SEPTEMBER 18, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

36,341 records on file
Page 148 of 1,212
CVE ID Score Description
1mo ago
9.8

Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions.

Exploit 1mo ago
9.9

Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions.

1mo ago
9.9

Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions.

1mo ago
9.9

Subscriber Arbitrary File Upload in Kids Gift Shop <= 0.5.4 versions.

1mo ago
9.9

Subscriber Arbitrary File Upload in Ecommerce Zone <= 0.9.7 versions.

1mo ago
9.9

Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions.

1mo ago
9.8

Unauthenticated PHP Object Injection in WooCommerce Product Filters < 2.0.6 versions.

1mo ago
9.3

Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions.

1mo ago
9.9

Subscriber Arbitrary File Upload in Webenvo <= 0.0.6 versions.

1mo ago
9.8

Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions.

1mo ago
9.3

Unauthenticated SQL Injection in ListingPro <= 2.9.10 versions.

1mo ago
9.1

Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

1mo ago
9.8

DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

1mo ago
9.8

Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions.

1mo ago
9.8

Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions.

1mo ago
9.9

Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions.

1mo ago
10

Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom Post Types Plugin for WordPress allows Remote Code Inclusion. This issue affects ACPT (Pro) - Custom Post Types Plugin for WordPress: from n/a through 2.0.47.

1mo ago
9.9

Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions.

1mo ago
9.1

Unauthenticated Broken Access Control in MetForm Pro <= 3.9.1 versions.

1mo ago
9.3

Unauthenticated SQL Injection in WPJobster <= 6.3.5 versions.

1mo ago
9.3

Unauthenticated SQL Injection in Tutor LMS Pro <= 3.9.6 versions.

1mo ago
9.9

Subscriber Arbitrary File Upload in Restaurt <= 1.0.4 versions.

1mo ago
9.6

Use after free in DigitalCredentials in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

1mo ago
9.8

A Path Traversal vulnerability affecting SOLIDWORKS Visualize from SOLIDWORKS Desktop Release 2024 through SOLIDWORKS Desktop Release 2026 could allow an attacker to write arbitrary files on the server.

1mo ago
9.8

Unauthenticated Privilege Escalation in Support Ticket Management System <= 1.9 versions.

1mo ago
10

Unauthenticated Arbitrary File Upload in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 versions.

1mo ago
9.8

Unauthenticated PHP Object Injection in SeaFood Company <= 1.4 versions.

1mo ago
9.8

Unauthenticated PHP Object Injection in Hot Coffee <= 1.7 versions.

1mo ago
9.9

Subscriber Arbitrary File Upload in PT Luxa Addons <= 1.2.2 versions.

1mo ago
9.8

Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions.