SEPTEMBER 24, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

379,817 records on file
Page 1281 of 12,661
CVE ID Score Description
1mo ago
8.8

Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2.13.0 versions.

1mo ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Profile Builder Pro <= 3.15.0 versions.

1mo ago
9.8

Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions.

1mo ago
6.5

Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access. This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue.

1mo ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Kapee < 1.7.1 versions.

1mo ago
4.9

Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue.

Exploit 1mo ago
9.9

Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions.

1mo ago
7.3

Unauthenticated Insecure Direct Object References (IDOR) in Salon booking system <= 10.30.24 versions.

1mo ago
7.1

Unauthenticated Cross Site Scripting (XSS) in collectchat <= 2.4.9 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in Behold <= 1.5 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in Esmée <= 1.4 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in TechLink <= 1.3 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in Roisin <= 1.4 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in EasyMeals <= 1.5.1 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions.

1mo ago
9.9

Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions.

1mo ago
9.9

Subscriber Arbitrary File Upload in Kids Gift Shop <= 0.5.4 versions.

1mo ago
9.9

Subscriber Arbitrary File Upload in Ecommerce Zone <= 0.9.7 versions.

1mo ago
9.9

Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in LuxeDrive <= 1.4 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in Laurits <= 1.5.1 versions.

1mo ago
8.1

Unauthenticated PHP Object Injection in Reina <= 2.1 versions.

1mo ago
8.1

Unauthenticated Local File Inclusion in ChapterOne <= 1.7 versions.

1mo ago
8.2

Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.14 versions.

1mo ago
9.8

Unauthenticated PHP Object Injection in WooCommerce Product Filters < 2.0.6 versions.

1mo ago
6.5

CP Client Arbitrary File Download in Client Portal (Pro) <= 5.6.2 versions.

1mo ago
4.3

Subscriber Broken Access Control in Bricks Builder <= 2.1.4 versions.

Exploit 1mo ago
5.5

Missing Authorization vulnerability in Yoast BV Yoast SEO Premium allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Yoast SEO Premium: from n/a through 26.6.