SEPTEMBER 21, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

169,884 records on file
Page 426 of 5,663
CVE ID Score Description
1mo ago
5.3

The Video Conferencing with Zoom plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.6.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to obtain the site's Zoom SDK API key and a freshly-signed JWT that can be used with the Zoom Web SDK to join any Zoom meeting associated with those credentials without a legitimate invitation.

1mo ago
6.6

A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path.

Exploit 1mo ago
5.6

A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit this heap buffer overflow vulnerability by providing a specially crafted MP3 file containing malformed ID3 tags. This incorrect length calculation during the parsing of performer tags can lead to a read beyond the allocated buffer, potentially causing a Denial of Service (DoS) due to a crash or enabling information disclosure.

Exploit 1mo ago
5.6

A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. This heap buffer overflow vulnerability occurs when processing specially crafted MP3 files containing malformed ID3v2.3 COMM (Comment) tags. An attacker could exploit this by providing a malicious MP3 file, leading to a denial of service (DoS), which causes an application crash, and potentially disclosing sensitive information from the heap memory.

Exploit 1mo ago
5.6

A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This vulnerability, a heap buffer overflow, occurs when processing specially crafted MP3 files. A remote attacker could exploit this by providing a malicious MP3 file, leading to a Denial of Service (DoS) where the application crashes. It may also potentially expose sensitive information from the system's memory.

1mo ago
5.6

A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially crafted MP3 files containing ID3v2.4 tags, a missing bounds check in the `extract_performers_tags` function can lead to a heap buffer overflow. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by triggering a read of unmapped memory. In some cases, it could also lead to information disclosure by reading visible heap data.

1mo ago
5.5

Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an attacker to disclose stored social login credentials via a crafted web entry pointing to a provider lookalike domain.

1mo ago
6.5

Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier

1mo ago
6.8

Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier

1mo ago
6.2

Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier

1mo ago
6.5

Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier

1mo ago
6.5

Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Exploit 1mo ago
6.1

Slim is a PHP micro framework that enables users to write simple web applications and APIs. In versions 4.4.0 through 4.15, if an application uses HttpException::setTitle() and/or setDescription() to include untrusted/request-derived data in the error title or description (e.g. "No products found matching '{$query}'."), an attacker could inject arbitrary HTML/JavaScript that executes in the victim's browser when they encounter an HTML error page generated by Slim. The vulnerability is present even with displayErrorDetails = false as the unescaped title and description are rendered on this error path. Built-in exceptions (HttpNotFoundException, HttpBadRequestException, etc.) ship plain-text defaults, so a vanilla Slim app with no user code is not exploitable. Only applications that feed untrusted data into setTitle() and/or setDescription() are affected. The issue has been fixed in 4.15.2. If developers are unable to immediately update their applications, they can work around this issue by avoiding passing untrusted/request-derived data into HttpException::setTitle() and setDescription() and using static, plain-text error copy instead. They should also register a custom error renderer (an ErrorRendererInterface implementation, or a subclass of HtmlErrorRenderer that escapes the title and description) for the HTML media type.

1mo ago
6.5

Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions.

1mo ago
6.5

Subscriber Cross Site Scripting (XSS) in FV Flowplayer Video Player < 7.5.51.7212 versions.

1mo ago
4.7

Unauthenticated Cross Site Request Forgery (CSRF) in WP Migrate Lite <= 2.7.8 versions.

1mo ago
6.5

Subscriber Sensitive Data Exposure in XCloner <= 4.8.6 versions.

1mo ago
6.5

Unauthenticated Broken Access Control in JS Help Desk <= 3.0.9 versions.

1mo ago
6.5

Subscriber Cross Site Scripting (XSS) in WP Job Portal <= 2.5.2 versions.

1mo ago
6.5

Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.4.1 versions.

1mo ago
6.5

Subscriber Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.62 versions.

Exploit 1mo ago
4.3

MultiJuicer is used to run separate Juice Shop instances on a central kubernetes cluster without the need for local instances. In versions 8.0.0 through 10.0.0, the team join endpoint (POST /multi-juicer/api/teams/{team}/join) accepted requests with any Content-Type, including text/plain. Because that content type does not trigger a CORS preflight, an attacker could host a cross-site HTML form that auto-submits to the endpoint and forces a victim's browser to log in as the attacker's team. A successful, undetected attacker can cause victims to unwittingly solve Juice Shop challenges under the attacker's team identity. In a CTF context this lets the attacker inflate their team's score using other players' activity, and any sensitive data the victim enters into "their" Juice Shop ends up in the attacker's instance. The vulnerability is exploitable without any prior authentication; the victim only needs to visit a page the attacker controls while having network access to the MultiJuicer deployment. SameSite=Strict on the session cookie does not mitigate this, because the attack plants a new cookie rather than relying on an existing one. This issue was fixed in version 10.0.1.

1mo ago
6.5

Unauthenticated Bypass Vulnerability in Stripe Payments <= 2.0.98 versions.

1mo ago
6.5

Unauthenticated Broken Authentication in Masteriyo - LMS <= 2.1.8 versions.

1mo ago
6.5

Subscriber Cross Site Scripting (XSS) in Modula Image Gallery <= 2.14.23 versions.

1mo ago
6.5

Unauthenticated Cross Site Scripting (XSS) in Simple Membership <= 4.7.2 versions.

1mo ago
6.5

Unauthenticated Bypass Vulnerability in Event Tickets <= 5.27.5 versions.

1mo ago
6.5

Subscriber Sensitive Data Exposure in Contest Gallery <= 28.1.7 versions.

1mo ago
6.5

Subscriber Broken Access Control in Advanced Form Integration <= 1.126.12 versions.

1mo ago
5.3

Unauthenticated Other Vulnerability Type in Contest Gallery <= 28.1.7 versions.