AUGUST 17, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

164,222 records on file
Page 100 of 5,475
CVE ID Score Description
56m ago
5.3

Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions.

56m ago
6.3

Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions.

56m ago
6.5

Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions.

56m ago
6.5

Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions.

56m ago
6.5

Customer Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.4 versions.

56m ago
4.3

Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions.

56m ago
5.3

Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions.

56m ago
5.3

Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions.

56m ago
6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub Lite allows Stored XSS. This issue affects Hubbub Lite: from n/a through 1.36.3.

56m ago
5.3

Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions.

56m ago
4.3

Contributor Broken Access Control in uListing <= 2.2.0 versions.

56m ago
5.4

Subscriber Broken Access Control in uListing <= 2.2.0 versions.

56m ago
6.7

Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions.

56m ago
6.5

Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions.

56m ago
5.3

Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions.

56m ago
5.3

Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions.

56m ago
5.4

Subscriber Broken Access Control in eRoom <= 1.7.1 versions.

56m ago
4.3

Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions.

56m ago
4.4

Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.

56m ago
5.9

Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions.

56m ago
4.3

Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions.

56m ago
5.9

Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions.

56m ago
6.1

Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitrary inline JavaScript.

56m ago
6.5

Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension - Modals gallery paths could enumerate unintended directories.

56m ago
6.2

Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension - CDN versioning could check file paths outside the site directory, exposing local file existence and modification metadata.

56m ago
6.5

Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension - GeoIP lookups trusted spoofable forwarded client-IP headers, this could cause GeoIP-rule bypass.

56m ago
6.5

Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension - Custom purge and log paths could escape the site webroot directory.

56m ago
5.4

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension - Administrator URL purges did not consistently require a valid token and cache-management permission.

Exploit 56m ago
6.5

The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9.8 via the 'type' parameter parameter. This makes it possible for authenticated attackers, with shop manager-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. Successful exploitation requires supplying context=edit in the request, which bypasses the content-stripping logic in prepare_item_for_response() and returns the traversed file verbatim in the REST API response.

56m ago
6.5

The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 7.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with admin-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.