CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 1mo ago | 9.8 | Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions. |
| Exploit 1mo ago | 9.9 | Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions. |
| 1mo ago | 9.9 | Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions. |
| 1mo ago | 9.9 | Subscriber Arbitrary File Upload in Kids Gift Shop <= 0.5.4 versions. |
| 1mo ago | 9.9 | Subscriber Arbitrary File Upload in Ecommerce Zone <= 0.9.7 versions. |
| 1mo ago | 9.9 | Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions. |
| 1mo ago | 9.8 | Unauthenticated PHP Object Injection in WooCommerce Product Filters < 2.0.6 versions. |
| 1mo ago | 9.3 | Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions. |
| 1mo ago | 9.9 | Subscriber Arbitrary File Upload in Webenvo <= 0.0.6 versions. |
| 1mo ago | 9.8 | Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions. |
| 1mo ago | 9.3 | Unauthenticated SQL Injection in ListingPro <= 2.9.10 versions. |
| 1mo ago | 9.1 | Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. |
| 1mo ago | 9.8 | DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. |
| 1mo ago | 9.8 | Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions. |
| 1mo ago | 9.8 | Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions. |
| 1mo ago | 9.9 | Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions. |
| 1mo ago | 10 | Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom Post Types Plugin for WordPress allows Remote Code Inclusion. This issue affects ACPT (Pro) - Custom Post Types Plugin for WordPress: from n/a through 2.0.47. |
| 1mo ago | 9.9 | Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions. |
| 1mo ago | 9.1 | Unauthenticated Broken Access Control in MetForm Pro <= 3.9.1 versions. |
| 1mo ago | 9.3 | Unauthenticated SQL Injection in WPJobster <= 6.3.5 versions. |
| 1mo ago | 9.3 | Unauthenticated SQL Injection in Tutor LMS Pro <= 3.9.6 versions. |
| 1mo ago | 9.9 | Subscriber Arbitrary File Upload in Restaurt <= 1.0.4 versions. |
| 1mo ago | 9.6 | Use after free in DigitalCredentials in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) |
| 1mo ago | 9.8 | A Path Traversal vulnerability affecting SOLIDWORKS Visualize from SOLIDWORKS Desktop Release 2024 through SOLIDWORKS Desktop Release 2026 could allow an attacker to write arbitrary files on the server. |
| 1mo ago | 9.8 | Unauthenticated Privilege Escalation in Support Ticket Management System <= 1.9 versions. |
| 1mo ago | 10 | Unauthenticated Arbitrary File Upload in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 versions. |
| 1mo ago | 9.8 | Unauthenticated PHP Object Injection in SeaFood Company <= 1.4 versions. |
| 1mo ago | 9.8 | Unauthenticated PHP Object Injection in Hot Coffee <= 1.7 versions. |
| 1mo ago | 9.9 | Subscriber Arbitrary File Upload in PT Luxa Addons <= 1.2.2 versions. |
| 1mo ago | 9.8 | Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions. |