SEPTEMBER 10, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

35,752 records on file
Page 745 of 1,192
CVE ID Score Description
1mo ago
9.8

Chain Sea ai chatbot system’s file upload function has insufficient filtering for special characters in URLs, which allows a remote attacker to by-pass file type validation, upload malicious script and execute arbitrary code without authentication, in order to take control of the system or terminate service.

1mo ago
9.8

4MOSAn GCB Doctor’s file upload function has improper user privilege control. A remote attacker can upload arbitrary files including webshell files without authentication and execute arbitrary code in order to perform arbitrary system operations or deny of service attack.

Exploit 1mo ago
9.8

This affects the package latte/latte before 2.10.6. There is a way to bypass allowFunctions that will affect the security of the application. When the template is set to allow/disallow the use of certain functions, adding control characters (x00-x08) after the function will bypass these restrictions.

1mo ago
10

TCMAN GIM is vulnerable to a SQL injection vulnerability inside several available webservice methods in /PC/WebService.asmx.

Exploit 1mo ago
9.8

A vulnerability in /include/web_check.php of SEMCMS v3.8 allows attackers to reset the Administrator account's password.

Exploit 1mo ago
9.6

A Missing Authentication for Critical Function vulnerability in SUSE Longhorn allows any workload in the cluster to execute any binary present in the image on the host without authentication. This issue affects: SUSE Longhorn longhorn versions prior to 1.1.3; longhorn versions prior to 1.2.3.

Exploit 1mo ago
9.8

Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpath parameter.

Exploit 1mo ago
9.1

eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows an attacker to authenticate as an existing user, if that user was created using a single sign-on authentication option such as LDAP or SAML. It impacts instances where LDAP or SAML is used for authentication instead of the (default) local password mechanism. Users should upgrade to at least version 4.2.0.

Exploit 1mo ago
9.8

SQL Injection vulnerability exists in ThinkPHP5 5.0.x <=5.1.22 via the parseOrder function in Builder.php.

Exploit 1mo ago
9.8

bookstack is vulnerable to Improper Access Control

1mo ago
9.8

FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 includes an account named "cmuser" that has administrative privileges and no password. Older versions of FatPipe software may also be vulnerable. The FatPipe advisory identifier for this vulnerability is FPSA002.

1mo ago
9.8

Product: AndroidVersions: Android kernelAndroid ID: A-192641593References: N/A

1mo ago
9.8

Product: AndroidVersions: Android kernelAndroid ID: A-199805112References: N/A

1mo ago
9.8

Product: AndroidVersions: Android kernelAndroid ID: A-199809304References: N/A

1mo ago
9.8

Product: AndroidVersions: Android kernelAndroid ID: A-126949257References: N/A

1mo ago
9.8

Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6.1) WordPress plugin.

Exploit 1mo ago
9.8

In NfcTag::discoverTechnologies (activation) of NfcTag.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additionalSystem execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-189942532

Exploit 1mo ago
9.8

In Android TV , there is a possible silent pairing due to lack of rate limiting in the pairing flow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-8.1 Android-9Android ID: A-180745296

Exploit 1mo ago
9.8

A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via VerificationController.php.

Exploit 1mo ago
9.8

Online Pre-owned/Used Car Showroom Management System 1.0 contains a SQL injection authentication bypass vulnerability. Admin panel authentication can be bypassed due to SQL injection vulnerability in the login form allowing attacker to get admin access on the application.

Exploit 1mo ago
9.8

Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability. The Admin panel authentication can be bypassed due to SQL injection vulnerability in the login form allowing attacker to gain access as admin to the application.

Exploit 1mo ago
9.8

Visual Studio Code WSL Extension Remote Code Execution Vulnerability

Exploit 1mo ago
9.6

Microsoft Office app Remote Code Execution Vulnerability

Exploit 1mo ago
9.8

Microsoft 4K Wireless Display Adapter Remote Code Execution Vulnerability

Exploit 1mo ago
9

Microsoft Defender for IoT Remote Code Execution Vulnerability

Exploit 1mo ago
9.8

iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution

Exploit 1mo ago
10

Microsoft Defender for IoT Remote Code Execution Vulnerability

Exploit 1mo ago
10

Microsoft Defender for IoT Remote Code Execution Vulnerability

Exploit 1mo ago
9.8

iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java.

Exploit 1mo ago
9.8

A SQL Injection vulnerability exists in ZZCMS 2021 via the askbigclassid parameter in /admin/ask.php.