SEPTEMBER 28, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

170,878 records on file
Page 1418 of 5,696
CVE ID Score Description
1mo ago
5.4

Path Traversal vulnerability in NotFound WPJobBoard allows Path Traversal. This issue affects WPJobBoard: from n/a through n/a.

1mo ago
6.5

Unauthenticated attackers can send configuration settings to device and possible perform physical actions remotely (e.g., on/off).

1mo ago
5.3

Unauthenticated attackers can retrieve serial number of smart meters associated to a specific user account.

1mo ago
5.3

Unauthenticated attackers can retrieve full list of users associated with arbitrary accounts.

1mo ago
5.3

An unauthenticated attackers can obtain a list of smart devices by knowing a valid username through an unprotected API.

Exploit 1mo ago
6.8

Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of a CVE-2024-22406 and CVE-2024-42357 regression.

1mo ago
5.3

Unauthenticated attackers can query an API endpoint and get device details.

1mo ago
5.3

An unauthenticated attacker can obtain EV charger version and firmware upgrading history by knowing the charger ID.

1mo ago
5.3

An unauthenticated attacker can delete any user's "rooms" by knowing the user's and room IDs.

1mo ago
5.3

Unauthenticated attackers can rename "rooms" of arbitrary users.

1mo ago
6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Blocks skt-blocks allows Stored XSS.This issue affects SKT Blocks: from n/a through <= 1.8.

1mo ago
6.5

Improper Control of Generation of Code ('Code Injection') vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets allows Code Injection.This issue affects Sign-up Sheets: from n/a through <= 2.3.0.1.

1mo ago
6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in covertnine C9 Blocks c9-blocks allows DOM-Based XSS.This issue affects C9 Blocks: from n/a through <= 1.7.7.

1mo ago
6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AddonsPress Nepali Date Converter nepali-date-converter allows Stored XSS.This issue affects Nepali Date Converter: from n/a through <= 2.0.8.

1mo ago
6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in graphthemes Glossy Blog glossy-blog allows Stored XSS.This issue affects Glossy Blog: from n/a through <= 1.0.3.

1mo ago
6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in alleythemes Home Services home-services allows DOM-Based XSS.This issue affects Home Services: from n/a through <= 1.2.6.

1mo ago
6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tainacan TainĂ¡ taina allows Stored XSS.This issue affects TainĂ¡: from n/a through < 0.2.5.

1mo ago
6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ren Ventura WP Delete User Accounts wp-delete-user-accounts allows DOM-Based XSS.This issue affects WP Delete User Accounts: from n/a through <= 1.2.3.

1mo ago
4.3

Cross-Site Request Forgery (CSRF) vulnerability in RealMag777 InPost Gallery inpost-gallery allows Cross Site Request Forgery.This issue affects InPost Gallery: from n/a through <= 2.1.4.3.

1mo ago
6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Skill Bar skt-skill-bar allows Stored XSS.This issue affects SKT Skill Bar: from n/a through <= 2.3.

1mo ago
6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine jet-engine allows DOM-Based XSS.This issue affects JetEngine: from n/a through <= 3.6.4.1.

1mo ago
5.3

Unauthenticated attackers can rename arbitrary devices of arbitrary users (i.e., EV chargers).

1mo ago
6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Additional Custom Product Tabs for WooCommerce product-tabs-for-woocommerce allows Stored XSS.This issue affects Additional Custom Product Tabs for WooCommerce: from n/a through <= 1.7.0.

1mo ago
6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in burgersoftware SpaBiz spabiz allows DOM-Based XSS.This issue affects SpaBiz: from n/a through <= 1.0.18.

1mo ago
5.3

An unauthenticated attacker can hijack other users' devices and potentially control them.

1mo ago
5.3

An attacker can export other users' plant information.

1mo ago
5.3

Unauthenticated attackers can add devices of other users to their scenes (or arbitrary scenes of other arbitrary users).

1mo ago
6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Stored XSS.This issue affects Real Testimonials: from n/a through <= 3.1.6.

1mo ago
6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash uncanny-learndash-toolkit allows Stored XSS.This issue affects Uncanny Toolkit for LearnDash: from n/a through <= 3.7.0.1.

Exploit 1mo ago
6.4

An issue was discovered in AcpiS3SaveDxe and ChipsetSvcDxe in Insyde InsydeH2O with kernel 5.2 though 5.7. A potential DXE memory corruption vulnerability has been identified. The root cause is use of a pointer originating from the value of an NVRAM variable as the target of a write operation. This can be leveraged by an attacker to perform arbitrary writes, potentially leading to arbitrary code execution. The issue has been fixed in kernel 5.2, Version 05.29.44; kernel 5.3, Version 05.38.44; kernel 5.4, Version 05.46.44; kernel 5.5, Version 05.54.44; kernel 5.6, Version 05.61.44; and kernel 5.7, Version 05.70.44.