SEPTEMBER 17, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

36,259 records on file
Page 961 of 1,209
CVE ID Score Description
Exploit 1mo ago
9.8

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

Exploit 1mo ago
9.8

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

Exploit 1mo ago
9.8

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

Exploit 1mo ago
9.8

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

Exploit 1mo ago
9.8

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

Exploit 1mo ago
9.8

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

1mo ago
9.8

An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are instr and mvwinstr buffer overflows because interaction with C functions is mishandled.

1mo ago
9.8

An issue was discovered in the slice-deque crate before 0.2.0 for Rust. There is memory corruption in certain allocation cases.

Exploit 1mo ago
9.8

XENFCoreSharp before 2019-07-16 allows SQL injection in web/verify.php.

1mo ago
9.8

cgi-cpn/xcoding/prontus_videocut.cgi in AltaVoz Prontus (aka ProntusCMS) through 12.0.3.0 has "Improper Neutralization of Special Elements used in an OS Command," allowing attackers to execute OS commands via an HTTP GET parameter.

1mo ago
10

The fetch API in Tightrope Media Carousel before 7.1.3 has CarouselAPI/v0/fetch?url= SSRF. This has two potential areas for abuse. First, a specially crafted URL could be used in a phishing attack to hijack the trust the user and the browser have with the website and could serve malicious content from a third-party attacker-controlled system. Second, arguably more severe, is the potential for an attacker to circumvent firewall controls, by proxying traffic, unauthenticated, into the internal network from the internet.

1mo ago
9.8

An issue was discovered in the arrayfire crate before 3.6.0 for Rust. Addition of the repr() attribute to an enum is mishandled, leading to memory corruption.

1mo ago
9.8

An issue was discovered in the openssl crate before 0.10.9 for Rust. A use-after-free occurs in CMS Signing.

1mo ago
9.8

An issue was discovered in the crossbeam crate before 0.4.1 for Rust. There is a double free because of destructor mishandling.

1mo ago
9.8

An issue was discovered in the slice-deque crate before 0.1.16 for Rust. move_head_unchecked allows memory corruption because deque updates are mishandled.

Exploit 1mo ago
9.8

XM^online 2 Common Utils and Endpoints 0.2.1 allows SQL injection, related to Constants.java, DropSchemaResolver.java, and SchemaChangeResolver.java.

Exploit 1mo ago
9.8

XM^online 2 User Account and Authentication server 1.0.0 allows SQL injection via a tenant key.

Exploit 1mo ago
9.8

FredReinink Wellness-app before 2019-06-19 allows SQL injection, related to dietTrack.php, exerciseGenerator.php, fitnessTrack.php, and server.php.

Exploit 1mo ago
9.8

The Reviews Module before 2019-06-14 for OpenSource Table allows SQL injection in database/index.js.

Exploit 1mo ago
9.8

DianoxDragon Hawn before 2019-07-10 allows SQL injection.

1mo ago
9.1

IBM Open Power Firmware OP910 and OP920 could allow access to BMC via IPMI using default OpenBMC password even after BMC password was changed away from the default password. IBM X-Force ID: 158702.

Exploit 1mo ago
9.8

Gesior-AAC before 2019-05-01 allows serviceID SQL injection in accountmanagement.php.

Exploit 1mo ago
9.8

Gesior-AAC before 2019-05-01 allows SQL injection in tankyou.php.

Exploit 1mo ago
9.8

Gesior-AAC before 2019-05-01 allows ServiceCategoryID SQL injection in shop.php.

Exploit 1mo ago
9.8

The WEB control panel before 2019-04-30 for ClonOS allows SQL injection in clonos.php.

Exploit 1mo ago
9.8

BEdita through 4.0.0-RC2 allows SQL injection during a save operation for a relation with parameters.

Exploit 1mo ago
9.8

HM Courts & Tribunals ccd-data-store-api before 2019-06-10 allows SQL injection, related to SearchQueryFactoryOperation.java and SortDirection.java.

Exploit 1mo ago
9.8

idseq-web before 2019-07-01 in Infectious Disease Sequencing Platform IDseq allows SQL injection via tax_levels.

Exploit 1mo ago
9.8

OpenForis Arena before 2019-05-07 allows SQL injection in the sorting feature.

Exploit 1mo ago
9.8

The Alfresco application before 1.8.7 for Android allows SQL injection in HistorySearchProvider.java.