SEPTEMBER 21, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

148,198 records on file
Page 483 of 4,940
CVE ID Score Description
1mo ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Responsive Lightbox <= 2.7.6 versions.

1mo ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Gutenverse Form <= 2.4.7 versions.

1mo ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Quick Interest Slider <= 3.1.6 versions.

1mo ago
8.8

Contributor Privilege Escalation in Frisbii Pay <= 1.8.2 versions.

1mo ago
8.6

Unauthenticated Multiple Vulnerabilities in BitFire Security <= 5.0.3 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions.

1mo ago
7.5

Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2.7.4 versions.

1mo ago
7.5

Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions.

1mo ago
7.1

Unauthenticated Cross Site Scripting (XSS) in MapPress Maps for WordPress <= 2.97.3 versions.

1mo ago
8.8

Subscriber Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.

1mo ago
8.8

Contributor Privilege Escalation in Fusion Builder <= 3.15.4 versions.

1mo ago
7.5

Unauthenticated Broken Access Control in Stylish Cost Calculator <= 8.3.9 versions.

1mo ago
7.5

Unauthenticated Broken Access Control in Syncee Premium Dropshipping &amp; Wholesale <= 1.0.27 versions.

1mo ago
7.3

Unauthenticated Broken Access Control in Newsletters <= 4.13 versions.

1mo ago
7.5

Unauthenticated Sensitive Data Exposure in Trinity Backup &#8211; Backup, Migrate, Restore, Clone &amp; Schedule Backups <= 2.0.9 versions.

1mo ago
7.5

Unauthenticated Broken Access Control in Intranet &amp; Private Site &#8211; All-In-One Intranet <= 1.8.1 versions.

1mo ago
7.5

Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions.

1mo ago
7.5

Unauthenticated Sensitive Data Exposure in Object Cache 4 everyone <= 2.3.2 versions.

1mo ago
7.4

Unauthenticated Backdoor in Enable CORS <= 2.0.3 versions.

1mo ago
7.5

Unauthenticated Broken Access Control in Gutenverse Companion <= 2.5.0 versions.

1mo ago
7.6

Subscriber Insecure Direct Object References (IDOR) in SupportCandy <= 3.4.6 versions.

1mo ago
7.5

Unauthenticated Sensitive Data Exposure in Ads by WPQuads <= 3.0.3 versions.

1mo ago
7.8

The KTLS receive path decrypted each record in place, assuming that the mbufs holding received data were anonymous and safe to modify. This assumption does not hold for data placed on a socket by sendfile(2), which can reference file-backed memory directly through non-anonymous M_EXTPG pages or EXT_SFBUF mbufs. When the sender transmits such data over a loopback connection without enabling KTLS on the transmit side, the file-backed mbufs reach the receiver's decryption path unchanged. Decrypting a record in place then overwrites the backing file's page cache instead of a private copy of the data. An unprivileged local user who can read a file can overwrite its contents with data of their choosing by sending the file over a loopback connection on which they have enabled KTLS receive. The write modifies the page cache directly, so it bypasses file flags such as schg and is written back to disk. By overwriting a setuid binary or other trusted file, a local user can escalate privileges, potentially gaining full control of the affected system.

1mo ago
7.5

An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via supplying a crafted PSD file.

1mo ago
7.5

Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions.

1mo ago
7.5

Contributor Local File Inclusion in Splash - Sport Club WordPress Theme for Basketball, Football, Hockey <= 4.4.3 versions.

1mo ago
8.8

Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions.

1mo ago
7.7

Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certain /rest/o/{orgId} endpoints.

1mo ago
7.3

It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users are recommended to upgrade to version 2.1.2, which fixes this issue.

Exploit 1mo ago
8

Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-powermax v2.16.0, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.