SEPTEMBER 20, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

148,122 records on file
Page 360 of 4,938
CVE ID Score Description
29d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions.

29d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions.

29d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions.

29d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions.

29d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions.

29d ago
7.1

Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions.

29d ago
7.1

Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions.

29d ago
7.1

Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This issue affects MailPoet: from 5.30.0 through 5.33.0.

29d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions.

29d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions.

29d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Coaching <= 3.9.2 versions.

29d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.7 versions.

29d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions.

29d ago
7.1

Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.

29d ago
8.5

Contributor SQL Injection in eRoom <= 1.7.1 versions.

29d ago
8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in John-Michael L'Allier Create allows Blind SQL Injection. This issue affects Create: from n/a through 2.5.3.

Exploit 29d ago
7.5

A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer advertisement, leading to denial of service.

Exploit 29d ago
8.8

A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure.

29d ago
8.2

Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions.

29d ago
8.1

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - The editor popup could expose restricted module data to authenticated users without the required module permissions or valid request tokens.

29d ago
7.5

Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension - Date-sensitive query cache keys did not retain a bounded time component. Cached results could remain active across future publication or expiry boundaries, potentially exposing content after it should become unavailable.

29d ago
7.5

Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the site directory.

29d ago
7.5

Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in request URLs, causing a credential leakage vulnerability.

29d ago
8.8

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-update requests lacked consistent token and Super User checks, this could cause unauthorized updates.

29d ago
7.5

Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they were images. This could result in SSRF, internal-data access or writing attacker-controlled files into a web-accessible folder.

29d ago
8.8

The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing capability checks and nonce verification in the `MDJM_Permissions::set_permissions()` and `MDJM_Employee_Manager::init()` functions, combined with the absence of server-side allow-list validation on the `employee_roles[]` and `new_role` POST parameters before they are passed to `mdjm_set_employee_role()` and `WP_User::set_role()`. This makes it possible for unauthenticated attackers to grant arbitrary MDJM capabilities — including `mdjm_employee` and `mdjm_employee_edit` — to any registered WordPress role, and subsequently leverage a subscriber-level account to escalate privileges to Administrator. `MDJM_Permissions::init()` is registered on the public WordPress `init` hook without any authentication gate, meaning the role-manipulation endpoint is reachable without any prior login.

29d ago
7.5

RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation

29d ago
7.8

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-update allows OS Command Injection. This issue affects pardus-update: from 0.6.6 before 0.7.0.

29d ago
7.5

A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data.

29d ago
8.4

Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information.