SEPTEMBER 23, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

378,884 records on file
Page 582 of 12,630
CVE ID Score Description
5d ago
7.5

Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions.

5d ago
9.8

Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.

5d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions.

5d ago
7.2

Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.

5d ago
9.8

Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.

5d ago
9.3

Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions.

5d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in URL Shortify <= 2.5.0 versions.

5d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Recipe Card Blocks for Gutenberg & Elementor <= 3.4.18 versions.

5d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions.

5d ago
6.5

Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions.

5d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Affiliates Manager <= 2.9.53 versions.

5d ago
8.2

Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions.

5d ago
9.3

Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions.

5d ago
6.5

Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions.

5d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions.

5d ago
8.2

Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions.

5d ago
6.5

Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.

5d ago
7.1

Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions.

Exploit 5d ago
10

Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.

5d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 2.4.31 versions.

5d ago
9.8

Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.

5d ago
9.3

Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions.

5d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions.

5d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions.

5d ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate to CVE-2026-14858

5d ago
9.3

Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.

5d ago
7.5

Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions.

Exploit 5d ago
8.9

n8n is an open source workflow automation platform. Prior to 1.123.64, 2.29.8, and 2.30.1, the Git node clone operation allows an authenticated workflow user to swap a validated directory for a symlink before cloning, planting a crafted repository in the community node directory that loads as a custom JavaScript node after restart and executes arbitrary code on the server. This issue is fixed in versions 1.123.64, 2.29.8, and 2.30.1.

Exploit 5d ago
4.3

Copyparty is a portable file server. Prior to 1.20.17, copyparty volumes with the dk or dks directory-key flag combined with the fk or fka file-key flag can convert a valid file key into a directory key, granting read access to the containing folder. This vulnerability was only reachable if both types of keys (filekeys and dirkeys) were manually enabled in the volume flags simultaneously. This issue is fixed in version 1.20.17.

Exploit 5d ago
7.6

Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLHistory, currentRESTSession, currentGQLSession, environments, globalEnvironments, and settings GraphQL paths expose another workspace member's private User data, while toggleHistoryStarStatus and removeRequestFromHistory in the UserHistory service accept another user's history identifier without enforcing userUid ownership, allowing an authenticated workspace member to read private request history, session data, request contents, authorization headers, environment values, and settings and to modify or delete the victim's private history entries. This issue is fixed in version 2026.6.0.