CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 4h ago | 8.8 | Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a privileged context. |
| Exploit 4h ago | 8.4 | A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Client Connector on Android and ChromeOS. |
| Exploit 4h ago | 8.8 | A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of Zscaler Client Connector on Windows. |
| Exploit 4h ago | 7.8 | A local privilege escalation vulnerability exists in the Restricted Access (Kiosk) Mode implementation of Scheidt & Bachmann entervo HMI prior to V2 R5 P0 M5. The vulnerability affects the external PDF viewer functionality used to display the application manual and its interaction with the underlying Windows operating system. An authenticated low-privileged user can escape the kiosk environment by opening the application manual in the external PDF viewer and abusing the print functionality. Successful exploitation allows execution of arbitrary commands outside the kiosk environment with local administrator privileges. |
| 4h ago | 7.4 | HCL Hive is affected by a cryptographic primitive with a risky implementation which could allow an attacker unauthorized lateral compromise or widespread credential leakage if a single internal component is breached. |
| Exploit 4h ago | 7.3 | A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=confirm_order. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. |
| 4h ago | 7.2 | HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unauthorized user to introduce unverified, malicious, or broken code directly into production environments. |
| 4h ago | 7.6 | Author SQL Injection in FluentCRM Pro <= 3.1.12 versions. |
| Exploit 4h ago | 7.3 | A vulnerability has been found in itsourcecode Online Clinic Management System 1.0. This vulnerability affects unknown code of the file success/login.php of the component Admin Login. The manipulation of the argument Username leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. |
| 4h ago | 7.1 | Firmware in KAON PG5298A and PG5298B routers allow an unauthenticated user to query a specific endpoint and acquire sensitive information such as a password to the administrative portal. This vulnerability has been fixed in firmware version: 3.0.82 for PG5298A and 4.0.82 for PG5298B. |
| 4h ago | 8.1 | Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions. |
| 4h ago | 8.1 | Unauthenticated Local File Inclusion in Måne <= 1.7 versions. |
| 4h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions. |
| 4h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions. |
| 4h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 2.9.5.6 versions. |
| 4h ago | 7.5 | Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions. |
| 4h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions. |
| 4h ago | 8.5 | Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions. |
| 4h ago | 8.6 | Unauthenticated Arbitrary File Deletion in ShopBuilder Pro – Elementor WooCommerce Builder Addons <= 2.2.0 versions. |
| 4h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Brave Conversion Engine (PRO) <= 0.8.6 versions. |
| 4h ago | 8.5 | Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions. |
| 4h ago | 7.1 | Subscriber Broken Access Control in ProLancer Element <= 1.4.8 versions. |
| 4h ago | 8.6 | Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions. |
| 4h ago | 7.5 | Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions. |
| 4h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions. |
| 4h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions. |
| 4h ago | 7.5 | Unauthenticated Broken Access Control in Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More <= 1.7.1 versions. |
| 4h ago | 8.1 | Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions. |
| 4h ago | 8.1 | Unauthenticated Local File Inclusion in Tonda < 2.6 versions. |
| 4h ago | 8.5 | Firmware in KAON PG5298A and PG5298B routers allow an authenticated user to send crafted JSON-RPC requests and perform operations not possible via GUI, e.g. system file read or command execution. This vulnerability has been fixed in firmware version: 3.0.82 for PG5298A and 4.0.82 for PG5298B. |