OCTOBER 8, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

150,883 records on file
Page 1673 of 5,030
CVE ID Score Description
Exploit 2mo ago
8

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `doOpenVPN.`

Exploit 2mo ago
8

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `autodiscovery_clear.`

Exploit 2mo ago
8

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `setSWMGroup.`

Exploit 2mo ago
8

DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `delete_map_profile.`

2mo ago
7.6

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPDeveloper BetterLinks betterlinks allows SQL Injection.This issue affects BetterLinks: from n/a through <= 2.1.7.

2mo ago
7.5

Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows PHP Local File Inclusion.This issue affects WP Hotel Booking: from n/a through <= 2.2.9.

Exploit 2mo ago
8.5

AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadata credentials.

Exploit 2mo ago
8

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doL2TP function.

Exploit 2mo ago
8

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the backup function.

Exploit 2mo ago
8

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the reboot function.

Exploit 2mo ago
8

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPTP function.

2mo ago
7.5

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Retrieve Embedded Sensitive Data.This issue affects Stacks Mobile App Builder: from n/a through <= 5.2.3.

2mo ago
7.1

Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admin functionality on the ThreatAvert Policy page. An authenticated user can navigate directly to the /#app/intelligence/threatAvertPolicies URI and disable policy enforcement.

Exploit 2mo ago
7.5

This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by intercepting and manipulating the responses exchanged during the second factor authentication process. Successful exploitation of this vulnerability could allow the attacker to bypass OTP verification for accessing other user accounts.

2mo ago
8.3

Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in Technician reports option.

2mo ago
8.3

Zohocorp ManageEngine ADManager Plus versions 7241 and prior are vulnerable to SQL Injection in Archived Audit Report.

Exploit 2mo ago
7.5

There exists a Path Traversal vulnerability in Safearchive on Platforms with Case-Insensitive Filesystems (e.g., NTFS). This allows Attackers to Write Arbitrary Files via Archive Extraction containing symbolic links. We recommend upgrading past commit f7ce9d7b6f9c6ecd72d0b0f16216b046e55e44dc

2mo ago
7.8

Memory corruption during GNSS HAL process initialization.

2mo ago
7.8

Memory corruption while processing GPU page table switch.

2mo ago
7.8

Memory corruption while processing voice packet with arbitrary data received from ADSP.

2mo ago
7.8

Memory corruption while processing GPU commands.

2mo ago
7.8

Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.

2mo ago
7.8

Memory corruption while handling session errors from firmware.

2mo ago
7.8

Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice.

2mo ago
7.8

Memory corruption while station LL statistic handling.

2mo ago
8.2

Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.

2mo ago
7.8

Memory corruption while processing input parameters for any IOCTL call in the JPEG Encoder driver.

2mo ago
7.8

Memory corruption while handling IOCTL calls in JPEG Encoder driver.

2mo ago
7.5

Transient DOS while processing the CU information from RNR IE.

2mo ago
7.5

Transient DOS while parsing BTM ML IE when per STA profile is not included.