CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| Exploit 5d ago | 2 | Pyenv provides simple Python version management. Prior to 2.8.0, is_version_safe() in libexec/pyenv-version-file-read accepts shell glob metacharacters in .python-version values, and unquoted PYENV_VERSION expansion in libexec/pyenv-version-name, libexec/pyenv-which, libexec/pyenv-prefix, libexec/pyenv-local, libexec/pyenv-global, libexec/pyenv-version, and libexec/pyenv-versions pathname-expands the value against the current directory, allowing a matching attacker-controlled file to silently select a different installed interpreter or version. This issue is fixed in version 2.8.0. |
| 5d ago | 6.3 | Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions. |
| 5d ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 1.0.1 versions. |
| 5d ago | 6.5 | Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 versions. |
| Exploit 5d ago | 8.8 | A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions to annotate the namespaced ManagedClusterAddOn resource can override the governance-policy container image. This allows an attacker to run a controlled image with cluster-admin privileges on the managed cluster, leading to arbitrary code execution and privilege escalation. |
| 5d ago | 6.5 | Unauthenticated Broken Access Control in Appointment Hour Booking <= 1.5.91 versions. |
| 5d ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions. |
| 5d ago | 6.5 | Unauthenticated Broken Access Control in MultiVendorX <= 5.0.14 versions. |
| 5d ago | 6.5 | Contributor Cross Site Scripting (XSS) in WP Tab Widget <= 1.2.11 versions. |
| 5d ago | 6.5 | Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions. |
| 5d ago | 6.5 | Contributor Cross Site Scripting (XSS) in Typing Effect <= 1.3.7 versions. |
| 5d ago | 6.5 | Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions. |
| 5d ago | 6.5 | Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions. |
| 5d ago | 6.5 | Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions. |
| 5d ago | 6.5 | Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions. |
| 5d ago | 6.5 | Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions. |
| 5d ago | 6.5 | Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions. |
| 5d ago | 6.5 | Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions. |
| 5d ago | 7.4 | Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions. |
| 5d ago | 4.3 | Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= 2.0.2.2.3 versions. |
| 5d ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions. |
| 5d ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions. |
| 5d ago | 9.9 | Unrestricted Upload of File with Dangerous Type vulnerability in EDGE22 Studios Ltd. GP Premium allows Remote Code Inclusion. This issue affects GP Premium: from n/a through 2.5.5. |
| 5d ago | 7.5 | Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions. |
| 5d ago | 7.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MapSteps UG Ultimate Dashboard Pro allows DOM-Based XSS. This issue affects Ultimate Dashboard Pro: from n/a through 3.11.2. |
| 5d ago | 7.2 | Editor PHP Object Injection in OptionTree <= 2.7.3 versions. |
| Exploit 5d ago | 7.5 | Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options. |
| Exploit 5d ago | 8.8 | Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a use-after-free when one consumer is deleted while another still references the shared NACK and potentially allowing remote code execution. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1. |
| Exploit 5d ago | 3.3 | Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0, onnx.version_converter.convert_version() can perform an out-of-bounds read in Gemm_7_6::adapt_gemm_7_6() in onnx/version_converter/adapters/gemm_7_6.h when a Gemm node has input tensors with fewer than two dimensions because B_shape[1], A_shape[0], or A_shape[1] is accessed without a rank check, potentially causing a process crash during an opset 7 to 6 downgrade. This issue is fixed in version 1.22.0. |
| Exploit 5d ago | 8.8 | Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation. |