CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 1h ago | 9.3 | Unauthenticated SQL Injection in Readabler < 2.0.18 versions. |
| 1h ago | 9.8 | Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions. |
| 1h ago | 9.8 | Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions. |
| 1h ago | 9.1 | Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions. |
| 1h ago | 9.8 | Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions. |
| 1h ago | 9.8 | Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions. |
| 1h ago | 9.8 | Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions. |
| 1h ago | 9.3 | Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions. |
| 1h ago | 9.3 | Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions. |
| Exploit 1h ago | 10 | Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions. |
| 1h ago | 9.8 | Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions. |
| 1h ago | 9.3 | Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions. |
| 1h ago | 9.3 | Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions. |
| 1h ago | 9.9 | Unrestricted Upload of File with Dangerous Type vulnerability in EDGE22 Studios Ltd. GP Premium allows Remote Code Inclusion. This issue affects GP Premium: from n/a through 2.5.5. |
| Exploit 1h ago | 9.8 | Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without verifying genuine internal Promise resolver records, causing deserialization side effects with plugins enabled and potentially unintended server-side invocation or remote code execution when downstream frameworks register callable wrappers. This issue is fixed in version 1.5.3. |
| 1h ago | 9.9 | Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions. |
| 1h ago | 9.8 | Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. |
| 1h ago | 9.9 | Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions. |
| Exploit 1h ago | 9.9 | Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions. |
| 1h ago | 9.6 | Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions. |
| 1h ago | 10 | Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 140.15, and Thunderbird 153.2. |
| Exploit 1h ago | 9.6 | A security vulnerability has been detected in TRENDnet TEW-WLC100P 12.07b01. Affected by this vulnerability is an unknown functionality of the file /sbin/netifd of the component DHCP blobmsg Handler. The manipulation leads to stack-based buffer overflow. The attack must be carried out from within the local network. The exploit has been disclosed publicly and may be used. |
| Exploit 1h ago | 9.8 | Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. |
| Exploit 1h ago | 9.8 | Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154 and Thunderbird 154. |
| Exploit 1h ago | 9.8 | Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
| Exploit 1h ago | 9.8 | Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. |
| 1h ago | 9.1 | Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
| 1h ago | 9.8 | Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
| 1h ago | 9.8 | Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
| 1h ago | 9.8 | Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. |