is due to improper santization of the user provided "newpass" field
Published Sep 2, 2025 · Updated Jul 5, 2026