OCTOBER 6, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

150,489 records on file
Page 1 of 5,017
CVE ID Score Description
Exploit 6h ago
8.8

Craft CMS 5.10.13.2 contains an authenticated remote code execution vulnerability in the Control Panel action app/render-components. Any authenticated user with basic Control Panel access can submit request-controlled component classes and property overrides. By first overriding an EntryType object’s uiLabelFormat and then rendering an Entry that resolves the same request-cached entry type, an attacker can cause arbitrary Twig supplied in the request to be evaluated by renderObjectTemplate(). This render path is not sandboxed. A Twig string callable can therefore reach PHP functions such as system(), resulting in operating-system command execution with the privileges of the PHP/web-server process. The issue was reproduced with an active non-admin Craft Team user with no optional permissions enabled. No access to entry-editing, Settings, utility, user-management, project-config, filesystem, Kubernetes, or environment variables was required.

Exploit 6h ago
7.5

CVE-2026-103831: Insecure deserialization vulnerability in the Psr16CacheAdapter component of the TrueLayer Magento 2 Plugin, due to the use of PHP's native unserialize() function without restrictions on the classes allowed when retrieving data stored in the cache. An attacker who already has the ability to write manipulated data to the cache backend used by Magento—such as Redis or Memcached—could inject specially crafted PHP objects and trigger their deserialization, potentially leading to arbitrary code execution via gadget strings available in the application environment. Exploitation therefore requires a prerequisite condition that allows writing to the cache infrastructure, either through access to the local file system or to a cache infrastructure accessible from the Magento environment.

6h ago
7

In the WibuKey driver for Windows below Version 6.72, insufficient validation of user input when calculating the size of a kernel buffer could cause small amounts of data to be written outside the intended kernel buffer. This can lead to a system crash. Under unfavorable circumstances, adjacent kernel memory may be modified.

6h ago
8.1

Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 4.0.0 versions.

6h ago
7.3

Unauthenticated Broken Access Control in BEAR <= 1.2.2 versions.

Exploit 6h ago
8.2

Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking vulnerability in danielberkompas cloak allows an attacker with write access to stored ciphertext to make it decrypt to a chosen value via bit flipping. Cloak.Ciphers.AES.CTR encrypts with AES-256 in CTR mode and stores the key tag, the IV and the ciphertext with no MAC. decrypt/2 checks only the key tag and the minimum length before it returns the plaintext, and Cloak.Ciphers.Deprecated.AES.CTR decrypts the legacy format the same way. CTR is a stream cipher, so a value XORed into the stored ciphertext is XORed into the plaintext at the same offset. An attacker who can write to the encrypted store (for example through SQL injection or a compromised replica) and who knows or can guess a stored plaintext can replace it with any value of the same length. The application receives that value with no error. This issue affects cloak: from 0.1.0-pre onward.

6h ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack <= 6.2.13 versions.

6h ago
7.5

Unauthenticated Broken Access Control in The7 <= 14.2.2 versions.

6h ago
8.8

Subscriber Broken Access Control in Progress Planner <= 1.10.0 versions.

Exploit 6h ago
7.8

SQL injection (SQLi) vulnerability in the eLoanApp application, specifically in the POST parameter 'logina' of the user process endpoint '/ajax/users.php?op=verify'. The parameter is vulnerable to boolean-based and time-based SQL injection. Successfully exploiting this vulnerability would allow an attacker to discover the platform's database engine and cause delays in database queries.

6h ago
7.5

Unauthenticated Broken Access Control in Sermon'e <= 1.0.2 versions.

6h ago
7.2

Incorrect Privilege Assignment vulnerability in PublishPress PublishPress Capabilities capability-manager-enhanced allows Privilege Escalation.This issue affects PublishPress Capabilities: from n/a through 2.45.0.

6h ago
7.5

Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.7.1 versions.

6h ago
7.1

Unauthenticated Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.4.6 versions.

6h ago
7.1

Unauthenticated Cross Site Scripting (XSS) in WooCommerce Simple Auctions <= 3.0.10 versions.

6h ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Video Background Block – Use video as background in the section. <= 2.0.3 versions.

6h ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Social Rocket <= 1.3.5 versions.

6h ago
8.5

Subscriber SQL Injection in UDesign Core <= 4.15.0 versions.

6h ago
8.5

Subscriber SQL Injection in ListingPro <= 2.9.12 versions.

6h ago
7.5

Unauthenticated Sensitive Data Exposure in Snapshotify &#8211; All-in-One Backup &amp; Restore &amp; Migrate <= 1.3.2 versions.

6h ago
7.5

Unauthenticated Sensitive Data Exposure in Norvis Backup <= 1.1.0 versions.

6h ago
7.5

Unauthenticated Sensitive Data Exposure in Museder RestoreOne <= 2.7.276 versions.

6h ago
7.5

Unauthenticated Broken Access Control in WXD Backup Lite <= 1.0.2 versions.

6h ago
7.5

Unauthenticated Sensitive Data Exposure in SafeSnap – Verified WordPress Backup &amp; Restore <= 2.1.2 versions.

6h ago
7.1

Unauthenticated Cross Site Scripting (XSS) in CF7 Views &#8211; Complete Entry Management for Contact Form 7 <= 3.2.6 versions.

6h ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Blog, Posts and Category Filter for Elementor <= 2.1.0 versions.

6h ago
7.5

Unauthenticated Broken Access Control in Advanced Posts Listing – Show Post List Easily <= 1.0.8 versions.

6h ago
7.5

Unauthenticated Broken Access Control in WooCommerce Multivendor Marketplace – REST API <= 1.6.3 versions.

6h ago
8.8

Subscriber Broken Authentication in Simple JWT Login 4.0.0 versions.

6h ago
8.6

Unauthenticated Arbitrary File Deletion in Simple File List <= 6.3.11 versions.