AUGUST 17, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

164,153 records on file
Page 88 of 5,472
CVE ID Score Description
4h ago
6.5

Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0. Users are recommended to upgrade to version 10.10.0, which fixes the issue.

4h ago
6.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0. Users are recommended to upgrade to version 10.10.0, which fixes the issue.

Exploit 4h ago
5

A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality of the file server/src/routes/goals.ts of the component Unsigned Scheduled Callback. This manipulation causes authorization bypass. Remote exploitation of the attack is possible. The attack is considered to have high complexity. The exploitation is known to be difficult. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Exploit 4h ago
6.5

phpMyFAQ before 4.1.6 contains a privilege escalation vulnerability in GroupController::updateMembers() that allows administrators with only group-management permissions to join privileged groups without verification of required rights. Attackers can add themselves to pre-existing groups holding user-management rights and immediately inherit those permissions to modify or delete user accounts.

Exploit 4h ago
4.8

Relative Path Traversal vulnerability in Erlang OTP (stdlib zip module) allows writing files outside the intended extraction directory via a crafted zip archive. zip:unzip/1,2 and zip:extract/1,2 validate entry paths using zip:check_dir_level/2, which tracks directory depth as a running integer counter: .. decrements it, normal path components increment it. The caller rejects only paths where the final counter value is less than zero. A path such as ../x/y causes the counter to go negative mid-traversal then recover to zero, passing validation while resolving to a location outside the extraction directory when joined with the current working directory via add_cwd. This vulnerability is associated with program file lib/stdlib/src/zip.erl. This issue affects OTP from OTP 27.1 before OTP 29.0.4, OTP 28.5.0.4 and OTP 27.3.4.15, corresponding to stdlib from 6.1 before 8.0.3, 7.3.0.1 and 6.2.2.4.

Exploit 4h ago
5.2

HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an invalid variable-length datatype type field may cause the application to crash when the attribute is read.

Exploit 4h ago
4

A double free vulnerability was discovered in the HDF5 library. Processing a crafted HDF5 file containing an oversized chunk size field via h5repack may cause the application to abort due to a double free.

Exploit 4h ago
5.5

Heap-based buffer overflow in the SOHM list-index deserialization code in HDF5 through 2.1.1 on all platforms allows attackers to cause a denial of service (crash) via a crafted HDF5 file whose shared-message list index declares a num_messages count exceeding list_max, triggering out-of-bounds heap reads and writes in H5SM__cache_list_deserialize and H5SM__cache_list_verify_chksum.

Exploit 4h ago
6.3

A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this vulnerability is the function _build_handoff_toolset of the file AstrBot/astrbot/core/astr_agent_tool_exec.py of the component Subagent. The manipulation results in incorrect authorization. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The patch is identified as d23011262e8e75e1ec41b0f1f0091493a022327e. A patch should be applied to remediate this issue.

Exploit 4h ago
6.3

A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Affected is an unknown function of the file astrbot/core/astr_main_agent.py. The manipulation of the argument req.func_tool leads to incorrect authorization. The attack may be initiated remotely. The exploit is publicly available and might be used. The identifier of the patch is d23011262e8e75e1ec41b0f1f0091493a022327e. It is suggested to install a patch to address this issue.

4h ago
5.3

Unauthenticated Broken Access Control in Gillion <= 4.13 versions.

4h ago
4.9

Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions.

4h ago
5.9

Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce &#8211; Checkout Manager <= 3.0.5 versions.

4h ago
4.3

Unauthenticated Cross Site Request Forgery (CSRF) in Insert Headers and Footers Code – HT Script <= 1.1.8 versions.

4h ago
6.5

Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions.

4h ago
6.5

Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions.

4h ago
5.4

Subscriber Broken Access Control in YayPricing <= 3.5.6 versions.

4h ago
5.3

Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor <= 2.8.0 versions.

4h ago
4.9

Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions.

4h ago
6.5

Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions.

4h ago
6.5

Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions.

4h ago
4.3

Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.

4h ago
5

Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions.

4h ago
5.3

Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions.

4h ago
5.3

Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions.

4h ago
5.9

Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions.

4h ago
6.5

Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions.

4h ago
6.5

Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.

4h ago
5.4

Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions.

4h ago
5.9

Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.