SEPTEMBER 24, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

379,437 records on file
Page 1270 of 12,648
CVE ID Score Description
1mo ago
8.1

Unauthenticated PHP Object Injection in Zermatt <= 1.6.1 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in Mikado Core <= 1.6 versions.

1mo ago
9.8

Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in Solene <= 3.4 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in Kapee < 1.7.0 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in EmallShop <= 2.4.21 versions.

1mo ago
9.3

Unauthenticated SQL Injection in ListingPro <= 2.9.10 versions.

1mo ago
6.5

Subscriber Arbitrary Content Deletion in WPAMS < 49.5.3 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in Softlab Core < 1.2.11 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in Integrio Core < 1.2.8 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in Thegov Core < 2.0.23 versions.

1mo ago
7.5

Unauthenticated Sensitive Data Exposure in Bricksforge <= 3.1.8.4 versions.

1mo ago
9.1

Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

1mo ago
9.8

DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

1mo ago
5.6

A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. This could potentially include critical Flatpak override files.

Exploit 1mo ago
7.8

In Telecomm, there is a possible way to initiate an unauthorized phone call due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Exploit 1mo ago
5.5

In MmsSmsProvider of MmsSmsProvider.java, there is a possible way to retrieve sensitive information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Exploit 1mo ago
5.5

In Contacts Provider, there is a possible way to access the contacts database due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Exploit 1mo ago
5.5

In PackageInstaller.Session#transfer of frameworks/base/services/core/java/com/android/server/pm/PackageInstallerSession.java, there is a possible memory exhaustion attack due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

1mo ago
—

An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, registration action IS required) who has the vulnerable software could, introduce arbitrary JavaScript by injecting a Cross-site Scripting (XSS)  payload into the 'Hostname' field of the configuration file resulting in a XSS in the path /upgrade/query.php?cmd=p+3%3Bversion. This issue affects Regesta Smart HD-PLC - TLDPH16D2: 11.02.05.10.02.

1mo ago
—

An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, NO registration action is required) who has the vulnerable software could, with a Slow Loris attack, cause Denial of Service (DoS) on the web interface of the device. This issue affects Regesta Smart HD-PLC - TLDPH16D2: 11.02.05.10.02.

1mo ago
—

An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, NO registration action is required) who has the vulnerable software could obtain privilege information by using the command Version via the path: /upgrade/query.php?cmd=p+3&3Bversion resulting in a information disclosure. This issue affects Regesta Smart HD-PLC - TLDPH16D2: 11.02.05.10.02.

1mo ago
9.8

Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions.

1mo ago
6.5

Unauthenticated Deserialization of untrusted data in Slimstat Analytics < 5.4.0 versions.

1mo ago
8.6

Unauthenticated Arbitrary File Deletion in BookPro <= 1.1.0 versions.

1mo ago
9.8

Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions.

1mo ago
9.9

Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions.

1mo ago
10

Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom Post Types Plugin for WordPress allows Remote Code Inclusion. This issue affects ACPT (Pro) - Custom Post Types Plugin for WordPress: from n/a through 2.0.47.

1mo ago
9.9

Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions.