SEPTEMBER 21, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

148,198 records on file
Page 482 of 4,940
CVE ID Score Description
1mo ago
8.5

Contributor SQL Injection in WP Job Portal <= 2.5.2 versions.

1mo ago
7.5

Contributor Local File Inclusion in Panorama Viewer – 360 Degree Image + Video Viewer <= 1.6.1 versions.

1mo ago
8.1

newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions.

1mo ago
8.5

Contributor SQL Injection in Restaurant Menu by MotoPress <= 2.4.10 versions.

1mo ago
8.5

Contributor SQL Injection in WP Post Author <= 3.9.1 versions.

1mo ago
8.5

Contributor SQL Injection in Gallery <= 4.7.8 versions.

1mo ago
8.5

Contributor SQL Injection in wpForo Forum <= 3.0.9 versions.

1mo ago
7.6

Administrator SQL Injection in Popup box <= 6.0.1 versions.

1mo ago
7.6

Administrator SQL Injection in WP All Import <= 4.0.1 versions.

Exploit 1mo ago
8.8

Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability that allows attackers who control a proxied web server to achieve arbitrary code execution by embedding a malicious serialized Java object in the javax.faces.ViewState HTTP response parameter. The JSFViewState.decode() method base64-decodes the ViewState value and passes it directly to ObjectInputStream.readObject() without a deserialization filter, allowlist, or type restriction, causing the malicious object to be deserialized within the ZAP JVM when the Desktop UI renders the ViewState panel.

1mo ago
7.1

Unauthenticated Cross Site Scripting (XSS) in NanoMag <= 1.8 versions.

1mo ago
7.1

Unauthenticated Cross Site Scripting (XSS) in weMail <= 2.1.2 versions.

1mo ago
7.1

Contributor Arbitrary File Deletion in H5P <= 1.17.7 versions.

1mo ago
7.1

Unauthenticated Cross Site Scripting (XSS) in FOX <= 1.4.8 versions.

1mo ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 versions.

Exploit 1mo ago
8.5

Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.45 versions.

1mo ago
7.1

Unauthenticated Cross Site Scripting (XSS) in SureCart <= 4.3.2 versions.

1mo ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Everest Forms <= 3.4.8 versions.

Exploit 1mo ago
8.8

Teable's v2 REST API controller lacks @Permissions metadata on ORPC endpoints, allowing any authenticated user to bypass authorization checks. Attackers can read table schemas, create tables, and modify or delete records across bases and tables via endpoints like GET /api/v2/tables/get and POST /api/v2/tables/updateRecords.

1mo ago
7.1

Unauthenticated Cross Site Scripting (XSS) in WoodMart <= 8.5.3 versions.

1mo ago
7.5

Unauthenticated Insecure Direct Object References (IDOR) in Toolset Forms <= 2.6.24 versions.

1mo ago
8.5

Subscriber SQL Injection in Tourfic <= 2.22.5 versions.

1mo ago
8.3

Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions.

1mo ago
7.5

Unauthenticated Broken Access Control in Subscriptions for WooCommerce <= 1.9.5 versions.

1mo ago
7.5

Unauthenticated Sensitive Data Exposure in Print Invoice & Delivery Notes for WooCommerce <= 7.1.1 versions.

1mo ago
8.8

Subscriber PHP Object Injection in RealHomes <= 4.5.3 versions.

1mo ago
7.1

Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.3 versions.

1mo ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Automatic < 3.135.1 versions.

1mo ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Blog2Social <= 8.9.2 versions.

1mo ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions.