SEPTEMBER 21, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

378,159 records on file
Page 514 of 12,606
CVE ID Score Description
3d ago
9.8

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Faydam Innovation Inc. FAYDAM Datalogger allows SQL Injection. This issue affects FAYDAM Datalogger: from 2.7.1 before 2.8.0.

Exploit 3d ago
8.8

Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAliases handling that allows attackers with commit access to execute arbitrary commands. Attackers can manipulate registryAliases keys with unquoted shell metacharacters to inject commands executed during helm repo add operations, gaining full access to Renovate's execution environment.

Exploit 3d ago
7.5

Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps, may expose the bot's authorization token in server or pipeline logs because the git http.extraheader=AUTHORIZATION parameter is logged without redaction. Anyone with access to saved logs could obtain the bot credentials. Fixed in 23.25.1; Azure DevOps users should revoke and regenerate credentials if logs may have been exposed.

Exploit 3d ago
7.5

Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repository tokens into pull request comments during certain Go Modules update failure scenarios. The issue is fixed in version 19.38.7. Anyone able to view the affected pull request comments could obtain the exposed tokens.

3d ago
7.5

A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request that carries a CockpitLang cookie, allowing a remote unauthenticated attacker to exhaust memory on the host and cause a denial of service.

3d ago
7.5

Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions.

3d ago
9.3

Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.

3d ago
9.8

Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.

3d ago
9.8

Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.

3d ago
9.3

Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions.

3d ago
8.1

Unauthenticated Local File Inclusion in Resido <= 1.5 versions.

3d ago
7.5

Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions.

3d ago
7.5

Unauthenticated Broken Access Control in Outranking Plugin Options <= 1.1.3 versions.

3d ago
7.5

Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.

3d ago
9.8

Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.

3d ago
6.5

Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce < 2.0.8 versions.

3d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate IDX <= 3.2.8 versions.

3d ago
9.8

Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.

3d ago
9.3

Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.

3d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Global Gallery <= 11.1.2 versions.

3d ago
9.3

Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.

3d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in BBQ Pro <= 3.9 versions.

Exploit 3d ago
10

Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) The form's optional custom-PHP post-submission handler is executed via eval(). The [URL parameter = X] shortcode is substituted with the raw, unescaped value of a query parameter, letting an unauthenticated attacker inject arbitrary PHP that executes server-side. The CSRF token needed to reach the endpoint is itself disclosed anonymously via a separate task, so it provides no real protection. Exploitability requires the form to have a custom-PHP handler configured (a documented builder feature) referencing that shortcode, and no reCAPTCHA on the submit button.

3d ago
7.7

Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The stripeCharges and payAuthorize endpoints accept the charge total from a client-controlled request parameter and forward it to the payment gateway without recomputing it from the form's configured product prices. Neither endpoint enforces authentication or CSRF checks. An unauthenticated attacker can purchase any priced item for an arbitrary amount (e.g., $0.01), and can additionally forge line items, quantities, and shipping.

3d ago
8.5

Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions.

Exploit 3d ago
9.8

Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.

3d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 versions.

3d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions.

3d ago
8.5

Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions.

3d ago
9.8

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.