CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| Exploit 1mo ago | 9.6 | mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.3.10, mise processes .tool-versions files through the Tera template engine during parsing, with the exec() function registered, enabling arbitrary command execution. Unlike .mise.toml files, .tool-versions files are not subject to trust verification in non-paranoid mode. This means an attacker can place a malicious .tool-versions file in a git repository, and when a victim with mise activated cds into the directory, arbitrary commands execute without any trust prompt. This vulnerability is fixed in 2026.3.10. |
| Exploit 1mo ago | 9 | Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron running as the Dokku user. An app.json cron command utilizing special shell characters - including, but not limited to, > or ; - can break out of the Docker container and execute commands on the host as the Dokku user. This vulnerability is fixed in 0.38.7. |
| Exploit 1mo ago | 9 | Dokku is a docker-powered PaaS. Prior to 0.38.2, the app name validation regex (^[a-z0-9][^/:_A-Z]*$) permits shell metacharacters. When an authenticated user pushes to a git remote with a crafted app name, the name is embedded unquoted into a bash pre-receive hook script via an unquoted heredoc (<<EOF instead of <<'EOF') in fn-git-create-hook() at plugins/git/internal-functions:378. On git push, bash interprets the semicolon as a command separator, executing arbitrary commands as the dokku user. This vulnerability is fixed in 0.38.2. |
| Exploit 1mo ago | 9 | Dokku is a docker-powered PaaS. Prior to 0.38.2, the openresty-vhosts plugin copies files from an app's openresty/http-includes/ git repository directory to the host and then interpolates their filenames, unescaped, into a single-quoted shell string that is later parsed by eval. A filename containing a single quote breaks the quoting and allows command substitution to execute arbitrary commands on the host as the dokku user during the app's next deploy. This vulnerability is fixed in 0.38.2. |
| Exploit 1mo ago | 9 | Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:from-archive and certs:add commands extract user-supplied tar/zip archives into temporary directories without sanitizing member paths or preventing symlink traversal. GNU tar creates symlinks during extraction and follows them for subsequent entries, allowing an attacker to write arbitrary files anywhere writable by the dokku user — including overwriting ~/.ssh/authorized_keys to gain unrestricted shell access. This vulnerability is fixed in 0.38.2. |
| Exploit 1mo ago | 9.8 | Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows a remote attacker to achieve remote code execution (RCE) via crafted template expressions. |
| Exploit 1mo ago | 9.6 | The default JVM can access files and directories under `/tmp/` including the `$TemporaryDirectory` of other users on the same cloud instance (`/tmp/UserTemporaryFiles/`). The `-init` file for the the JVM initialization exists in the vulnerable directory during the startup of the JVM. An attacker with access to the shared `/tmp/` space can preemptively create or replace `.jar` files or directories (via the `-init` file) that the victim JVM will resolve first in its classpath. By strategically placing a malicious version of a commonly used library (e.g., `commons-io`) in a location that is included in the classpath before the legitimate version, an attacker can cause the JVM to load the malicious class during startup, thereby executing the attacker's code. |
| 1mo ago | 9.1 | Administrator Arbitrary File Upload in TemplateSpare <= 4.2.0 versions. |
| 1mo ago | 9.3 | Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions. |
| 1mo ago | 9.3 | Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions. |
| 1mo ago | 9.3 | Unauthenticated SQL Injection in JetSmartFilters <= 3.8.3 versions. |
| 1mo ago | 9.3 | Unauthenticated SQL Injection in Quotes llama <= 3.1.5 versions. |
| 1mo ago | 9.9 | Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions. |
| 1mo ago | 9.9 | Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions. |
| 1mo ago | 9.8 | Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions. |
| 1mo ago | 9.3 | Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions. |
| 1mo ago | 9.3 | Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions. |
| 1mo ago | 9.8 | Unauthenticated Privilege Escalation in Dokan Pro <= 5.0.4 versions. |
| 1mo ago | 9.8 | Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions. |
| 1mo ago | 9.8 | Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions. |
| 1mo ago | 9.8 | Unauthenticated Privilege Escalation in Easy Elements for Elementor – Addons & Website Templates <= 1.4.9 versions. |
| 1mo ago | 9.9 | Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions. |
| 1mo ago | 9.3 | Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions. |
| 1mo ago | 9.3 | Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions. |
| 1mo ago | 9.3 | Unauthenticated SQL Injection in wpDataTables <= 7.4 versions. |
| 1mo ago | 9.3 | Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions. |
| 1mo ago | 9.1 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.6, from 2.0.0 before 2.0.7. Users are recommended to upgrade to version 1.3.6 and 2.0.7, which fixes the issue. |
| 1mo ago | 9.1 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 2.0.0 before 2.0.6, from 1.0.0 before 1.3.6. Users are recommended to upgrade to version 1.3.6 and 2.0.6, which fixes the issue. |
| Exploit 1mo ago | 9.8 | An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient length validation when processing remote login data. A remote attacker may exploit this vulnerability by sending crafted login data with overly long input, resulting in memory corruption, denial of service, or potentially arbitrary code execution. |
| Exploit 1mo ago | 9.8 | An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when parsing RTSP Digest authentication fields. A remote attacker may exploit this vulnerability by sending a crafted RTSP request containing overly long authentication data, resulting in memory corruption, denial of service, or potentially arbitrary code execution. |