SEPTEMBER 24, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

379,817 records on file
Page 1278 of 12,661
CVE ID Score Description
1mo ago
8.1

Unauthenticated Local File Inclusion in Etude <= 1.6 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in Eventicity <= 1.5 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in Gunslinger <= 1.7 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in Skyward <= 1.10 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in Granola <= 1.13 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in Gamic <= 1.15 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in Preservation <= 1.10 versions.

1mo ago
7.1

Unauthenticated Cross Site Scripting (XSS) in SweetDate Core < 1.1.5 versions.

1mo ago
8.8

Subscriber PHP Object Injection in Entrepreneur - Booking for Small Businesses WordPress Theme <= 3.1.3 versions.

1mo ago
8.6

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in EMV JobCareer allows Path Traversal. This issue affects JobCareer: from n/a through 7.3.

1mo ago
9.8

Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in Fortius <= 2.3.0 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in Snow Club <= 1.1 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in Dazzle <= 1.0.0 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in LuxMed | Medicine & Healthcare Doctor WordPress Theme <= 1.2.2 versions.

1mo ago
9.8

Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in Imba <= 1.5.0 versions.

1mo ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Avante < 3.0.5 versions.

Exploit 1mo ago
8.8

In Citrix Cloud through 2025-11-10, an account with read-only access can trigger the beginning of a workflow for write operations, e.g., the system will send a one-time password to an attacker-controlled email address when the attacker attempts to reset the password of a user account.

1mo ago
9.8

Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection. This issue affects Creatify: from n/a through 1.5.

1mo ago
9.8

Deserialization of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object Injection. This issue affects The Hospital: from n/a through 1.8.1.

1mo ago
9.8

Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects The Barber Shop: from n/a through 1.9.

1mo ago
9.8

Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. This issue affects Lagom: from n/a through 2.0.

1mo ago
9.3

Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions.

1mo ago
5.3

Unauthenticated Insecure Direct Object References (IDOR) in School Management <= 93.1.0 versions.

1mo ago
7.5

Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4.0.1 versions.

1mo ago
7.1

The Taskbuilder WordPress plugin before 5.0.8 does not properly sanitise a URL parameter before echoing it into inline JavaScript on a frontend page containing one of its shortcodes, leading to a Reflected Cross-Site Scripting vulnerability that can be triggered against any logged-in user.

1mo ago
6.4

The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wrap' Shortcode Attribute in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

1mo ago
6.4

The Permalink Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in the admin URI Editor interface in all versions up to, and including, 2.5.3.3 due to insufficient output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in the admin Permalink Manager page that will execute whenever an administrator accesses the Permalink Manager page.

1mo ago
5.3

The LearnPress WordPress plugin before 4.3.7 does not gate the `edit` context on one of its REST endpoint behind the `edit_users` capability, allowing unauthenticated visitors to retrieve each returned user's roles, full capabilities map, extra capabilities, locale, and registration date via a crafted request