SEPTEMBER 22, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

148,259 records on file
Page 514 of 4,942
CVE ID Score Description
1mo ago
8.1

When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition serverTokens field and the AuthenticationFilter Custom Resource Definition extraAuthArgs field are rendered directly into NGINX configuration templates without sanitization or escaping. An authenticated attacker with permission to create or modify these Custom Resource Definitions may craft values that inject arbitrary NGINX configuration directives. This is a control plane issue; there is no data plane exposure from the vulnerability trigger itself. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Exploit 1mo ago
8.8

A stack-based buffer overflow exists in the raw_to_header() function in src/microtar.c in rxi microtar 0.1.0. The function copies the 100-byte name and linkname fields of a TAR header with strcpy() without guaranteeing null termination of the source. The POSIX ustar format permits these fixed-width fields to be fully populated with non-null bytes, so a crafted archive whose linkname field (followed by the trailing padding of the 512-byte raw header) contains no null terminator causes strcpy() to read past the end of the 512-byte raw header stack buffer and to write past the destination header buffer. A remote attacker who supplies a crafted TAR archive that the victim opens or parses (via mtar_open(), mtar_read_header(), or mtar_find()) can cause an out-of-bounds read and a stack buffer overflow, resulting in denial of service (crash) and potentially arbitrary code execution. Confirmed with AddressSanitizer: stack-buffer-overflow READ of size 356 in raw_to_header at src/microtar.c:112.

1mo ago
8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs Slimstat Analytics allows Blind SQL Injection. This issue affects Slimstat Analytics: from n/a through 5.4.11.

1mo ago
7.5

Improper Control of Generation of Code ('Code Injection') vulnerability in Monetizemore Advanced Ads allows Remote Code Inclusion. This issue affects Advanced Ads: from n/a through 2.0.21.

1mo ago
8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors allows PHP Local File Inclusion. This issue affects Motors: from n/a through 1.4.109.

1mo ago
8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force SureDash allows Blind SQL Injection. This issue affects SureDash: from n/a through 1.8.0.

Exploit 1mo ago
7.5

An integer overflow in the mtar_next() function in src/microtar.c in rxi microtar 0.1.0 allows a remote attacker to cause a denial of service (uncontrolled CPU consumption / infinite loop) via a crafted tar archive. mtar_next() computes the offset to the next record as round_up(h.size, 512) + sizeof(mtar_raw_header_t) using 32-bit arithmetic. When the header size field is a multiple of 512 in the range 0xFFFFFC01-0xFFFFFE00 (e.g. 0xFFFFFE00), the addition wraps to 0, so mtar_next() seeks to the current record position instead of advancing. As a result, mtar_find() and any loop that iterates entries with mtar_next() repeat indefinitely over the same record, hanging the process at 100% CPU with no recovery.

1mo ago
7.7

Contributor Arbitrary File Deletion in Fusion Builder <= 3.15.4 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in Kastell <= 2.0 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in Château <= 1.2.1 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in Zoya <= 1.4 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in Manufaktur Solutions <= 1.1.1 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions.

1mo ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Royal Elementor Addons Pro < 1.7.1041 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in Atomlab <= 2.4.5 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in Uppercase < 1.2.2 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in Konsept <= 1.9 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in Solene Core <= 2.3.2 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions.

Exploit 1mo ago
7.1

Zephyr's Bluetooth Classic Hands-Free Profile (HFP) Hands-Free role parser (subsys/bluetooth/host/classic/hfp_hf.c) contains an out-of-bounds write. During Service Level Connection setup the HF sends AT+CIND=? and parses the AG's +CIND: response in cind_handle(), which assigns a per-entry counter index and calls cind_handle_values() for each list element. cind_handle_values() then wrote hf->ind_table[index] = i without verifying that index is within the 20-element int8_t ind_table[] array of struct bt_hfp_hf. Because the parser places no cap on the number of +CIND: list entries, a remote Attendant Gateway (a malicious, compromised, or spoofed peer the device connects to over Bluetooth) can send a response with more than 20 recognized indicator entries and drive index arbitrarily large, writing a small attacker-positioned value past the array into adjacent struct fields (feature masks, SDP/version state, the calls[] array, work/atomic bookkeeping) and potentially beyond the static connection pool slot. This yields memory corruption and at least denial of service of the Bluetooth host, triggered by a single malformed AT response with no user interaction. The sibling consumer ag_indicator_handle_values() already performed the equivalent bounds check; this commit adds the same index >= ARRAY_SIZE(hf->ind_table) guard to close the gap. Affects builds with CONFIG_BT_HFP_HF enabled; introduced with the original HFP HF CIND parser (~v1.7) and present through v4.4.0.

Exploit 1mo ago
7.3

Missing Authorization vulnerability in EMV JobBank allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JobBank: from n/a through 1.2.3.

1mo ago
8.1

Unauthenticated Local File Inclusion in Line Agency <= 1.3.1 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in Etude <= 1.6 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in Eventicity <= 1.5 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in Gunslinger <= 1.7 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in Skyward <= 1.10 versions.