CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 12d ago | 9.3 | Unauthenticated SQL Injection in JetEngine < 3.8.9.1 versions. |
| 12d ago | 9.3 | Unauthenticated SQL Injection in wpDataTables <= 7.3.6 versions. |
| 12d ago | 9.3 | Unauthenticated SQL Injection in JetSearch <= 3.5.17 versions. |
| 12d ago | 9.3 | Unauthenticated SQL Injection in JetEngine <= 3.8.9.1 versions. |
| 12d ago | 9.8 | Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions. |
| 12d ago | 9.8 | Unauthenticated Privilege Escalation in LoginPress Pro <= 6.2.2 versions. |
| 12d ago | 9.3 | Unauthenticated SQL Injection in JetSmartFilters <= 3.8.1 versions. |
| Exploit 12d ago | 9.9 | Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an attacker-controlled JSON blob into a session-shape JWT using the application's JWT_SECRET, and the auth middleware trusted every claim in that JWT without re-resolving the user from the database. Any authenticated Postiz user could forge a SUPERADMIN session and impersonate arbitrary organizations. This allowed Full Access to the following: all parts of Postiz, including users registered to the specific instance and the ability to post in the name of the victim's social media channels added to that Postiz instance. This issue has been fixed in version 2.21.8. |
| Exploit 12d ago | 9.3 | Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source Traccar platform. In versions 9.7.19 and below, a single crafted deep link can silently hijack all GPS tracking parameters and redirect telemetry to an attacker-controlled server. The app registers a custom org.traccar.client://config deep-link scheme that silently writes attacker-supplied parameters (server URL, device ID, accuracy, distance, and interval) into the app's persistent configuration with no confirmation, notification, or visual indication. A single crafted link delivered via SMS, email, a webpage, or any installed app can therefore reconfigure the app the moment the victim taps it, with no special permissions required. As a result, an attacker can covertly redirect all of the victim's GPS telemetry to their own server at maximum precision and frequency, and the change persists across restarts. This gives the attacker continuous, real-time tracking of the victim's location. This issue has been fixed in version 9.7.20. |
| Exploit 12d ago | 9.3 | Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files. Protected file downloads at /file-upload/:fileId/:name authorize livechat access using rc_room_type=l with rc_rid+rc_token, but the authorization path does not verify that rc_rid matches the requested file's rid. Furthermore, :fileId is predictable via sequential MongoDB IDs, and :name can be anything, allowing unauthenticated discovery of all uploaded files. |
| Exploit 12d ago | 10 | Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior, a high-severity Zip Slip vulnerability was identified in Streambert's subtitle extraction logic. The application does not sanitize archive entry filenames during extraction, allowing a malicious archive to perform path traversal and write arbitrary files to the host filesystem. The subtitle extraction process downloads a ZIP archive and extracts its entries. The destination file path is constructed by concatenating the raw archive entry name (extracted.name) directly to the temporary directory path. If a malicious ZIP archive containing directory traversal sequences is processed, it escapes the temporary directory boundaries. The application then writes the extracted payload anywhere on the host filesystem subject to the application's current write permissions. This issue has been fixed in version 2.5.0. |
| 12d ago | 9.8 | Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions. |
| Exploit 12d ago | 9.9 | Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions. |
| 12d ago | 9.9 | Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions. |
| 12d ago | 9.9 | Subscriber Arbitrary File Upload in Kids Gift Shop <= 0.5.4 versions. |
| 12d ago | 9.9 | Subscriber Arbitrary File Upload in Ecommerce Zone <= 0.9.7 versions. |
| 12d ago | 9.9 | Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions. |
| 12d ago | 9.8 | Unauthenticated PHP Object Injection in WooCommerce Product Filters < 2.0.6 versions. |
| 12d ago | 9.3 | Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions. |
| 12d ago | 9.9 | Subscriber Arbitrary File Upload in Webenvo <= 0.0.6 versions. |
| 12d ago | 9.8 | Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions. |
| 12d ago | 9.3 | Unauthenticated SQL Injection in ListingPro <= 2.9.10 versions. |
| 12d ago | 9.1 | Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. |
| 12d ago | 9.8 | DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. |
| 12d ago | 9.8 | Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions. |
| 12d ago | 9.8 | Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions. |
| 12d ago | 9.9 | Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions. |
| 12d ago | 10 | Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom Post Types Plugin for WordPress allows Remote Code Inclusion. This issue affects ACPT (Pro) - Custom Post Types Plugin for WordPress: from n/a through 2.0.47. |
| 12d ago | 9.9 | Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions. |
| 12d ago | 9.1 | Unauthenticated Broken Access Control in MetForm Pro <= 3.9.1 versions. |