SEPTEMBER 22, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

148,259 records on file
Page 517 of 4,942
CVE ID Score Description
1mo ago
8.1

Unauthenticated Local File Inclusion in Hitek < 1.8.3 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in Micdrop <= 1.3.1 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in Mildhill <= 1.5 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in Mr. SEO <= 2.0 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in Santé <= 1.5.1 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in Malmö <= 2.2 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in NeoBeat <= 1.7 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in Fidalgo <= 1.2.2 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in Aperitif <= 1.5 versions.

1mo ago
7.1

Unauthenticated Cross Site Scripting (XSS) in MagOne <= 9.0 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in Getaway < 1.8 versions.

1mo ago
7.6

Subscriber Privilege Escalation in MultiLoca <= 4.2.15 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in Zermatt <= 1.6.1 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in Mikado Core <= 1.6 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in Solene <= 3.4 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in Kapee < 1.7.0 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in EmallShop <= 2.4.21 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in Softlab Core < 1.2.11 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in Integrio Core < 1.2.8 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in Thegov Core < 2.0.23 versions.

1mo ago
7.5

Unauthenticated Sensitive Data Exposure in Bricksforge <= 3.1.8.4 versions.

Exploit 1mo ago
7.8

In Telecomm, there is a possible way to initiate an unauthorized phone call due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

1mo ago
8.6

Unauthenticated Arbitrary File Deletion in BookPro <= 1.1.0 versions.

1mo ago
8.1

Unauthenticated Broken Authentication in Booknetic <= 4.8.5 versions.

1mo ago
8.6

Unauthenticated Broken Access Control in WordPress Dating Theme <= 11.2.0 versions.

1mo ago
8.8

Unauthenticated Cross Site Request Forgery (CSRF) in WordPress Dating Theme <= 11.2.0 versions.

1mo ago
7.1

Unauthenticated Cross Site Scripting (XSS) in WPJobster <= 6.3.5 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in EcoBlue <= 1.15 versions.

1mo ago
8.5

Subscriber SQL Injection in WooCommerce Frontend Manager – Ultimate < 6.7.7 versions.