SEPTEMBER 20, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

169,823 records on file
Page 286 of 5,661
CVE ID Score Description
28d ago
5.4

Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.

28d ago
4.3

Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions.

28d ago
4.3

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Chouby Polylang and Chouby Polylang Pro allows Retrieve Embedded Sensitive Data. This issue affects Polylang: through 3.8.5; Polylang Pro: through 3.8.5.

28d ago
4.3

Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions.

28d ago
4.3

Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions.

28d ago
5.3

Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.

28d ago
5.3

Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.

28d ago
6.5

Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions.

28d ago
4.3

In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking

28d ago
5.4

Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.

28d ago
4.3

Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.

28d ago
5.3

Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.

28d ago
6.5

Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.

28d ago
6.5

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6.

28d ago
6.5

Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.

28d ago
6.5

Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.

28d ago
6.5

Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions.

28d ago
6.5

Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions.

28d ago
6.5

Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions.

28d ago
5.3

Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions.

28d ago
6.3

Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions.

28d ago
6.5

Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions.

28d ago
6.5

Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions.

28d ago
6.5

Customer Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.4 versions.

28d ago
4.3

Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions.

28d ago
5.3

Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions.

28d ago
5.3

Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions.

28d ago
6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub Lite allows Stored XSS. This issue affects Hubbub Lite: from n/a through 1.36.3.

28d ago
5.3

Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions.

28d ago
4.3

Contributor Broken Access Control in uListing <= 2.2.0 versions.