OCTOBER 2, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

382,997 records on file
Page 894 of 12,767
CVE ID Score Description
26d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions.

26d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions.

26d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions.

26d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.

26d ago
6.5

Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions.

Exploit 26d ago
9.1

Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered critical as it allows an unauthenticated attacker to obtain active session credentials and fully impersonate authenticated users, including administrators. Dell recommends customers to upgrade at the earliest opportunity.

Exploit 26d ago
9.1

OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query parameter alongside an absolute path, bypassing the workspace boundary check in resolveReadPathFromContext. Attackers can exploit the vacuous isPathWithinRoot guard to read sensitive files such as the JWT signing secret, SSH private keys, API credentials, and environment variables, enabling full authentication bypass by forging session cookies on password-protected deployments.

Exploit 26d ago
9.8

OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any allowlist, blocklist, or argument validation. The authentication middleware becomes a no-op when UI_PASSWORD is not configured, matching the default Docker deployment, enabling attackers to execute arbitrary OS commands as the application user and retrieve full command output including stdout, stderr, and exit code from the server response.

26d ago
7.5

Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3.

26d ago
7.5

Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue.

26d ago
9.1

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3

26d ago
5.3

Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions.

26d ago
5.3

Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.

26d ago
9.1

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

26d ago
—

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

26d ago
5.3

Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.

26d ago
5.9

Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions.

26d ago
6.5

Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions.

26d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.

26d ago
7.1

Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.

26d ago
5.3

Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions.

26d ago
6.5

Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions.

26d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.

26d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.

26d ago
7.5

Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.

26d ago
9.8

Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.

26d ago
8.8

Contributor Privilege Escalation in Forminator <= 1.56.0 versions.

26d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.

26d ago
9.8

Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.

26d ago
6.5

Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.