SEPTEMBER 25, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

380,376 records on file
Page 705 of 12,680
CVE ID Score Description
13d ago
—

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate to CVE-2026-13610.

Exploit 13d ago
7.5

crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in RubyLLM::Utils.underscore on Ruby 3.1.x. A very long crafted class, agent, or tool name can cause excessive CPU consumption and a denial of service.

Exploit 13d ago
5.4

basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager and Prometheus proxy controllers. An unauthenticated attacker can induce a logged-in user's browser to submit requests that are forwarded to enabled upstream write or management endpoints, such as creating an Alertmanager silence or requesting a Prometheus reload. The final impact depends on the APIs enabled by the upstream services.

Exploit 13d ago
8.4

amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep. A specially named method containing Ruby interpolation syntax can be interpolated into a dynamically constructed eval string when grep is called with a block, resulting in Ruby code execution in the host process. Exploitation requires an application path that allows an attacker to influence dynamic method names.

13d ago
7.2

Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions.

13d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover <= 1.6.1 versions.

13d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in SureDash <= 1.10.1 versions.

13d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions.

13d ago
6.5

Subscriber Broken Access Control in Motors <= 1.4.113 versions.

13d ago
9.8

Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions.

13d ago
6.3

Unauthenticated Broken Access Control in Anti Spam and list cleaner &#8211; AcyChecker <= 2.0.0 versions.

13d ago
6.5

Customer Cross Site Scripting (XSS) in WpBookingly <= 1.3.2 versions.

13d ago
7.7

Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions.

13d ago
6.5

Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions.

13d ago
8.5

Subscriber SQL Injection in Reviewer <= 3.14.2 versions.

13d ago
8.1

Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions.

13d ago
8.1

Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions.

13d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce <= 1.30.36 versions.

13d ago
6

Subscriber Server Side Request Forgery (SSRF) in Vehica Core <= 1.0.104 versions.

13d ago
8.1

Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions.

13d ago
9.3

Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions.

13d ago
9.3

Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions.

13d ago
6.5

Subscriber Cross Site Scripting (XSS) in Accordion <= 3.0.6 versions.

13d ago
7.5

Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions.

13d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versions.

13d ago
6.5

Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions.

13d ago
7.5

Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.1 versions.

13d ago
9.8

Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.

13d ago
6.5

Unauthenticated Broken Access Control in Internal Link Optimiser <= 5.2.7 versions.

13d ago
7.5

Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions.