Vulnerabilities
566 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-7807 | SmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vulnerability in the /api/v1/report/summary/{type} API endpoint that allows authent SmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vulnerability in the /api/v1/report/summary/{type} API endpoint that allows authenticated users to read arbitrary .json files on the system. Attackers can exploit this vulnerability combined with weak encryption algorithms and hardcoded keys to decrypt and access stored passwords and 2FA secrets for all users. NVD description · AI analysis pending | 8.7 | <1% |
| — | ||
| CVE-2026-40514 | SmarterTools SmarterMail builds prior to 9610 contain a cryptographic weakness in the file and email sharing endpoints that use DES-CBC encryption with keys and SmarterTools SmarterMail builds prior to 9610 contain a cryptographic weakness in the file and email sharing endpoints that use DES-CBC encryption with keys and initialization vectors derived from System.Random seeded with insufficient entropy, reducing the seed space to approximately 19,000 possible values. An unauthenticated attacker can use the attachment download endpoint as an oracle to determine the seed in use and derive encryption keys and initialization vectors to forge sharing tokens for arbitrary emails, attachments, or file storage contents without prior access to the targeted content. NVD description · AI analysis pending | 8.2 | <1% |
| — | ||
| CVE-2026-40097 | Step CA is an online certificate authority for secure, automated certificate management for DevOps. Step CA is an online certificate authority for secure, automated certificate management for DevOps. From 0.24.0 to before 0.30.0-rc3, an attacker can trigger an index out-of-bounds panic in Step CA by sending a crafted attestation key (AK) certificate with an empty Extended Key Usage (EKU) extension during TPM device attestation. When processing a device-attest-01 ACME challenge using TPM attestation, Step CA validates that the AK certificate contains the tcg-kp-AIKCertificate Extended Key Usage OID. During this validation, the EKU extension value is decoded from its ASN.1 representation and the first element is checked. A crafted certificate could include an EKU extension that decodes to an empty sequence, causing the code to panic when accessing the first element of the empty slice. This vulnerability is only reachable when a device-attest-01 ACME challenge with TPM attestation is configured. Deployments not using TPM device attestation are not affected. This vulnerability is fixed in 0.30.0-rc3. NVD description · AI analysis pending | 3.7 | <1% |
| — | ||
| CVE-2019-25680 | Advance Gift Shop Pro Script 2.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting m Advance Gift Shop Pro Script 2.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parameter. Attackers can submit crafted SQL payloads in the 's' parameter of search requests to extract sensitive database information including version details and other data. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2019-25676 | Ask Expert Script 3.0.5 contains cross-site scripting and SQL injection vulnerabilities that allow unauthenticated attackers to inject malicious code by manipul Ask Expert Script 3.0.5 contains cross-site scripting and SQL injection vulnerabilities that allow unauthenticated attackers to inject malicious code by manipulating URL parameters. Attackers can inject script tags through the cateid parameter in categorysearch.php or SQL code through the view parameter in list-details.php to execute arbitrary code or extract database information. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2019-25668 | News Website Script 2.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code thr News Website Script 2.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the news ID parameter. Attackers can send GET requests to index.php/show/news/ with malicious SQL statements to extract sensitive database information. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2018-25234 | SmartFTP Client 9.0.2615.0 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long stri SmartFTP Client 9.0.2615.0 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Host field. Attackers can paste a buffer of 300 repeated characters into the Host connection parameter to trigger an application crash. NVD description · AI analysis pending | 6.9 | <1% | PoC |
| — | |
| CVE-2025-41368 +1 in the same advisory: …41359 | Problem in the Small HTTP Server v3.06.36 service. Problem in the Small HTTP Server v3.06.36 service. An authenticated path traversal vulnerability in '/' allows remote users to bypass the intended restrictions of SecurityManager and display any file if they have the appropriate permissions outside the document root configured on the server. NVD description · AI analysis pending | 8.7 group max | <1% |
| — | ||
| CVE-2026-30836 | Step CA is an online certificate authority for secure, automated certificate management for DevOps. Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been fixed in version 0.30.0. NVD description · AI analysis pending | 10.0 | <1% |
| — | ||
| CVE-2026-3265 +1 in the same advisory: …3264 | A vulnerability was identified in go2ismail Free-CRM up to b83c40a90726d5e58f0cc680ffdcaa28a03fb5d1. A vulnerability was identified in go2ismail Free-CRM up to b83c40a90726d5e58f0cc680ffdcaa28a03fb5d1. This affects an unknown part of the file /api/Security/ of the component Security API. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 2.1 | <1% | PoC |
| — | |
| CVE-2026-3263 +1 in the same advisory: …3262 | A vulnerability was found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. A vulnerability was found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected by this vulnerability is an unknown functionality of the file /api/Security/ of the component Security API. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 5.3 group max | <1% | PoC |
| — | |
| CVE-2019-25444 +1 in the same advisory: …25445 | Fiverr Clone Script 1.2.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code thr Fiverr Clone Script 1.2.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the page parameter. Attackers can supply malicious SQL syntax in the page parameter to extract sensitive database information or modify database contents. NVD description · AI analysis pending | 8.8 group max | <1% | PoC |
| — | |
| CVE-2026-2547 | A vulnerability was detected in LigeroSmart up to 6.1.26. A vulnerability was detected in LigeroSmart up to 6.1.26. The impacted element is the function AgentDashboard of the file /otrs/index.pl. Performing a manipulation of the argument Subaction results in cross site scripting. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet. NVD description · AI analysis pending | 2.0 | <1% | PoC ×3 |
| — | |
| CVE-2026-25067 | SmarterTools SmarterMail versions prior to build 9518 contain an unauthenticated path coercion vulnerability in the background-of-the-day preview endpoint. SmarterTools SmarterMail versions prior to build 9518 contain an unauthenticated path coercion vulnerability in the background-of-the-day preview endpoint. The application base64-decodes attacker-supplied input and uses it as a filesystem path without validation. On Windows systems, this allows UNC paths to be resolved, causing the SmarterMail service to initiate outbound SMB authentication attempts to attacker-controlled hosts. This can be abused for credential coercion, NTLM relay attacks, and unauthorized network authentication. NVD description · AI analysis pending | 6.9 | <1% |
| — | ||
| CVE-2020-36972 | SmartBlog 2.0.1 contains a blind SQL injection vulnerability in the 'id_post' parameter of the details controller that allows attackers to extract database info SmartBlog 2.0.1 contains a blind SQL injection vulnerability in the 'id_post' parameter of the details controller that allows attackers to extract database information. Attackers can systematically test and retrieve database contents by injecting crafted SQL queries that compare character-by-character of database information. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2026-24423 | Unauthenticated RCE in SmarterTools SmarterMail (CVE-2026-24423) SmarterTools SmarterMail builds prior to build 9511 fail to require authentication on the ConnectToHub API method (CWE-306, Missing Authentication for Critical Function), resulting in unauthenticated remote code execution. An attacker triggers the flaw by directing SmarterMail to connect to an attacker-controlled HTTP server, which serves a malicious OS command that the vulnerable application then executes on the host. Successful exploitation yields arbitrary command execution on the mail server, enough for full system compromise and serving as the initial-access vector for the Warlock ransomware group. Any organization running an affected SmarterMail build is exposed, particularly those with the server's web/API interface reachable from the internet. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-02-05 with known ransomware use, and EPSS assigns an 87.7% probability of exploitation within 30 days (100th percentile). Do: Upgrade SmarterMail to build 9511 or later as soon as possible, prioritizing internet-facing mail servers. If patching cannot be done immediately, restrict internet access to the SmarterMail web/API interface and monitor the host for signs of compromise given confirmed ransomware exploitation. Federal agencies must apply vendor mitigations or follow BOD 22-01 guidance per the KEV listing. | 9.3 | 88% | KEV ransomware |
| largeon the order of tens of thousands of deployed SmarterMail servers (10k-100k installations) | |
| CVE-2026-23760 | Unauthenticated Admin Password Reset Bypass in SmarterTools SmarterMail SmarterTools SmarterMail builds prior to 9511 contain an authentication bypass (CWE-288) in the password reset API: the force-reset-password endpoint accepts anonymous requests and, when targeting a system administrator account, never verifies the existing password or requires a reset token. An unauthenticated remote attacker simply submits a target administrator username and a new password, taking over the system administrator account with no privileges or user interaction required. Because SmarterMail's system administrator role can execute operating system commands through built-in management functionality, this escalation effectively yields SYSTEM/root-level access on the underlying mail server host, making it a path to full server and network compromise. All SmarterMail deployments running builds older than 9511 are affected, with roughly 6,000+ likely vulnerable servers observed exposed to the internet. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-01-26 with known ransomware use (including Storm-1175 and Warlock activity), and public PoCs exist from WatchTowr and Huntress. Do: Immediately upgrade SmarterMail to build 9511 or later, prioritizing internet-exposed instances. Given known ransomware exploitation and the host-level access this flaw grants, check logs for anonymous calls to the force-reset-password endpoint, unexpected system administrator password changes, and signs of OS command execution or lateral movement on affected hosts. If patching is delayed, restrict or firewall access to the SmarterMail API/web interface, and follow CISA BOD 22-01 guidance for cloud-hosted deployments. | 9.3 | 96% | KEV ransomware PoC ×2 |
| moderate≈6,000+ internet-exposed SmarterMail servers | |
| CVE-2026-1048 +1 in the same advisory: …1049 | A weakness has been identified in LigeroSmart up to 6.1.26. A weakness has been identified in LigeroSmart up to 6.1.26. Impacted is an unknown function of the file /otrs/index.pl?Action=AgentTicketZoom. This manipulation of the argument TicketID causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. NVD description · AI analysis pending | 2.0 | <1% | PoC ×2 |
| — | |
| CVE-2021-47791 | SmartFTP Client 10.0.2909.0 contains multiple denial of service vulnerabilities that allow attackers to crash the application through specific input manipulatio SmartFTP Client 10.0.2909.0 contains multiple denial of service vulnerabilities that allow attackers to crash the application through specific input manipulation. Attackers can trigger crashes by entering malformed paths, using invalid IP addresses, or clearing connection history in the client's interface. NVD description · AI analysis pending | 4.6 | <1% | PoC |
| — | |
| CVE-2020-36926 | SmarterTrack 7922 contains an information disclosure vulnerability in the Chat Management search form that reveals agent identification details. SmarterTrack 7922 contains an information disclosure vulnerability in the Chat Management search form that reveals agent identification details. Attackers can access the vulnerable /Management/Chat/frmChatSearch.aspx endpoint to retrieve agents' first and last names along with their unique identifiers. NVD description · AI analysis pending | 6.9 | <1% | PoC |
| — | |
| CVE-2025-15437 | A vulnerability was found in LigeroSmart up to 6.1.24. A vulnerability was found in LigeroSmart up to 6.1.24. This affects an unknown part of the component Environment Variable Handler. Performing a manipulation of the argument REQUEST_URI results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be used. Upgrading to version 6.1.26 and 6.3 is able to mitigate this issue. The patch is named 264ac5b2be5b3c673ebd8cb862e673f5d300d9a7. The affected component should be upgraded. NVD description · AI analysis pending | 2.0 | <1% | PoC |
| — | |
| CVE-2025-52691 | Unauthenticated Arbitrary File Upload RCE in SmarterTools SmarterMail SmarterTools SmarterMail contains an unrestricted file upload flaw (CWE-434, CVSS 10.0) that lets an unauthenticated attacker upload files of dangerous types over the network without any credentials or user interaction. Because the uploaded files can be written to any location on the mail server, an attacker can drop a file into an executable path and achieve remote code execution on the host, which is why the CVSS scope is changed with high confidentiality, integrity and availability impact. An attacker who lands this foothold gains control of the mail server, and CISA notes known ransomware use, with press coverage linking the wave of SmarterMail exploitation to groups such as Storm-1175 and Warlock. Any organization running an internet-facing SmarterMail server — typically hosting providers, MSPs and SMBs using it as a Windows mail platform — is exposed. Exploitation is active: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-01-26, EPSS puts the 30-day exploitation probability at 85.7% (100th percentile), and a public proof-of-concept exploit is available from watchTowr. Do: Upgrade SmarterMail to the patched build referenced in the vendor advisory (exact build number not provided in the source data), prioritizing internet-exposed servers, and note that news reports indicate exploit activity began within roughly two days of the patch release, so unpatched systems should be assumed targeted. Check servers for signs of compromise — unexpected files in web-accessible or executable paths, new admin accounts, webshells, and ransomware indicators — and restrict webmail endpoints to trusted networks if immediate patching is not possible. US federal agencies must apply the required mitigation or discontinue use under BOD 22-01 timelines. | 10.0 | 86% | KEV ransomware PoC |
| moderateseveral thousand internet-exposed SmarterMail servers (niche Windows mail server with a total install base in the low tens of thousands) | |
| CVE-2025-65346 | alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The unzip/extraction functionality improperly allows archive contents to be written to arbitrary locations on the filesystem due to insufficient validation of extraction paths. NVD description · AI analysis pending | 9.1 | <1% | PoC |
| — | |
| CVE-2025-65345 | alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The zip/archiving functionality allows an attacker to create archives containing files and directories outside the intended scope due to improper path validation. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2025-50361 | Buffer Overflow was found in SmallBASIC community SmallBASIC with SDL Before v12_28, and commit sha:298a1d495355959db36451e90a0ac74bcc5593fe in the function mai Buffer Overflow was found in SmallBASIC community SmallBASIC with SDL Before v12_28, and commit sha:298a1d495355959db36451e90a0ac74bcc5593fe in the function main.cpp, which can lead to potential information leakage and crash. NVD description · AI analysis pending | 5.1 | <1% | PoC |
| — | |
| CVE-2025-63678 | An authenticated arbitrary file upload vulnerability in the /uploads/ endpoint of CMS Made Simple Foundation File Manager v2.2.22 allows attackers with Administ An authenticated arbitrary file upload vulnerability in the /uploads/ endpoint of CMS Made Simple Foundation File Manager v2.2.22 allows attackers with Administrator privileges to execute arbitrary code via uploading a crafted PHP file. NVD description · AI analysis pending | 7.2 | <1% | PoC |
| — | |
| CVE-2025-63307 | alexusmai laravel-file-manager 3.3.1 is vulnerable to Cross Site Scripting (XSS). alexusmai laravel-file-manager 3.3.1 is vulnerable to Cross Site Scripting (XSS). The application permits user-controlled upload, create, and rename of files to HTML and SVG types and serves those files inline without adequate content-type validation or output sanitization. NVD description · AI analysis pending | 8.1 | <1% | PoC |
| — | |
| CVE-2025-29157 | An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server returns a 404-error page An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server returns a 404-error page exposing sensitive information including the Servlet name (default) and server version NVD description · AI analysis pending | 6.5 group max | <1% | PoC |
| — | |
| CVE-2025-5692 | The Lead Form Data Collection to CRM plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in the ~/i The Lead Form Data Collection to CRM plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in the ~/includes/LB_admin_ajax.php file in all versions up to, and including, 3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform several actions like updating settings. Initially this CVE was assigned specifically to all AJAX actions and the doFieldAjaxAction() function, however it was determined that CVE-2025-47690 is assigned to the doFieldAjaxAction() function that leads to arbitrary options updates. NVD description · AI analysis pending | 4.3 | <1% |
| — | ||
| CVE-2025-48929 | The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expiration time) that can b The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expiration time) that can be reused at a later date if discovered by an adversary. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2025-48927 +1 in the same advisory: …48928 | Unauthenticated Heap Dump Disclosure in Smarsh TeleMessage TM SGNL CVE-2025-48927 is an insecure-default-configuration flaw (CWE-1188) in the TeleMessage TM SGNL messaging-archiving service sold by Smarsh, in which Spring Boot Actuator was enabled with its heap dump endpoint exposed at the /heapdump URI in service builds through 2025-05-05. The endpoint required no authentication, so any unauthenticated remote attacker could simply request /heapdump and download the Java process's heap dump, with no privileges or user interaction required. A heap dump exposes the application's in-memory state, potentially including archived message content, credentials, and session secrets, so the impact is confidentiality (information disclosure). Affected parties are organizations and users of the TeleMessage TM SGNL service running service builds through 2025-05-05. The flaw was exploited in the wild in May 2025 and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-07-01 (ransomware use unknown, no public proof-of-concept known), with EPSS currently at about 11% probability of exploitation over the next 30 days. Do: U.S. federal agencies must apply mitigations per Smarsh/TeleMessage instructions under BOD 22-01, or discontinue use of the service if mitigations are unavailable. Other customers should confirm with the vendor that their TM SGNL service is running builds later than 2025-05-05 with the Actuator /heapdump endpoint disabled or authenticated, review whether service credentials or archived message data may have leaked through heap dumps, and rotate any exposed secrets. | 5.3 group max | 11% | KEV |
| nicheunknown; plausibly thousands of users across a limited set of government and enterprise customers of the hosted TM SGNL service (no public user or install… | |
| CVE-2025-5153 | A vulnerability, which was classified as problematic, has been found in CMS Made Simple 2.2.21. A vulnerability, which was classified as problematic, has been found in CMS Made Simple 2.2.21. This issue affects some unknown processing of the component Design Manager Module. The manipulation of the argument Description leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 5.1 | <1% | PoC |
| — | |
| CVE-2025-4008 | Unauthenticated Command Injection RCE in Smartbedded Meteobridge The Meteobridge web interface, implemented in CGI shell scripts and C, exposes an endpoint vulnerable to command injection (CWE-77) with missing authentication requirements (CWE-306). A remote, unauthenticated attacker who can reach the web interface can supply crafted input that is passed to the underlying shell, gaining arbitrary command execution with root privileges on the device. Affected products are Smartbedded Meteobridge firmware and the Meteobridge VM, used to bridge weather-station data. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-10-02, and public reporting indicates it is being actively exploited in the wild; EPSS puts the 30-day exploitation probability at 93.7%. Exploitation details are documented in a public advisory by the discovering researcher (oneKey). Do: Apply the fix or mitigations per the Smartbedded vendor instructions referenced in the CISA KEV entry (fixed version numbers are not specified in the source data, so consult the vendor advisory and the oneKey write-up before upgrading). Until patched, do not expose the Meteobridge web interface directly to the internet — restrict it to trusted management networks or via VPN/firewall rules — and check exposed instances for signs of compromise given confirmed in-the-wild exploitation. Organizations under BOD 22-01 must apply the required mitigations within the mandated timeframe or discontinue use of the product. | 8.7 | 94% | KEV PoC |
| moderate≈1,000–10,000 internet-exposed Meteobridge instances (public scans historically show low thousands of exposed Meteobridge web interfaces; total installed base,… | |
| CVE-2024-12725 | The Clasify Classified Listing WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Refle The Clasify Classified Listing WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2025-47730 | The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Signal) app with the c The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Signal) app with the credentials of logfile for the user and enRR8UVVywXYbFkqU#QDPRkO for the password. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2024-13344 | The Advance Seat Reservation Management for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'profileId' parameter in all versions up to, The Advance Seat Reservation Management for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'profileId' parameter in all versions up to, and including, 3.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. NVD description · AI analysis pending | 7.5 | <1% |
| — |