OCTOBER 2, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

383,340 records on file
Page 905 of 12,778
CVE ID Score Description
27d ago
7.5

Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions.

27d ago
8.8

Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.

27d ago
7.3

Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions.

27d ago
7.5

Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions.

27d ago
9.3

Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.

27d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions.

27d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions.

27d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions.

27d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions.

27d ago
9.3

Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.

27d ago
9.8

Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.

27d ago
7.5

Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.

27d ago
5.3

Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions.

27d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions.

27d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions.

27d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions.

27d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.

27d ago
6.5

Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions.

Exploit 27d ago
9.1

Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered critical as it allows an unauthenticated attacker to obtain active session credentials and fully impersonate authenticated users, including administrators. Dell recommends customers to upgrade at the earliest opportunity.

Exploit 27d ago
9.1

OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query parameter alongside an absolute path, bypassing the workspace boundary check in resolveReadPathFromContext. Attackers can exploit the vacuous isPathWithinRoot guard to read sensitive files such as the JWT signing secret, SSH private keys, API credentials, and environment variables, enabling full authentication bypass by forging session cookies on password-protected deployments.

Exploit 27d ago
9.8

OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any allowlist, blocklist, or argument validation. The authentication middleware becomes a no-op when UI_PASSWORD is not configured, matching the default Docker deployment, enabling attackers to execute arbitrary OS commands as the application user and retrieve full command output including stdout, stderr, and exit code from the server response.

27d ago
7.5

Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3.

27d ago
7.5

Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue.

27d ago
9.1

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3

27d ago
5.3

Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions.

27d ago
5.3

Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.

27d ago
9.1

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

27d ago
—

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

27d ago
5.3

Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.

27d ago
5.9

Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions.