SEPTEMBER 17, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

36,259 records on file
Page 963 of 1,209
CVE ID Score Description
Exploit 1mo ago
9.8

drivers/media/usb/dvb-usb/technisat-usb2.c in the Linux kernel through 5.2.9 has an out-of-bounds read via crafted USB device traffic (which may be remote via usbip or usbredir).

1mo ago
9.8

drivers/net/wireless/rsi/rsi_91x_usb.c in the Linux kernel through 5.2.9 has a Double Free via crafted USB device traffic (which may be remote via usbip or usbredir).

1mo ago
9.8

The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection.

1mo ago
9.8

The email-newsletter plugin through 20.15 for WordPress has SQL injection.

1mo ago
9.8

The slidedeck2 plugin before 2.3.5 for WordPress has file inclusion.

1mo ago
9.1

The insert-pages plugin before 3.2.4 for WordPress has directory traversal via custom template paths.

1mo ago
9.8

The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number.

1mo ago
9.1

The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal.

1mo ago
9.8

The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication.

1mo ago
9.8

The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection.

1mo ago
9.8

Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the auto-update feature of IDVRUpdateService2 in DVRServer.exe. An attacker can upload files with a Setup-Files action, and then execute these files with SYSTEM privileges.

1mo ago
9.8

Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.dll in AuditTrailService in SMServer.exe. This method triggers insecure deserialization within the .NET garbage collector, in which a gadget (contained in a serialized object) may be executed with SYSTEM privileges. The attacker must properly encrypt the object; however, the hardcoded keys are available.

1mo ago
9.8

The shortcode-factory plugin before 2.8 for WordPress has Local File Inclusion.

1mo ago
9.8

The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled.

1mo ago
9.8

The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled.

1mo ago
9.8

The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce.

1mo ago
9.8

The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay-rec.

1mo ago
9.8

The patreon-connect plugin before 1.2.2 for WordPress has Object Injection.

1mo ago
9.8

The post-pay-counter plugin before 2.731 for WordPress has PHP Object Injection.

Exploit 1mo ago
9.8

The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or user shortcode.

1mo ago
10

The nelio-ab-testing plugin before 4.5.11 for WordPress has SSRF in ajax/iesupport.php.

1mo ago
10

The nelio-ab-testing plugin before 4.5.9 for WordPress has SSRF in ajax/iesupport.php.

1mo ago
9.8

The woocommerce-store-toolkit plugin before 1.5.8 for WordPress has privilege escalation.

1mo ago
9.8

The woocommerce-store-toolkit plugin before 1.5.7 for WordPress has privilege escalation.

1mo ago
9.8

The memphis-documents-library plugin before 3.0 for WordPress has Local File Inclusion.

1mo ago
9.8

The memphis-documents-library plugin before 3.0 for WordPress has Remote File Inclusion.

1mo ago
9.8

The yikes-inc-easy-mailchimp-extender plugin before 6.5.3 for WordPress has code injection via the admin input field.

1mo ago
9.1

The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests.

1mo ago
9.8

The contact-form-7 plugin before 5.0.4 for WordPress has privilege escalation because of capability_type mishandling in register_post_type.

1mo ago
9.8

The simple-login-log plugin before 1.1.2 for WordPress has SQL injection.