CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| Exploit 1mo ago | 9.8 | drivers/media/usb/dvb-usb/technisat-usb2.c in the Linux kernel through 5.2.9 has an out-of-bounds read via crafted USB device traffic (which may be remote via usbip or usbredir). |
| 1mo ago | 9.8 | drivers/net/wireless/rsi/rsi_91x_usb.c in the Linux kernel through 5.2.9 has a Double Free via crafted USB device traffic (which may be remote via usbip or usbredir). |
| 1mo ago | 9.8 | The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection. |
| 1mo ago | 9.8 | The email-newsletter plugin through 20.15 for WordPress has SQL injection. |
| 1mo ago | 9.8 | The slidedeck2 plugin before 2.3.5 for WordPress has file inclusion. |
| 1mo ago | 9.1 | The insert-pages plugin before 3.2.4 for WordPress has directory traversal via custom template paths. |
| 1mo ago | 9.8 | The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number. |
| 1mo ago | 9.1 | The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal. |
| 1mo ago | 9.8 | The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication. |
| 1mo ago | 9.8 | The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection. |
| 1mo ago | 9.8 | Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the auto-update feature of IDVRUpdateService2 in DVRServer.exe. An attacker can upload files with a Setup-Files action, and then execute these files with SYSTEM privileges. |
| 1mo ago | 9.8 | Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.dll in AuditTrailService in SMServer.exe. This method triggers insecure deserialization within the .NET garbage collector, in which a gadget (contained in a serialized object) may be executed with SYSTEM privileges. The attacker must properly encrypt the object; however, the hardcoded keys are available. |
| 1mo ago | 9.8 | The shortcode-factory plugin before 2.8 for WordPress has Local File Inclusion. |
| 1mo ago | 9.8 | The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled. |
| 1mo ago | 9.8 | The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled. |
| 1mo ago | 9.8 | The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce. |
| 1mo ago | 9.8 | The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay-rec. |
| 1mo ago | 9.8 | The patreon-connect plugin before 1.2.2 for WordPress has Object Injection. |
| 1mo ago | 9.8 | The post-pay-counter plugin before 2.731 for WordPress has PHP Object Injection. |
| Exploit 1mo ago | 9.8 | The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or user shortcode. |
| 1mo ago | 10 | The nelio-ab-testing plugin before 4.5.11 for WordPress has SSRF in ajax/iesupport.php. |
| 1mo ago | 10 | The nelio-ab-testing plugin before 4.5.9 for WordPress has SSRF in ajax/iesupport.php. |
| 1mo ago | 9.8 | The woocommerce-store-toolkit plugin before 1.5.8 for WordPress has privilege escalation. |
| 1mo ago | 9.8 | The woocommerce-store-toolkit plugin before 1.5.7 for WordPress has privilege escalation. |
| 1mo ago | 9.8 | The memphis-documents-library plugin before 3.0 for WordPress has Local File Inclusion. |
| 1mo ago | 9.8 | The memphis-documents-library plugin before 3.0 for WordPress has Remote File Inclusion. |
| 1mo ago | 9.8 | The yikes-inc-easy-mailchimp-extender plugin before 6.5.3 for WordPress has code injection via the admin input field. |
| 1mo ago | 9.1 | The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests. |
| 1mo ago | 9.8 | The contact-form-7 plugin before 5.0.4 for WordPress has privilege escalation because of capability_type mishandling in register_post_type. |
| 1mo ago | 9.8 | The simple-login-log plugin before 1.1.2 for WordPress has SQL injection. |