SEPTEMBER 20, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

378,050 records on file
Page 405 of 12,602
CVE ID Score Description
3h ago
6.6

The Defender Security WordPress plugin before 6.2.0 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.

3h ago
7.2

The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.

3h ago
4.3

The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not check the user's capabilities before allowing a stock-update operation through one of its REST endpoints, allowing any authenticated user, such as a customer or subscriber, to change the stock quantity of arbitrary products.

3h ago
4.3

The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not verify that the requesting user owns the customer profile being queried through one of its REST endpoints, allowing any authenticated user (e.g. a customer/subscriber) to retrieve other users' personal data, including their email address, name, and roles.

3h ago
5.3

The Document Embedder WordPress plugin before 2.3.1 does not check a document's status before issuing a download token and streaming the file, allowing unauthenticated attackers to download arbitrary Document Embedder WordPress plugin before 2.3.1 documents, including private and draft ones, by enumerating IDs.

3h ago
3.5

The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting it on the coming-soon page, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to inject arbitrary web scripts that execute when a visitor views the page.

3h ago
7.2

The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one of its AJAX actions, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to update arbitrary WordPress options, including options that lead to privilege escalation to Administrator.

3h ago
4.8

The CMP WordPress plugin before 4.1.18 does not perform authorization checks on one of its AJAX actions and relies on a nonce that is skipped for certain (and exposed to anonymous visitors on others), allowing unauthenticated attackers to disable the site's maintenance/coming-soon mode under a non-default countdown configuration.

3h ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

3h ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

3h ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

3h ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

3h ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

3h ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

3h ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

3h ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

3h ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

3h ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

3h ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

3h ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

3h ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

3h ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

3h ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

3h ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

3h ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

Exploit 3h ago
7.3

A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_notes/teleport_notes/sync_notes/project_folder of the file src/index.ts. Executing a manipulation can lead to path traversal. It is possible to launch the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Exploit 3h ago
5.1

A logic vulnerability (fail-open condition) has been identified within the Metasploit Framework's JSON-RPC web service interface. When an exception occurs during the database health check (db.check) and the environment variable MSF_WS_JSON_RPC_API_TOKEN is not explicitly set, the application resets the internal state flag msf.auth_initialized to false. The ApiToken Warden authentication strategy misinterprets this false value as an indicator that authentication is not initialized or required, thereby granting unauthenticated local access to the JSON-RPC request dispatcher.

Exploit 3h ago
5.3

A vulnerability was detected in bsmi021 mcp-file-context-server 1.0.0. Affected by this issue is the function read_context of the file src/index.ts of the component Path Resolution. Performing a manipulation of the argument path results in path traversal. It is possible to initiate the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Exploit 3h ago
5.3

A security vulnerability has been detected in danielpopamd linkedin-ads-mcp 1.0.0. Affected by this vulnerability is the function fs.readFileSync of the file src/tools/campaign-management.ts of the component Media Upload. Such manipulation of the argument filePath leads to path traversal. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

3h ago
6.8

An out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a local  administrator to cause a system crash (BSOD) or BIOS corruption via a crafted software SMI (SW SMI) request with an oversized length value.Refer to the '  Security Update for ASUS FA507NV / FA507NU BIOS   ' section on the ASUS Security Advisory for more information.