CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 24d ago | 5.9 | Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce – Checkout Manager <= 3.0.5 versions. |
| 24d ago | 4.3 | Unauthenticated Cross Site Request Forgery (CSRF) in Insert Headers and Footers Code – HT Script <= 1.1.8 versions. |
| 24d ago | 6.5 | Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions. |
| 24d ago | 6.5 | Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions. |
| 24d ago | 5.4 | Subscriber Broken Access Control in YayPricing <= 3.5.6 versions. |
| 24d ago | 5.3 | Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor <= 2.8.0 versions. |
| 24d ago | 4.9 | Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions. |
| 24d ago | 6.5 | Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions. |
| 24d ago | 6.5 | Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions. |
| 24d ago | 4.3 | Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions. |
| 24d ago | 5 | Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions. |
| 24d ago | 5.3 | Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions. |
| 24d ago | 5.3 | Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions. |
| 24d ago | 5.9 | Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions. |
| 24d ago | 6.5 | Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions. |
| 24d ago | 6.5 | Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions. |
| 24d ago | 5.4 | Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions. |
| 24d ago | 5.9 | Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions. |
| 24d ago | 6.8 | Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions. |
| 24d ago | 6.5 | Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions. |
| 24d ago | 6.5 | Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions. |
| 24d ago | 6.5 | Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions. |
| 24d ago | 6.5 | Subscriber Broken Access Control in FundEngine <= 1.7.8 versions. |
| 24d ago | 6.5 | Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions. |
| 24d ago | 6.5 | Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions. |
| 24d ago | 6.5 | Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file size cap on animated GIF uploads, which allows an authenticated attacker to cause a denial of service via a crafted animated GIF uploaded as a custom emoji.. Mattermost Advisory ID: MMSA-2026-00695 |
| 24d ago | 4.3 | Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document content extraction which allows an authenticated user with file-upload permission to degrade file uploads for all users on the server via repeatedly uploading small documents that are cheap to upload but expensive to extract, saturating the shared extraction worker pool.. Mattermost Advisory ID: MMSA-2026-00694 |
| 24d ago | 4.8 | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuration Management that could allow an attacker to change directory permissions, denying access to legitimate users. |
| 24d ago | 5.1 | Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with knowledge of the hardcoded credential can read alarm and alert information. |
| 24d ago | 4.8 | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other users on the system. |