AUGUST 19, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

141,688 records on file
Page 144 of 4,723
CVE ID Score Description
Exploit 2h ago
7.1

Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in the POST /pages/{route}/move endpoint. PagesController::move() sanitizes the slug only with ltrim($body['slug'], '.'), which strips leading periods but does not neutralize '/' or '..' segments. An authenticated API caller with the api.pages.write permission can supply path traversal sequences (e.g., 01.home/../../../pwned) to move an entire page directory (content and media) to an arbitrary writable location outside user/pages/, including outside the Grav installation.

Exploit 2h ago
8.5

Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users with api.config.write privilege to modify rate limiting and CORS settings. Attackers can disable rate limiting site-wide to enable credential brute-forcing attacks and reconfigure CORS policies to include attacker-controlled origins with credentials enabled.

Exploit 2h ago
8.8

Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. FlexDirectory::dynamicDataField() resolves blueprint data-*@: directives by calling call_user_func_array() on attacker-influenced input, validating only that the target is callable (is_callable()) without restricting dangerous functions such as exec, system, passthru, or shell_exec. Because FlexDirectory registers this handler for every Flex directory, it bypasses the validation added to Blueprint::dynamicData() in 2.0.7 (GHSA-fj2p-qj2f-74v5). Any authenticated user with create or update permission on any Flex-based directory (Flex Users, Flex Pages, Flex Objects, or custom Flex types) can execute arbitrary shell commands on the server.

2h ago
7.1

Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions.

2h ago
7.1

Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.

2h ago
7.6

Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions.

2h ago
8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer allows Blind SQL Injection. This issue affects Visualizer: from n/a through 4.0.1.

2h ago
7.2

Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.

2h ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.

2h ago
7.1

Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions.

2h ago
7.5

Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.

2h ago
7.2

Administrator PHP Object Injection in Complianz <= 7.5.0 versions.

2h ago
7.5

Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.

2h ago
7.1

Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.

2h ago
7.5

Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.

2h ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Dokan Pro <= 5.0.0 versions.

2h ago
7.1

Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.

2h ago
7.5

Contributor Local File Inclusion in Vino <= 1.9 versions.

2h ago
7.5

Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions.

2h ago
7.6

Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.

2h ago
8.5

Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.

2h ago
8.5

Contributor SQL Injection in MapSVG <= 8.14.0 versions.

2h ago
8.5

Contributor SQL Injection in MapSVG <= 8.14.0 versions.

2h ago
8.1

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files

2h ago
8.6

In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session

Exploit 2h ago
7.8

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration

Exploit 2h ago
8.4

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter

Exploit 2h ago
8.4

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling

Exploit 2h ago
7.8

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration

Exploit 2h ago
8.4

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter