SEPTEMBER 18, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

169,699 records on file
Page 179 of 5,657
CVE ID Score Description
1d ago
6.5

Unauthenticated Broken Access Control in Appointment Hour Booking <= 1.5.91 versions.

1d ago
6.5

Unauthenticated Broken Access Control in MultiVendorX <= 5.0.14 versions.

1d ago
6.5

Contributor Cross Site Scripting (XSS) in WP Tab Widget <= 1.2.11 versions.

1d ago
6.5

Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions.

1d ago
6.5

Contributor Cross Site Scripting (XSS) in Typing Effect <= 1.3.7 versions.

1d ago
6.5

Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions.

1d ago
6.5

Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions.

1d ago
6.5

Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions.

1d ago
6.5

Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions.

1d ago
6.5

Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions.

1d ago
6.5

Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions.

1d ago
6.5

Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions.

1d ago
4.3

Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= 2.0.2.2.3 versions.

Exploit 1d ago
6.5

yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(), XXHashFactory.nativeInstance().newStreamingHash32().update(), and XXHashFactory.nativeInstance().newStreamingHash64().update(), allowing null arrays or oversized ranges to reach native code, read outside the Java array, and fatally terminate the JVM. This issue is fixed in version 1.11.1.

Exploit 1d ago
5.9

goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token's `DownloadLimit` under `RLock`, releases the lock, serves the file, then re-acquires the lock to increment the counter. Concurrent requests all read the same `Downloaded`/`DownloadLimit` snapshot, all pass the check, and all are served — exceeding the operator's intended cap. Version 2.1.0 patches the issue.

1d ago
6

Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions.

Exploit 1d ago
6

The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0. This behavior would cause mismatches when processing domain names using IDNA 2003 (the "idna" codec) and the in_table_b2() function of the "stringprep" module. This only affects domain names containing characters that were not previously registered or had their Unicode attributes such as case-folding behavior updated since Unicode 3.2.0.

1d ago
6.8

Race condition in the JavaScript Engine component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

1d ago
6.5

Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.

1d ago
6.5

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

1d ago
5.4

Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.

1d ago
5.4

Same-origin policy bypass in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

1d ago
4.2

Race condition, use-after-free in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

1d ago
4.3

Information disclosure in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

1d ago
4.3

Information disclosure in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

1d ago
5.4

Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

1d ago
5.4

Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

1d ago
5.4

Same-origin policy bypass in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

1d ago
5.4

Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

1d ago
6.5

Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154.