OCTOBER 9, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

37,231 records on file
Page 82 of 1,242
CVE ID Score Description
Exploit 20d ago
9.8

dbx is a cross-platform database client for databases. Prior to 0.5.51, dbx-web auth_middleware in crates/dbx-web/src/auth.rs passes every protected request to the handler chain when password_hash is None. A fresh deployment reaches that state when DBX_PASSWORD is unset and no stored password exists, while crates/dbx-web/src/main.rs binds the service to 0.0.0.0 on port 4224 by default. An unauthenticated network attacker can call the /api/connection/connect and /api/query/execute routes to use configured database credentials and execute arbitrary SQL, allowing disclosure, modification, or destruction of data in connected databases. The desktop Tauri application is not affected because it binds only to loopback. This issue is fixed in version 0.5.51.

Exploit 20d ago
9.8

OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OSNEXUS QuantaStor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of Kapacitor. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-30036.

20d ago
9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject the string value into the SQL statement, enabling SQL injection. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/12080 .

20d ago
9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject arbitrary SQL code through the dbName, tableName, schemaName, and username parameters.  This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/issues/12135 .

20d ago
9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This appears to allow SQL injection in the ORDER BY clause against the Manager backend database. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/issues/12079 .

20d ago
9.1

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due to improper neutralization of special elements in input.

20d ago
9.8

Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Baylan Smart Meter Management Application (BMS) allows Authentication Bypass. This issue affects Baylan Smart Meter Management Application (BMS): before v1.1.10.142.

20d ago
9.6

Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. This issue affects Easy Elementor Addons: from n/a through 2.3.7.

Exploit 20d ago
9.8

Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-system MCP server, where the checkSyntax() and runPlaywrightTest() functions unsafely interpolate caller-controlled absolutePath values into shell commands, enabling arbitrary OS command execution when an AI agent is induced to invoke these tools. Commit 88c77fc fixes these vulnerabilities.

Exploit 20d ago
9.8

n8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vulnerability in the Supabase node's Row Get Many, Delete, and Update operations, which built filter queries by concatenating an expression-bindable value without escaping. An attacker could inject a condition that widened the filter to match every row, turning an intended single-row operation into full-table disclosure, deletion, or modification.

Exploit 20d ago
9.8

n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node's Find, Delete, and Aggregate operations, which parse the Query parameter as JSON after expression resolution without sanitizing MongoDB operators. An attacker who can influence the resolved query (e.g., via externally-controlled data) can inject operators such as $ne or $where, turning an intended single-document lookup into full-collection disclosure, full-collection deletion, or other operations on the database server.

20d ago
9.9

Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.

20d ago
9.9

Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.

20d ago
9.9

Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.

20d ago
9.8

Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.

20d ago
9.8

Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.

Exploit 20d ago
9.9

Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.

20d ago
9.3

Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.

20d ago
9.8

Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.

20d ago
9.3

Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.

20d ago
9.8

Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions.

20d ago
9.3

Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.

20d ago
9.3

Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.

20d ago
9.1

Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions.

20d ago
9.3

Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.

20d ago
9.3

Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.

20d ago
9.8

Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.

20d ago
9.8

Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.

20d ago
9.3

Unauthenticated SQL Injection in Capella <= 2.5.5 versions.

20d ago
9.6

A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name in the Ticket Granting Service (TGS) due to FreeIPA services not verifying Privilege Attribute Certificate (PAC) certificates. This vulnerability could allow an authenticated Active Directory user to escalate their privileges within the FreeIPA domain.