SEPTEMBER 24, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

379,437 records on file
Page 1266 of 12,648
CVE ID Score Description
1mo ago
9.8

Deserialization of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object Injection. This issue affects The Hospital: from n/a through 1.8.1.

1mo ago
9.8

Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects The Barber Shop: from n/a through 1.9.

1mo ago
9.8

Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. This issue affects Lagom: from n/a through 2.0.

1mo ago
9.3

Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions.

1mo ago
5.3

Unauthenticated Insecure Direct Object References (IDOR) in School Management <= 93.1.0 versions.

1mo ago
7.5

Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4.0.1 versions.

1mo ago
7.1

The Taskbuilder WordPress plugin before 5.0.8 does not properly sanitise a URL parameter before echoing it into inline JavaScript on a frontend page containing one of its shortcodes, leading to a Reflected Cross-Site Scripting vulnerability that can be triggered against any logged-in user.

1mo ago
6.4

The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wrap' Shortcode Attribute in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

1mo ago
6.4

The Permalink Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in the admin URI Editor interface in all versions up to, and including, 2.5.3.3 due to insufficient output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in the admin Permalink Manager page that will execute whenever an administrator accesses the Permalink Manager page.

1mo ago
5.3

The LearnPress WordPress plugin before 4.3.7 does not gate the `edit` context on one of its REST endpoint behind the `edit_users` capability, allowing unauthenticated visitors to retrieve each returned user's roles, full capabilities map, extra capabilities, locale, and registration date via a crafted request

1mo ago
7.1

The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress plugin before 2.1.3 does not properly escape a user-supplied parameter before reflecting it into an HTML attribute on a non-nonce-protected AJAX response, allowing unauthenticated attackers to deliver Reflected Cross-Site Scripting against any authenticated user (including administrators) via a crafted URL.

1mo ago
5.9

The WP Magnific Popup WordPress plugin through 1.0 does not properly escape user-controlled link URLs before injecting them into the DOM when displaying image load error messages, allowing authenticated attackers with Author-level access or above to perform Stored Cross-Site Scripting attacks against any visiting user.

1mo ago

Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Packaged Air Conditioners (for Japan and outside Japan); Refrigerators (for Japan); Heat Pump Water Heaters / HEMS-Compatible Adapters / Wireless LAN Adapters (for Japan); Bathroom Dryer / Heater / Ventilation Systems (for Japan); Adapters for Airflow Ventilation Systems, Heat Pump Chilled / Hot Water Systems, and Ventilation / Air-Conditioning System Air Resorts (for Japan); Lossnay Central Ventilation Systems (for Japan); Smart Switches for Ventilation Fans and Lossnay (for Japan); IH Cooking Heaters (for Japan); and Rice Cookers (for Japan) allows an attacker within Wi-Fi radio range of an affected product to access the affected product using a hard-coded SSID and password, thereby obtaining device data such as operation status, room set temperature, and room temperature; changing the air-conditioner or Wi-Fi settings; or causing Wi-Fi communication to enter a denial-of-service (DoS) condition.

Exploit 1mo ago
5.8

sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows authentication bypass via certain zero values for lengths.

1mo ago
9.3

Unauthenticated SQL Injection in WP eMember < v10.9.4 versions.

1mo ago
9.8

Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions.

1mo ago
9.8

Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions.

1mo ago
8.8

Subscriber Privilege Escalation in Falang multilanguage <= 1.4.2 versions.

1mo ago
7.6

Subscriber Broken Authentication in Melhor Envio <= 2.16.3 versions.

1mo ago
9.8

Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.4 versions.

1mo ago
7.5

Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions.

1mo ago
6.8

Subscriber Privilege Escalation in JetFormBuilder <= 3.6.1 versions.

1mo ago
7.1

Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.0.1 versions.

1mo ago
9.8

Contributor PHP Object Injection in Fusion Builder <= 3.15.4 versions.

1mo ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Popup box <= 6.2.9 versions.

1mo ago
7.1

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.

1mo ago
7.1

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.

1mo ago
9.3

Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions.

1mo ago
9.3

Unauthenticated SQL Injection in JobSearch <= 3.2.9 versions.

1mo ago
8.5

Subscriber SQL Injection in Cornerstone < 7.8.8 versions.