CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| Exploit 5d ago | 10 | A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the argument Server results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be used. |
| Exploit 5d ago | 6.3 | A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile (AVRCP) implementation allows a malicious Bluetooth device within range to cause an out-of-bounds memory read. This vulnerability, affecting the parse_media_element() and parse_media_folder() functions, can lead to a crash of the bluetoothd daemon, resulting in a Denial of Service (DoS). It could also potentially expose sensitive heap memory contents. Exploitation requires user interaction to pair with the malicious device. |
| 5d ago | 9.3 | Unauthenticated SQL Injection in Readabler < 2.0.18 versions. |
| 5d ago | 8.8 | Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection. This issue affects TaxoPress: from n/a through 3.51.0. |
| 5d ago | 5.3 | Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions. |
| 5d ago | 5.3 | Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17.22 versions. |
| 5d ago | 5.3 | Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions. |
| 5d ago | 4.3 | Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions. |
| 5d ago | 5.4 | Subscriber Broken Access Control in Gravity Booster – Styles & Layouts for Gravity Forms <= 6.0 versions. |
| 5d ago | 4.3 | Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions. |
| 5d ago | 7.5 | Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions. |
| 5d ago | 9.8 | Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions. |
| 5d ago | 5.4 | Subscriber Broken Authentication in User Registration <= 5.2.6 versions. |
| 5d ago | 7.5 | Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions. |
| Exploit 5d ago | 4.6 | Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix is vulnerable to cross-site scripting when a data-trix-serialized-attributes attribute bypasses the DOMPurify sanitizer. An attacker can craft HTML containing a data-trix-serialized-attributes attribute with a malicious payload that, when rendered, executes arbitrary JavaScript in the user's session and may perform unauthorized actions or disclose sensitive information. This issue is fixed in version 2.1.17. |
| 5d ago | 6.5 | Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions. |
| 5d ago | 8.1 | Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions. |
| 5d ago | 6.5 | Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions. |
| 5d ago | 6.5 | Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions. |
| 5d ago | 9.8 | Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions. |
| 5d ago | 7.1 | Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions. |
| 5d ago | 6.5 | Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions. |
| 5d ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions. |
| 5d ago | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate to CVE-2026-12965. |
| 5d ago | 4.9 | Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions. |
| 5d ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions. |
| 5d ago | 9.1 | Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions. |
| 5d ago | 9.8 | Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions. |
| 5d ago | 6.5 | Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions. |
| 5d ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions. |