CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Especio <= 1.0 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Deliciosa <= 1.10.0 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Corbesier <= 1.15.0 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in CopyPress <= 1.4.5 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Ingenioso <= 1.14.0 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Iona <= 1.0.8 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in MaxiNet <= 1.2.10 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Nexio <= 1.10.0 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Planty <= 1.14.0 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in AirSupply <= 2.0.0 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Raider Spirit <= 1.1.2 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Rosaleen <= 2.8 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Modernee <= 1.6.0 versions. |
| 1mo ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Qreatix <= 1.9.4 versions. |
| 1mo ago | 7.5 | Subscriber Arbitrary Content Deletion in Brikk <= 3.0.0 versions. |
| 1mo ago | 7.7 | Subscriber Arbitrary File Deletion in WPBot Pro Wordpress Chatbot <= 13.6.5 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Learnify <= 1.15.0 versions. |
| 1mo ago | 8.8 | Subscriber Privilege Escalation in Sonaar <= 4.27.4 versions. |
| 1mo ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Sonaar <= 4.27.4 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in HomeRoofer <= 2.11.0 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Joly <= 1.22.0 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Neuronet < 1.14.0 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Geya <= 1.15 versions. |
| 1mo ago | 7.5 | Unauthenticated Arbitrary File Download in Premium Age Verification / Restriction for WordPress <= 3.0.2 versions. |
| Exploit 1mo ago | 7.8 | In multiple locations there is a possible provisioning bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. |
| Exploit 1mo ago | 8 | In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. |
| Exploit 1mo ago | 7.8 | In overrideConfig of CarrierConfigLoader.java, there is a possible way to bypass UID check due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. |
| 1mo ago | 7.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Folo allows Reflected XSS. This issue affects Themify Folo: from n/a through 1.9.6. |
| 1mo ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in my flatonica <= 0.0.8 versions. |
| Exploit 1mo ago | 8.3 | Missing Authorization vulnerability in Prince Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Integrate Google Drive: from n/a through 1.3.8. |