OCTOBER 2, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

383,015 records on file
Page 895 of 12,768
CVE ID Score Description
26d ago
5.3

Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.

26d ago
9.1

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

26d ago
—

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

26d ago
5.3

Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.

26d ago
5.9

Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions.

26d ago
6.5

Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions.

26d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.

26d ago
7.1

Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.

26d ago
5.3

Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions.

26d ago
6.5

Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions.

26d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.

26d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.

26d ago
7.5

Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.

26d ago
9.8

Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.

26d ago
8.8

Contributor Privilege Escalation in Forminator <= 1.56.0 versions.

26d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.

26d ago
9.8

Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.

26d ago
6.5

Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.

Exploit 26d ago
5.3

A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the function SecretDialog.showSecretDialog of the file src/utils/secretDialog.ts of the component get_credential_from_user. This manipulation of the argument Description causes command injection. It is possible to launch the attack on the local host. The project was informed of the problem early through an issue report but has not responded yet.

Exploit 26d ago
5.3

A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of the file src/index.ts of the component create_scene/add_node. This manipulation of the argument projectPath causes command injection. The attack needs to be launched locally. The project was informed of the problem early through an issue report but has not responded yet.

26d ago
4.3

The RealHomes Memberships WordPress plugin before 3.1.0 does not verify that a membership payment actually completed, nor check a nonce or the user's capability, before granting a paid membership package, allowing any authenticated user such as a Subscriber to obtain paid membership packages without paying.

26d ago
7.5

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

Exploit 26d ago
6.8

Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated attacker could potentially exploit this vulnerability leading to loss of confidentiality and integrity.

26d ago
9.8

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. CMS allows SQL Injection. This issue affects CMS: through 06082026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Exploit 26d ago
6.3

A vulnerability has been found in MissionSquad mcp-api up to 1.11.8. The impacted element is the function this.packageService.installPackage of the file src/controllers/packages.ts of the component NPM Package Version Handler. The manipulation leads to command injection. It is possible to initiate the attack remotely. Upgrading to version 1.11.9 is sufficient to resolve this issue. The identifier of the patch is a40f54d4533ba6618e1749383a245900eeb024c1. The affected component should be upgraded.

Exploit 26d ago
6.3

A flaw has been found in MissionSquad mcp-api up to 1.11.9. The affected element is an unknown function of the file src/services/dcrClients.ts. Executing a manipulation can lead to server-side request forgery. The attack may be performed from remote. Upgrading to version 1.11.10 is sufficient to fix this issue. This patch is called f068ab4ad6f0907ac7001b995588c2673f11a755. You should upgrade the affected component.

Exploit 26d ago
6.4

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Badge Widget Variable Substitution in all versions up to, and including, 1.2.69 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

26d ago
8.3

OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attacker to forge valid authentication credentials, bypass authentication and authorization, and impersonate legitimate clients. An attacker can gain full access to the system configuration, allowing modification, reset, or unauthorized alteration of system parameters or injecting network traffic into the connected network.

26d ago
4.3

OMICRON StationGuard 4.00 contains an improper input validation vulnerability in its IEC 61850 Sampled Values (SV) frame processing. A specially crafted SV frame can cause the affected process to terminate, disrupting alert processing for Sampled Values traffic. The vulnerability does not affect overall system availability or the processing of other traffic types, and the process is automatically restarted, and the failure is immediately reported to the user.

26d ago
8.7

OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attacker to forge valid authentication credentials, bypass authentication and authorization, and impersonate legitimate clients. An attacker can gain full access to the system configuration, allowing modification, reset, or unauthorized alteration of system parameters.