CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 1mo ago | 9.8 | Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions. |
| 1mo ago | 9.8 | Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions. |
| 1mo ago | 9.8 | Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection. This issue affects Creatify: from n/a through 1.5. |
| 1mo ago | 9.8 | Deserialization of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object Injection. This issue affects The Hospital: from n/a through 1.8.1. |
| 1mo ago | 9.8 | Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects The Barber Shop: from n/a through 1.9. |
| 1mo ago | 9.8 | Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. This issue affects Lagom: from n/a through 2.0. |
| 1mo ago | 9.3 | Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions. |
| 1mo ago | 9.3 | Unauthenticated SQL Injection in WP eMember < v10.9.4 versions. |
| 1mo ago | 9.8 | Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions. |
| 1mo ago | 9.8 | Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions. |
| 1mo ago | 9.8 | Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.4 versions. |
| 1mo ago | 9.8 | Contributor PHP Object Injection in Fusion Builder <= 3.15.4 versions. |
| 1mo ago | 9.3 | Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions. |
| 1mo ago | 9.3 | Unauthenticated SQL Injection in JobSearch <= 3.2.9 versions. |
| 1mo ago | 9.8 | Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions. |
| 1mo ago | 9 | Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI Generated Forms <= 1.4.5 versions. |
| Exploit 1mo ago | 9.1 | A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP server write files outside the configured local destination directory via crafted directory-entry names. No Airflow account is required — the attack surface is any deployment downloading directories from an untrusted SFTP server. Upgrade `apache-airflow-providers-sftp` to 5.8.1 or later. |
| 1mo ago | 9.8 | Unauthenticated Broken Authentication in wpForo Forum <= 3.1.0 versions. |
| 1mo ago | 9.8 | Unauthenticated PHP Object Injection in Thrive Apprentice < 10.8.10.2 versions. |
| 1mo ago | 9.3 | Unauthenticated SQL Injection in JetEngine < 3.8.9.1 versions. |
| 1mo ago | 9.3 | Unauthenticated SQL Injection in wpDataTables <= 7.3.6 versions. |
| 1mo ago | 9.3 | Unauthenticated SQL Injection in JetSearch <= 3.5.17 versions. |
| 1mo ago | 9.3 | Unauthenticated SQL Injection in JetEngine <= 3.8.9.1 versions. |
| 1mo ago | 9.8 | Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions. |
| 1mo ago | 9.8 | Unauthenticated Privilege Escalation in LoginPress Pro <= 6.2.2 versions. |
| 1mo ago | 9.3 | Unauthenticated SQL Injection in JetSmartFilters <= 3.8.1 versions. |
| Exploit 1mo ago | 9.9 | Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an attacker-controlled JSON blob into a session-shape JWT using the application's JWT_SECRET, and the auth middleware trusted every claim in that JWT without re-resolving the user from the database. Any authenticated Postiz user could forge a SUPERADMIN session and impersonate arbitrary organizations. This allowed Full Access to the following: all parts of Postiz, including users registered to the specific instance and the ability to post in the name of the victim's social media channels added to that Postiz instance. This issue has been fixed in version 2.21.8. |
| Exploit 1mo ago | 9.3 | Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source Traccar platform. In versions 9.7.19 and below, a single crafted deep link can silently hijack all GPS tracking parameters and redirect telemetry to an attacker-controlled server. The app registers a custom org.traccar.client://config deep-link scheme that silently writes attacker-supplied parameters (server URL, device ID, accuracy, distance, and interval) into the app's persistent configuration with no confirmation, notification, or visual indication. A single crafted link delivered via SMS, email, a webpage, or any installed app can therefore reconfigure the app the moment the victim taps it, with no special permissions required. As a result, an attacker can covertly redirect all of the victim's GPS telemetry to their own server at maximum precision and frequency, and the change persists across restarts. This gives the attacker continuous, real-time tracking of the victim's location. This issue has been fixed in version 9.7.20. |
| Exploit 1mo ago | 9.3 | Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files. Protected file downloads at /file-upload/:fileId/:name authorize livechat access using rc_room_type=l with rc_rid+rc_token, but the authorization path does not verify that rc_rid matches the requested file's rid. Furthermore, :fileId is predictable via sequential MongoDB IDs, and :name can be anything, allowing unauthenticated discovery of all uploaded files. |
| Exploit 1mo ago | 10 | Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior, a high-severity Zip Slip vulnerability was identified in Streambert's subtitle extraction logic. The application does not sanitize archive entry filenames during extraction, allowing a malicious archive to perform path traversal and write arbitrary files to the host filesystem. The subtitle extraction process downloads a ZIP archive and extracts its entries. The destination file path is constructed by concatenating the raw archive entry name (extracted.name) directly to the temporary directory path. If a malicious ZIP archive containing directory traversal sequences is processed, it escapes the temporary directory boundaries. The application then writes the extracted payload anywhere on the host filesystem subject to the application's current write permissions. This issue has been fixed in version 2.5.0. |