CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 28d ago | 9.8 | Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php, that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal. |
| Exploit 28d ago | 9.1 | rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source address. Attackers who can connect directly to the rsync daemon can inject a spoofed source IP in the PROXY protocol header to circumvent hosts allow/deny rules, gaining unauthorized access that would otherwise be blocked based on their real source address. |
| 28d ago | 9.8 | Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions. |
| 28d ago | 9.3 | Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions. |
| 28d ago | 9.3 | Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions. |
| 28d ago | 9.8 | Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions. |
| 28d ago | 9.3 | Unauthenticated SQL Injection in RealPress <= 1.1.2 versions. |
| 28d ago | 9.8 | Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions. |
| 28d ago | 9.3 | Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions. |
| 28d ago | 9.3 | Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions. |
| 28d ago | 9.8 | Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions. |
| 28d ago | 9.3 | Unauthenticated SQL Injection in Listdom <= 5.6.0 versions. |
| 28d ago | 9.8 | Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions. |
| 28d ago | 9.3 | Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions. |
| Exploit 28d ago | 10 | Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions. |
| 28d ago | 9.8 | Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions. |
| 28d ago | 9.8 | Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions. |
| 28d ago | 9.8 | Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions. |
| 28d ago | 9.3 | Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions. |
| 28d ago | 9.8 | Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions. |
| 28d ago | 9.3 | Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions. |
| Exploit 28d ago | 10 | Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions. |
| Exploit 28d ago | 9.8 | WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execution. Combined with open registration (no invite required) and broken role middleware (CheckUserRole silently swallows RouteNotFoundException), this chain is effectively unauthenticated RCE against any default installation. The issue is patched in commit 5c54862fa044b363fd2be03d586750e81afd6818. |
| Exploit 28d ago | 9.9 | Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment locale validation bypass. Attackers can craft a fake String object with a match function that bypasses path traversal checks to load and execute malicious JavaScript files stored in the document store outside the sandbox. |
| Exploit 28d ago | 9.8 | Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inject malicious code via prompt injection. Attackers can exploit unblocked pandas functions like pd.read_json() to exfiltrate datasets, perform SSRF against internal services, or achieve code execution through the unauthenticated prediction API. |
| 28d ago | 9.3 | : Use of Hard-coded Credentials : Exposure of Sensitive Information to an Unauthorized Actor : Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3. |
| 28d ago | 9.3 | : Missing Authentication for Critical Function vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3. |
| 28d ago | 9.1 | : Client-Side Enforcement of Server-Side Security vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3. |
| 28d ago | 9.1 | : Exposure of Sensitive Information to an Unauthorized Actor : Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3. |
| 28d ago | 10 | : Improper Authentication vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3. |