Vulnerabilities
141 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-41049 | Incorrect caching of authentication between different users of the qSnapper dbus service before version 1.3.3 allowed any local attacker to use dbus functions a Incorrect caching of authentication between different users of the qSnapper dbus service before version 1.3.3 allowed any local attacker to use dbus functions after a privileged users has authenticated for them. NVD description · AI analysis pending | 8.4 group max | <1% |
| — | ||
| CVE-2025-66944 | SQL Injection vulnerability in vran-dev databaseir v.1.0.7 and before allows a remote attacker to execute arbitrary code via the query parameter in the search A SQL Injection vulnerability in vran-dev databaseir v.1.0.7 and before allows a remote attacker to execute arbitrary code via the query parameter in the search API endpoint NVD description · AI analysis pending | 9.8 | <1% | PoC ×2 |
| — | |
| CVE-2025-61464 +1 in the same advisory: …60859 | gnuboard gnuboard4 v4.36.04 and before is vulnerable to Second-order SQL Injection via the search_table in bbs/search.php. gnuboard gnuboard4 v4.36.04 and before is vulnerable to Second-order SQL Injection via the search_table in bbs/search.php. NVD description · AI analysis pending | 6.5 group max | <1% | PoC ×2 |
| — | |
| CVE-2025-7786 | A vulnerability, which was classified as problematic, has been found in Gnuboard g6 up to 6.0.10. A vulnerability, which was classified as problematic, has been found in Gnuboard g6 up to 6.0.10. This issue affects some unknown processing of the file /bbs/scrap_popin_update/qa/ of the component Post Reply Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. NVD description · AI analysis pending | 2.0 | <1% | PoC |
| — | |
| CVE-2024-37656 | An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the insufficient URL parameter verification in An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the insufficient URL parameter verification in bbs/logout.php. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2025-46233 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sirv CDN and Image Hosting Sirv sirv allows Stored XSS.Thi Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sirv CDN and Image Hosting Sirv sirv allows Stored XSS.This issue affects Sirv: from n/a through <= 7.5.3. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2024-10855 | The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to insufficient validation on the filename parameter of the sirv_upload_file_by_chunks() function and lack of in all versions up to, and including, 7.3.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary option values on the WordPress site. This can be leveraged to delete an option that would create an error on the site and deny service to legitimate users. NVD description · AI analysis pending | 8.1 | <1% |
| — | ||
| CVE-2024-8964 | The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and in The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 7.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2024-8480 | The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'si The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sirv_save_prevented_sizes' function in all versions up to, and including, 7.2.7. This makes it possible for authenticated attackers, with Contributor-level access and above, to exploit the 'sirv_upload_file_by_chunks_callback' function, which lacks proper file type validation, allowing attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2024-39097 | There is an Open Redirect vulnerability in Gnuboard v6.0.4 and below via the `url` parameter in login path. There is an Open Redirect vulnerability in Gnuboard v6.0.4 and below via the `url` parameter in login path. NVD description · AI analysis pending | 6.1 | <1% | PoC ×2 |
| — | |
| CVE-2024-41475 | Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration. Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2024-6223 +1 in the same advisory: …6224 | The Send email only on Reply to My Comment WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leadin The Send email only on Reply to My Comment WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin NVD description · AI analysis pending | 6.1 group max | <1% | PoC |
| — | |
| CVE-2024-6392 | The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized plugin settings modification due to missing capability checks on The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized plugin settings modification due to missing capability checks on the plugin functions in all versions up to, and including, 7.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the connected Sirv account to an attacker-controlled one. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2024-5853 | The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the sirv_upload_ The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the sirv_upload_file_by_chanks AJAX action in all versions up to, and including, 7.2.6. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2024-6056 | A vulnerability was found in nasirkhan Laravel Starter up to 11.8.0. A vulnerability was found in nasirkhan Laravel Starter up to 11.8.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /forgot-password of the component Password Reset Handler. The manipulation of the argument Email leads to observable response discrepancy. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-268784. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 6.3 | <1% | PoC |
| — | |
| CVE-2024-32959 | Incorrect Privilege Assignment vulnerability in Sirv CDN and Image Hosting Sirv sirv.This issue affects Sirv: Incorrect Privilege Assignment vulnerability in Sirv CDN and Image Hosting Sirv sirv.This issue affects Sirv: from n/a through <= 7.2.2. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2024-24157 | Gnuboard g6 / https://github.com/gnuboard/g6 commit c2cc1f5069e00491ea48618d957332d90f6d40e4 is vulnerable to Cross Site Scripting (XSS) via board.py. Gnuboard g6 / https://github.com/gnuboard/g6 commit c2cc1f5069e00491ea48618d957332d90f6d40e4 is vulnerable to Cross Site Scripting (XSS) via board.py. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2024-33782 | MP-SPDZ v0.3.8 was discovered to contain a stack overflow via the function OTExtensionWithMatrix::extend in /OT/OTExtensionWithMatrix.cpp. MP-SPDZ v0.3.8 was discovered to contain a stack overflow via the function OTExtensionWithMatrix::extend in /OT/OTExtensionWithMatrix.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message. NVD description · AI analysis pending | 7.5 group max | <1% | PoC |
| — | |
| CVE-2024-24156 | Cross Site Scripting (XSS) vulnerability in Gnuboard g6 before Github commit 58c737a263ac0c523592fd87ff71b9e3c07d7cf5, allows remote attackers execute arbitrary Cross Site Scripting (XSS) vulnerability in Gnuboard g6 before Github commit 58c737a263ac0c523592fd87ff71b9e3c07d7cf5, allows remote attackers execute arbitrary code via the wr_content parameter. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2023-50898 | Missing Authorization vulnerability in sirv.Com Sirv.This issue affects Sirv: Missing Authorization vulnerability in sirv.Com Sirv.This issue affects Sirv: from n/a through 7.1.2. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2024-27950 +1 in the same advisory: …27949 | Missing Authorization vulnerability in Sirv CDN and Image Hosting Sirv sirv.This issue affects Sirv: Missing Authorization vulnerability in Sirv CDN and Image Hosting Sirv sirv.This issue affects Sirv: from n/a through <= 7.2.0. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2023-35857 | In Siren Investigate before 13.2.2, session keys remain active even after logging out. In Siren Investigate before 13.2.2, session keys remain active even after logging out. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2023-27821 | Databasir v1.0.7 was discovered to contain a remote code execution (RCE) vulnerability via the mockDataScript parameter. Databasir v1.0.7 was discovered to contain a remote code execution (RCE) vulnerability via the mockDataScript parameter. NVD description · AI analysis pending | 9.8 | 2% | PoC ×2 |
| — | |
| CVE-2022-48111 | A cross-site scripting (XSS) vulnerability in the check_login function of SIPE s.r.l WI400 between version 8 and 11 included allows attackers to execute arbitra A cross-site scripting (XSS) vulnerability in the check_login function of SIPE s.r.l WI400 between version 8 and 11 included allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the f parameter. NVD description · AI analysis pending | 6.1 | <1% | PoC ×2 |
| — | |
| CVE-2022-44216 | Gnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions. Gnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions. An attacker can change password of all users without knowing victim's original password. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2022-42484 +1 in the same advisory: …38451 | An OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5. An OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability. NVD description · AI analysis pending | 9.8 group max | 6% | PoC |
| — | |
| CVE-2022-44264 +1 in the same advisory: …44263 | Dentsply Sirona Sidexis <= 4.3 is vulnerable to Unquoted Service Path. Dentsply Sirona Sidexis <= 4.3 is vulnerable to Unquoted Service Path. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2022-42493 | Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is reachable through the m2m's DOWNLOAD_INFO command. NVD description · AI analysis pending | 9.8 group max | 3% |
| — |