Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2018-25165 — Galaxy Forces MMORPG 0.5.8 SQL Injection via ads.php

Galaxy Forces MMORPG 0.5.8 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'type' parameter. Attac…

Remote | Injection
Mar 06, 2026 Mar 09, 2026
Mar 06, 2026
Mar 09, 2026
8.7 HIGH
CVE-2018-25164 — EverSync 0.5 Arbitrary File Download via files Directory

EverSync 0.5 contains an arbitrary file download vulnerability that allows unauthenticated attackers to access sensitive files by requesting them directly from the files directory. Attackers can send…

Remote | Path Traversal
Mar 06, 2026 Mar 09, 2026
Mar 06, 2026
Mar 09, 2026
8.8 HIGH
CVE-2018-25163 — BitZoom 1.0 SQL Injection via rollno Parameter

BitZoom 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the rollno and username parameters in fo…

Remote | Injection
Mar 06, 2026 Mar 09, 2026
Mar 06, 2026
Mar 09, 2026
7.1 HIGH
CVE-2018-25162 — 2-Plan Team 1.0.4 Arbitrary File Upload via managefile.php

2-Plan Team 1.0.4 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload executable PHP files by sending multipart form data to managefile.php. Attackers can up…

Remote | Misconfiguration
Mar 06, 2026 Mar 09, 2026
Mar 06, 2026
Mar 09, 2026
8.8 HIGH
CVE-2018-25161 — Warranty Tracking System 11.06.3 SQL Injection via SearchCustomer.php

Warranty Tracking System 11.06.3 contains an SQL injection vulnerability that allows attackers to execute arbitrary SQL queries by injecting malicious code through the txtCustomerCode, txtCustomerNam…

Remote | Injection
Mar 06, 2026 Mar 09, 2026
Mar 06, 2026
Mar 09, 2026
4.7 MEDIUM
CVE-2026-28106 — WordPress B2BKing Premium plugin < 5.4.20 - Open Redirection vulnerability

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Kings Plugins B2BKing Premium allows Phishing.This issue affects B2BKing Premium: from n/a before 5.4.20.

Remote | Misconfiguration
Mar 06, 2026 Mar 09, 2026
Mar 06, 2026
Mar 09, 2026
4.3 MEDIUM
CVE-2026-28080 — WordPress Rank Math SEO PRO plugin <= 3.0.95 - Broken Access Control vulnerability

Missing Authorization vulnerability in Rank Math Rank Math SEO PRO allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rank Math SEO PRO: from n/a through 3.0.9…

Remote | Authorization
Mar 06, 2026 Mar 09, 2026
Mar 06, 2026
Mar 09, 2026
5.9 MEDIUM
CVE-2024-35644 — WordPress Preferred Languages plugin <= 2.2.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pascal Birchler Preferred Languages allows DOM-Based XSS.This issue affects Preferred Lang…

Remote | Cross-Site Scripting
Mar 06, 2026 Mar 09, 2026
Mar 06, 2026
Mar 09, 2026
5.1 MEDIUM
CVE-2026-1468 — Cross-Site Request Forgery in QuickCMS

QuickCMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. An attacker can craft special website, which when visited by the victim, will automatically send a POST request with vi…

quick.cms | Remote | Cross-Site Request Forgery
Mar 06, 2026 Mar 09, 2026
Mar 06, 2026
Mar 09, 2026
Showing 20 of 5909 Results