CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| Exploit 2h ago | 9.3 | Authorization Bypass Through User-Controlled Key in the supplier API in Roskus Prospero Flow CRM 4.0.0 through 5.3.1 allows any authenticated user to read and modify another company's supplier record, and to reassign it to their own company, via a PUT request to /api/supplier/{id} setting company_id in the body. |
| Exploit 2h ago | 7.3 | A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=confirm_order. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. |
| 2h ago | 4.3 | HCL Hive is affected by an information exposure vulnerability where Swagger documentation was found exposed publicly. Although no sensitive information (e.g., credentials, PII) was discovered, exposing API documentation to unauthenticated users can increase the overall attack surface. |
| 2h ago | 7.2 | HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unauthorized user to introduce unverified, malicious, or broken code directly into production environments. |
| 2h ago | 6.5 | A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted as trust anchors for TLS connections. In non-default configurations where certificate revocation checking is disabled, this could allow a man-in-the-middle attacker to forge certificates accepted by PKI client connections. |
| 2h ago | 5.3 | Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 versions. |
| 2h ago | 6.5 | Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions. |
| 2h ago | 4.3 | Unauthenticated Cross Site Request Forgery (CSRF) in Hash Form <= 1.4.0 versions. |
| 2h ago | 5.4 | Unauthenticated Cross Site Request Forgery (CSRF) in Fluent Support Pro <= 2.3.1 versions. |
| 2h ago | 5.3 | Subscriber Insecure Direct Object References (IDOR) in Fluent Boards Pro <= 2.0.11 versions. |
| 2h ago | 4.9 | Subscriber Server Side Request Forgery (SSRF) in FluentCRM Pro <= 3.1.12 versions. |
| 2h ago | 5.4 | Subscriber Broken Access Control in Fluent Support Pro <= 2.3.1 versions. |
| 2h ago | 7.6 | Author SQL Injection in FluentCRM Pro <= 3.1.12 versions. |
| 2h ago | 6.4 | Contributor Server Side Request Forgery (SSRF) in Shared Files <= 1.7.69 versions. |
| 2h ago | 5.3 | Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.5 versions. |
| Exploit 2h ago | 7.3 | A vulnerability has been found in itsourcecode Online Clinic Management System 1.0. This vulnerability affects unknown code of the file success/login.php of the component Admin Login. The manipulation of the argument Username leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. |
| 2h ago | 7.1 | Firmware in KAON PG5298A and PG5298B routers allow an unauthenticated user to query a specific endpoint and acquire sensitive information such as a password to the administrative portal. This vulnerability has been fixed in firmware version: 3.0.82 for PG5298A and 4.0.82 for PG5298B. |
| 2h ago | 8.1 | Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions. |
| 2h ago | 8.1 | Unauthenticated Local File Inclusion in Måne <= 1.7 versions. |
| 2h ago | 9.8 | Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions. |
| 2h ago | 9.8 | Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions. |
| 2h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions. |
| 2h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions. |
| 2h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 2.9.5.6 versions. |
| 2h ago | 9.8 | Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions. |
| 2h ago | 7.5 | Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions. |
| 2h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions. |
| 2h ago | 9.8 | Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions. |
| 2h ago | 9.3 | Unauthenticated SQL Injection in Woo Essential <= 4.3.0 versions. |
| 2h ago | 8.5 | Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions. |