CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 2h ago | 7.6 | Administrator SQL Injection in WP Google Review Slider <= 18.4 versions. |
| Exploit 2h ago | 7.5 | NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows unauthenticated attackers on the same network to write arbitrary files by sending a crafted filename containing directory traversal sequences in the JSON item header name field. Attackers can exploit the lack of path validation to write files outside the transfer root directory to arbitrary locations the current user has write access, including the Windows Startup folder, enabling persistent code execution on the next user login. |
| 2h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions. |
| 2h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions. |
| 2h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions. |
| 2h ago | 7.2 | Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions. |
| 2h ago | 8.5 | Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions. |
| 2h ago | 7.5 | Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions. |
| 2h ago | 7.4 | Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions. |
| 2h ago | 7.5 | Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions. |
| 2h ago | 7.6 | Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versions. |
| 2h ago | 7.5 | Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions. |
| 2h ago | 7.3 | Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions. |
| 2h ago | 7.5 | Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions. |
| 2h ago | 7.5 | Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions. |
| 2h ago | 7.5 | Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions. |
| 2h ago | 7.5 | Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions. |
| 2h ago | 7.5 | Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions. |
| 2h ago | 7.5 | Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions. |
| 2h ago | 8.5 | Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vulnerability allowing an attacker to execute arbitrary code as root. |
| 2h ago | 8.3 | Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a file deletion vector in the media manager. |
| 2h ago | 8.2 | Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of various parameters in the media manager search and date filters lead to an SQL injection vector. |
| 2h ago | 8 | A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that should not be accessible to their permission level, potentially resulting in a system compromise. |
| 2h ago | 8 | An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise. |
| 2h ago | 8.4 | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the backup restore functionality, potentially resulting in complete system compromise. |
| 2h ago | 8.4 | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the Geo Location management interface, potentially resulting in complete system compromise. |
| 2h ago | 8.4 | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, potentially resulting in complete system compromise. |
| 2h ago | 8.7 | The lack of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics' Vision 60 robot (APK v5.5.0) exposes the system to man-in-the-middle attacks. An attacker located on the local network can use ARP spoofing and selective traffic blocking techniques to intercept and manipulate packets between the legitimate operator and the robot. This allows the attacker to disconnect the original controller, establish unauthorized communications, and prevent the operator from regaining control of the device, seriously compromising the confidentiality, integrity, and availability (CIA) of operations. |
| 2h ago | 7.7 | An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simultaneous sessions to run without proper client validation or session integrity checks. An attacker with a modified version of the app can connect to the robot during an active, legitimate session. This allows the attacker to bypass control restrictions, intercept sensitive information (such as real-time video), and partially interact with the system unnoticed and without disconnecting the legitimate user, compromising confidentiality and operational security. |
| Exploit 2h ago | 8.7 | A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows an unauthenticated attacker connected to the device's internal Wi-Fi network to gain unrestricted access to the web administration interface and the HTTP API. Due to the lack of authorization mechanisms, the attacker can view real-time camera feeds, control the robot’s movements, manage sensors (GPS, RTK, SAM, LIDAR), and execute critical operational commands (Play, Pause, Stop, E-Stop). Successful exploitation completely compromises the confidentiality, integrity, and physical security of the system. |