Vulnerabilities
399 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-5964 +1 in the same advisory: …5963 | EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. NVD description · AI analysis pending | 9.3 | <1% |
| — | ||
| CVE-2026-39397 | @delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page builder. @delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page builder. Prior to 0.6.23, all /api/puck/* CRUD endpoint handlers registered by createPuckPlugin() called Payload's local API with the default overrideAccess: true, bypassing all collection-level access control. The access option passed to createPuckPlugin() and any access rules defined on Puck-registered collections were silently ignored on these endpoints. This vulnerability is fixed in 0.6.23. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2026-33896 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints requirements when an intermediate certificate lacks both the `basicConstraints` and `keyUsage` extensions. This allows any leaf certificate (without these extensions) to act as a CA and sign other certificates, which node-forge will accept as valid. Version 1.4.0 patches the issue. NVD description · AI analysis pending | 9.1 group max | <1% | PoC |
| — | |
| CVE-2026-25061 | tcpflow is a TCP/IP packet demultiplexer. tcpflow is a TCP/IP packet demultiplexer. In versions up to and including 1.61, wifipcap parses 802.11 management frame elements and performs a length check on the wrong field when handling the TIM element. A crafted frame with a large TIM length can cause a 1-byte out-of-bounds write past `tim.bitmap[251]`. The overflow is small and DoS is the likely impact; code execution is potential, but still up in the air. The affected structure is stack-allocated in `handle_beacon()` and related handlers. As of time of publication, no known patches are available. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2025-13979 | Privilege Defined With Unsafe Actions vulnerability in Drupal Mini site allows Stored XSS.This issue affects Mini site: Privilege Defined With Unsafe Actions vulnerability in Drupal Mini site allows Stored XSS.This issue affects Mini site: from 0.0.0 before 3.0.2. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2023-53975 | Atom CMS 2.0 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries through unvalidated parameters. Atom CMS 2.0 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries through unvalidated parameters. Attackers can inject malicious SQL code in the 'id' parameter of the admin index page to execute time-based blind SQL injection attacks. NVD description · AI analysis pending | 9.3 | <1% | PoC |
| — | |
| CVE-2025-55816 | HotelDruid v3.0.7 and before is vulnerable to Cross Site Scripting (XSS) in the /modifica_app.php file. HotelDruid v3.0.7 and before is vulnerable to Cross Site Scripting (XSS) in the /modifica_app.php file. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2025-66031 +1 in the same advisory: …66030 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2. NVD description · AI analysis pending | 8.7 group max | <1% |
| — | ||
| CVE-2025-12816 | An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desyn An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may bypass downstream cryptographic verifications and security decisions. NVD description · AI analysis pending | 8.6 | <1% | PoC |
| — | |
| CVE-2025-12082 +1 in the same advisory: …12083 | Incorrect Authorization vulnerability in Drupal CivicTheme Design System allows Forceful Browsing.This issue affects CivicTheme Design System: Incorrect Authorization vulnerability in Drupal CivicTheme Design System allows Forceful Browsing.This issue affects CivicTheme Design System: from 0.0.0 before 1.12.0. NVD description · AI analysis pending | 7.5 group max | <1% |
| — | ||
| CVE-2025-59684 | DigiSign DigiSigner ONE 1.0.4.60 allows DLL Hijacking. DigiSign DigiSigner ONE 1.0.4.60 allows DLL Hijacking. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2025-59717 | In the @digitalocean/do-markdownit package through 1.16.1 (in npm), the callout and fence_environment plugins perform .includes substring matching if allowedCla In the @digitalocean/do-markdownit package through 1.16.1 (in npm), the callout and fence_environment plugins perform .includes substring matching if allowedClasses or allowedEnvironments is a string (instead of an array). NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2021-4457 | The ZoomSounds plugin before 6.05 contains a PHP file allowing unauthenticated users to upload an arbitrary file anywhere on the web server. The ZoomSounds plugin before 6.05 contains a PHP file allowing unauthenticated users to upload an arbitrary file anywhere on the web server. NVD description · AI analysis pending | 9.1 | <1% | PoC |
| — | |
| CVE-2025-44203 | In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database creation wi In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database creation without locking. By sending many concurrent requests, an attacker can trigger a race condition during which verbose SQL error messages disclose the administrator username, password hash, and salt. The same race leaves the setup partially initialized, so the administrator can no longer log in with the credentials set during installation, resulting in a denial of service that requires reinstallation to recover. Remote exploitation additionally requires the installation to allow non-localhost access. The vulnerability was fixed in version 3.0.8. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2025-47568 | Deserialization of Untrusted Data vulnerability in ZoomIt ZoomSounds dzs-zoomsounds allows Object Injection.This issue affects ZoomSounds: Deserialization of Untrusted Data vulnerability in ZoomIt ZoomSounds dzs-zoomsounds allows Object Injection.This issue affects ZoomSounds: from n/a through <= 6.91. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2023-6786 | The Payment Gateway for Telcell WordPress plugin through 2.0.1 does not validate the api_url parameter before redirecting the user to its value, leading to an O The Payment Gateway for Telcell WordPress plugin through 2.0.1 does not validate the api_url parameter before redirecting the user to its value, leading to an Open Redirect issue NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2025-4527 | A security flaw has been discovered in Dígitro NGC Explorer up to 3.48.21. A security flaw has been discovered in Dígitro NGC Explorer up to 3.48.21. The impacted element is an unknown function of the component Password Transmission Handler. Performing a manipulation results in client-side enforcement of server-side security. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is regarded as difficult. Upgrading to version 3.48.22 is sufficient to resolve this issue. Upgrading the affected component is recommended. The action taken by the vendor is: "Strengthening of security validation performed on the server side, together with improvements to administrative and authentication controls." The vulnerabilities are limited to NGC Explorer and do not affect other Dígitro products, including UNA and Guardião. NVD description · AI analysis pending | 2.9 group max | <1% |
| — | ||
| CVE-2025-3927 | Digigram's PYKO-OUT audio-over-IP (AoIP) web-server does not require a password by default, allowing any attacker with the target IP address to connect and comp Digigram's PYKO-OUT audio-over-IP (AoIP) web-server does not require a password by default, allowing any attacker with the target IP address to connect and compromise the device, potentially pivoting to connected network or hardware devices. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2023-43378 | A cross-site scripting (XSS) vulnerability in Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into th A cross-site scripting (XSS) vulnerability in Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the commento1_1 parameter. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2025-3431 | The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.91 The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.91 via the 'dzsap_download' action. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2024-13776 +1 in the same advisory: …0839 | The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'dzsap_delete_notice' AJAX action in all versions up to, and including, 6.91. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update option values to 'seen' on the WordPress site. This can be leveraged to update an option that would create an error on the site and deny service to legitimate users or be used to set some values to true such as registration. There are several other functions also vulnerable to missing authorization. NVD description · AI analysis pending | 8.1 group max | <1% |
| — | ||
| CVE-2025-25748 | A CSRF vulnerability in the gestione_utenti.php endpoint of HotelDruid 3.0.7 allows attackers to perform unauthorized actions (e.g., modifying user passwords) o A CSRF vulnerability in the gestione_utenti.php endpoint of HotelDruid 3.0.7 allows attackers to perform unauthorized actions (e.g., modifying user passwords) on behalf of authenticated users by exploiting the lack of origin or referrer validation and the absence of CSRF tokens. NOTE: this is disputed because there is an id_sessione CSRF token. NVD description · AI analysis pending | 7.3 group max | <1% |
| — | ||
| CVE-2024-13777 | The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.91 The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.91 via deserialization of untrusted input from the 'margs' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2025-1387 | Orca HCM from LEARNING DIGITAL has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to log in to the system as any user. Orca HCM from LEARNING DIGITAL has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to log in to the system as any user. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2025-25167 +1 in the same advisory: …25168 | Missing Authorization vulnerability in Black and White BookPress – For Book Authors book-press allows Exploiting Incorrectly Configured Access Control Security Missing Authorization vulnerability in Black and White BookPress – For Book Authors book-press allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BookPress – For Book Authors: from n/a through <= 1.2.7. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2023-52163 | Missing Authorization Enables Command Injection in Digiever DS-2105 Pro NVRs Digiever DS-2105 Pro network video recorders (firmware version 3.1.0.71-11 is cited in the advisory) expose a time_tzsetup.cgi endpoint that fails to properly enforce authorization (CWE-862), and crafted requests to it trigger operating-system command injection; the CVSS 8.8 score reflects network reachability, low privilege requirements, and no user interaction. Successful exploitation yields command execution on the device with high impact on confidentiality, integrity, and availability — effectively remote code execution, which makes these NVRs attractive targets for IoT botnets such as the RondoDox campaign and the Mirai-variant ShadowV2. Only organizations still running the DS-2105 Pro (or DS-2105 Pro+) are affected, and because the vendor no longer supports the product, unpatched internet-facing units are the primary risk. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-12-22, EPSS puts the 30-day exploitation probability at 96.9%, and ransomware use is currently unknown. Do: Because the product is end-of-life, check with Digiever for any final firmware update and apply it per vendor instructions; if no patch or mitigation is available, the CISA KEV required action is to discontinue use of the device, and federal agencies must follow BOD 22-01 timelines. In the interim, remove direct internet exposure of the NVR's web interface (restrict via firewall or place behind VPN) and hunt for compromise by looking for suspicious requests to time_tzsetup.cgi and unexpected outbound connections consistent with botnet infection. | 8.8 | 97% | KEV PoC ×3 |
| moderatelikely on the order of thousands of internet-exposed NVRs (estimated; exact install base unknown) | |
| CVE-2024-11842 | The DN Shipping by Weight for WooCommerce WordPress plugin before 1.2 does not have CSRF check in place when updating its settings, which could allow attackers The DN Shipping by Weight for WooCommerce WordPress plugin before 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack NVD description · AI analysis pending | 4.3 | <1% | PoC |
| — | |
| CVE-2024-50626 | An issue was discovered in Digi ConnectPort LTS before 1.4.12. An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Directory Traversal vulnerability exists in WebFS. This allows an attacker on the local area network to manipulate URLs to include traversal sequences, potentially leading to unauthorized access to data. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2021-4449 | The ZoomSounds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'savepng.php' file in versions up to, and The ZoomSounds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'savepng.php' file in versions up to, and including, 5.96. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. CVE-2021-4457 is a duplicate of this. NVD description · AI analysis pending | 9.8 | 5% | PoC ×2 |
| — | |
| CVE-2024-8803 | The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.15. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2024-6845 | The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, allowing unauthenticated users to retriev The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, allowing unauthenticated users to retrieve the encoded key and then decode it, thereby leaking the OpenAI API key NVD description · AI analysis pending | 5.3 | 1% | PoC |
| — | |
| CVE-2024-43988 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in digitalnature Mystique allows Stored XSS.This issue Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in digitalnature Mystique allows Stored XSS.This issue affects Mystique: from n/a through 2.5.7. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2024-8585 | Orca HCM from LEARNING DIGITA does not properly restrict a specific parameter of the file download functionality, allowing a remote attacker with regular privil Orca HCM from LEARNING DIGITA does not properly restrict a specific parameter of the file download functionality, allowing a remote attacker with regular privileges to download arbitrary system files. NVD description · AI analysis pending | 6.5 | <1% |
| — |