SEPTEMBER 23, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

378,884 records on file
Page 581 of 12,630
CVE ID Score Description
Exploit 5d ago
10

A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the argument Server results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be used.

Exploit 5d ago
6.3

A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile (AVRCP) implementation allows a malicious Bluetooth device within range to cause an out-of-bounds memory read. This vulnerability, affecting the parse_media_element() and parse_media_folder() functions, can lead to a crash of the bluetoothd daemon, resulting in a Denial of Service (DoS). It could also potentially expose sensitive heap memory contents. Exploitation requires user interaction to pair with the malicious device.

5d ago
9.3

Unauthenticated SQL Injection in Readabler < 2.0.18 versions.

5d ago
8.8

Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection. This issue affects TaxoPress: from n/a through 3.51.0.

5d ago
5.3

Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions.

5d ago
5.3

Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17.22 versions.

5d ago
5.3

Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions.

5d ago
4.3

Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions.

5d ago
5.4

Subscriber Broken Access Control in Gravity Booster &#8211; Styles &amp; Layouts for Gravity Forms <= 6.0 versions.

5d ago
4.3

Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions.

5d ago
7.5

Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions.

5d ago
9.8

Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.

5d ago
5.4

Subscriber Broken Authentication in User Registration <= 5.2.6 versions.

5d ago
7.5

Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions.

Exploit 5d ago
4.6

Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix is vulnerable to cross-site scripting when a data-trix-serialized-attributes attribute bypasses the DOMPurify sanitizer. An attacker can craft HTML containing a data-trix-serialized-attributes attribute with a malicious payload that, when rendered, executes arbitrary JavaScript in the user's session and may perform unauthorized actions or disclose sensitive information. This issue is fixed in version 2.1.17.

5d ago
6.5

Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.

5d ago
8.1

Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.

5d ago
6.5

Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.

5d ago
6.5

Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.

5d ago
9.8

Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.

5d ago
7.1

Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.

5d ago
6.5

Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions.

5d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions.

5d ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate to CVE-2026-12965.

5d ago
4.9

Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions.

5d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions.

5d ago
9.1

Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.

5d ago
9.8

Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.

5d ago
6.5

Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.

5d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions.