Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 401-420 of 1249 records
Threat Entry Updated 2026-01-23

CVE-2026-1021 - Police Statistics Database System Plugin

Police Statistics Database System developed by Gotac has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attacker to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

PLUGIN Police Statistics Database System

CVE-2026-1021

CRITICAL CVSS 9.3 2026-01-16
Threat Entry Updated 2026-01-23

CVE-2026-1019 - Police Statistics Database System Plugin

Police Statistics Database System developed by Gotac has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify, and delete database contents by using a specific functionality.

PLUGIN Police Statistics Database System

CVE-2026-1019

CRITICAL CVSS 9.3 2026-01-16
Threat Entry Updated 2026-01-21

CVE-2026-22863 - Deno Plugin

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.6.0, node:crypto doesn't finalize cipher. The vulnerability allows an attacker to have infinite encryptions. This can lead to naive attempts at brute forcing, as well as more refined attacks with the goal to learn the server secrets. This vulnerability is fixed in 2.6.0.

PLUGIN Deno

CVE-2026-22863

CRITICAL CVSS 9.2 2026-01-15
Threat Entry Updated 2026-01-23

CVE-2026-1009 - Altium Live Plugin

A stored cross-site scripting (XSS) vulnerability exists in the Altium Forum due to missing server-side input sanitization in forum post content. An authenticated attacker can inject arbitrary JavaScript into forum posts, which is stored and executed when other users view the affected post. Successful exploitation allows the attacker’s payload to execute in the context of the victim’s authenticated Altium 365 session, enabling unauthorized access to workspace data, including design files and workspace settings. Exploitation requires user interaction to view a malicious forum post.

PLUGIN Altium Live

CVE-2026-1009

CRITICAL CVSS 9.0 2026-01-15
Threat Entry Updated 2026-01-16

CVE-2026-23746 - Instant Financial Issuance (IF) Plugin

Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prior to 6.11.1 contain an insecure .NET Remoting exposure in the SmartCardController service (DCG.SmartCardControllerService.exe). The service registers a TCP remoting channel with unsafe formatter/settings that permit untrusted remoting object invocation. A remote, unauthenticated attacker who can reach the remoting port can invoke exposed remoting objects to read arbitrary files from the server and coerce outbound authentication, and may achieve arbitrary file write and remote code execution via known .NET Remoting exploitation…

PLUGIN Instant Financial Issuance (IF)

CVE-2026-23746

CRITICAL CVSS 9.3 2026-01-15
Threat Entry Updated 2026-02-05

CVE-2026-23520 - Arcane Plugin

Arcane provides modern docker management. Prior to 1.13.0, Arcane has a command injection in the updater service. Arcane’s updater service supported lifecycle labels com.getarcaneapp.arcane.lifecycle.pre-update and com.getarcaneapp.arcane.lifecycle.post-update that allowed defining a command to run before or after a container update. The label value is passed directly to /bin/sh -c without sanitization or validation. Because any authenticated user (not limited to administrators) can create projects through the API, an attacker can create a project that specifies one of these lifecycle labels with a malicious command. When an administrator later triggers a container…

PLUGIN Arcane

CVE-2026-23520

CRITICAL CVSS 9.0 2026-01-15
Threat Entry Updated 2026-01-23

CVE-2026-22908 - TDC-X401GL Plugin

Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially compromising its integrity and confidentiality.

PLUGIN TDC-X401GL

CVE-2026-22908

CRITICAL CVSS 9.1 2026-01-15
Threat Entry Updated 2026-02-02

CVE-2026-22240 - BLUVOYIX Plugin

The vulnerability exists in BLUVOYIX due to an improper password storage implementation and subsequent exposure via unauthenticated APIs. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable users API to retrieve the plaintext passwords of all user users. Successful exploitation of this vulnerability could allow the attacker to gain full access to customers' data and completely compromise the targeted platform by logging in using an exposed admin email address and password.

PLUGIN BLUVOYIX

CVE-2026-22240

CRITICAL CVSS 10.0 2026-01-14
Threat Entry Updated 2026-02-02

CVE-2026-22239 - BLUVOYIX Plugin

The vulnerability exists in BLUVOYIX due to design flaws in the email sending API. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable email sending API. Successful exploitation of this vulnerability could allow the attacker to send unsolicited emails to anyone on behalf of the company.

PLUGIN BLUVOYIX

CVE-2026-22239

CRITICAL CVSS 10.0 2026-01-14
Threat Entry Updated 2026-02-02

CVE-2026-22238 - BLUVOYIX Plugin

The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX admin APIs. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable admin API to create a new user with admin privileges. Successful exploitation of this vulnerability could allow the attacker to gain full access to customers' data and completely compromise the targeted platform by logging in to the newly-created admin user.

PLUGIN BLUVOYIX

CVE-2026-22238

CRITICAL CVSS 10.0 2026-01-14
Threat Entry Updated 2026-02-02

CVE-2026-22237 - BLUVOYIX Plugin

The vulnerability exists in BLUVOYIX due to the exposure of sensitive internal API documentation. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the APIs exposed by the documentation. Successful exploitation of this vulnerability could allow the attacker to cause damage to the targeted platform by abusing internal functionality.

PLUGIN BLUVOYIX

CVE-2026-22237

CRITICAL CVSS 10.0 2026-01-14
Threat Entry Updated 2026-02-02

CVE-2026-22236 - BLUVOYIX Plugin

The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX backend APIs. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable APIs. Successful exploitation of this vulnerability could allow the attacker to gain full access to customers' data and completely compromise the targeted platform.

PLUGIN BLUVOYIX

CVE-2026-22236

CRITICAL CVSS 10.0 2026-01-14
Threat Entry Updated 2026-06-17

CVE-2026-23550 - Modular DS Plugin

Incorrect Privilege Assignment vulnerability in Modular DS Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from n/a through

PLUGIN Modular DS

CVE-2026-23550

CRITICAL CVSS 10.0 2026-01-14
Threat Entry Updated 2026-01-14

CVE-2025-14502 - News And Blog Designer Bundle Plugin

The News and Blog Designer Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1 via the template parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.

PLUGIN News And Blog Designer Bundle

CVE-2025-14502

CRITICAL CVSS 9.8 2026-01-14
Threat Entry Updated 2026-01-14

CVE-2025-14301 - Woosa Ai For Woocommerce Plugin

The Integration Opvius AI for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.0. This is due to the `process_table_bulk_actions()` function processing user-supplied file paths without authentication checks, nonce verification, or path validation. This makes it possible for unauthenticated attackers to delete or download arbitrary files on the server via the `wsaw-log[]` POST parameter, which can be leveraged to delete critical files like `wp-config.php` or read sensitive configuration files.

PLUGIN Woosa Ai For Woocommerce

CVE-2025-14301

CRITICAL CVSS 9.8 2026-01-14
Threat Entry Updated 2026-02-24

CVE-2026-22686 - Enclave Plugin

Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.7.0, there is a critical sandbox escape vulnerability in enclave-vm that allows untrusted, sandboxed JavaScript code to execute arbitrary code in the host Node.js runtime. When a tool invocation fails, enclave-vm exposes a host-side Error object to sandboxed code. This Error object retains its host realm prototype chain, which can be traversed to reach the host Function constructor. An attacker can intentionally trigger a host error, then climb the prototype chain. Using the host Function…

PLUGIN Enclave

CVE-2026-22686

CRITICAL CVSS 10.0 2026-01-14
Threat Entry Updated 2026-02-03

CVE-2026-23478 - cal.com Plugin

Cal.com is open-source scheduling software. From 3.1.6 to before 6.0.7, there is a vulnerability in a custom NextAuth JWT callback that allows attackers to gain full authenticated access to any user's account by supplying a target email address via session.update(). This vulnerability is fixed in 6.0.7.

PLUGIN cal.com

CVE-2026-23478

CRITICAL CVSS 10.0 2026-01-13
Scroll to top