CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 1mo ago | 7.6 | Administrator SQL Injection in WP All Import <= 4.0.1 versions. |
| 1mo ago | 4.9 | Subscriber Server Side Request Forgery (SSRF) in Kirki <= 6.0.11 versions. |
| 1mo ago | 4.3 | Subscriber Broken Access Control in WPCafe <= 3.0.14 versions. |
| 1mo ago | 6.5 | Contributor Cross Site Scripting (XSS) in Neve PRO <= 3.1.2 versions. |
| 1mo ago | 6.5 | Contributor Cross Site Scripting (XSS) in SeedProd Pro < 6.19.5 versions. |
| Exploit 1mo ago | 8.8 | Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability that allows attackers who control a proxied web server to achieve arbitrary code execution by embedding a malicious serialized Java object in the javax.faces.ViewState HTTP response parameter. The JSFViewState.decode() method base64-decodes the ViewState value and passes it directly to ObjectInputStream.readObject() without a deserialization filter, allowlist, or type restriction, causing the malicious object to be deserialized within the ZAP JVM when the Desktop UI renders the ViewState panel. |
| 1mo ago | 6.5 | Author Cross Site Scripting (XSS) in Featured Image <= 2.1 versions. |
| 1mo ago | 4.3 | Contributor Broken Access Control in SEOPress PRO <= 9.1.1 versions. |
| 1mo ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in NanoMag <= 1.8 versions. |
| 1mo ago | 6.5 | Unauthenticated Broken Access Control in GIFT4U <= 1.0.10 versions. |
| 1mo ago | 5.8 | Unauthenticated Broken Access Control in Flash & HTML5 Video <= 2.11.0 versions. |
| 1mo ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in weMail <= 2.1.2 versions. |
| 1mo ago | 7.1 | Contributor Arbitrary File Deletion in H5P <= 1.17.7 versions. |
| 1mo ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in FOX <= 1.4.8 versions. |
| 1mo ago | 6.5 | Subscriber Sensitive Data Exposure in Site Reviews <= 8.0.11 versions. |
| 1mo ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 versions. |
| 1mo ago | 6.5 | Subscriber Sensitive Data Exposure in GetGenie <= 4.4.2 versions. |
| Exploit 1mo ago | 8.5 | Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.45 versions. |
| 1mo ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in SureCart <= 4.3.2 versions. |
| 1mo ago | 6.5 | Subscriber Cross Site Scripting (XSS) in SureCart <= 4.2.2 versions. |
| 1mo ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Everest Forms <= 3.4.8 versions. |
| Exploit 1mo ago | 8.8 | Teable's v2 REST API controller lacks @Permissions metadata on ORPC endpoints, allowing any authenticated user to bypass authorization checks. Attackers can read table schemas, create tables, and modify or delete records across bases and tables via endpoints like GET /api/v2/tables/get and POST /api/v2/tables/updateRecords. |
| 1mo ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in WoodMart <= 8.5.3 versions. |
| 1mo ago | 9.3 | Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions. |
| 1mo ago | 7.5 | Unauthenticated Insecure Direct Object References (IDOR) in Toolset Forms <= 2.6.24 versions. |
| 1mo ago | 9.3 | Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions. |
| 1mo ago | 9.3 | Unauthenticated SQL Injection in JetSmartFilters <= 3.8.3 versions. |
| 1mo ago | 5.8 | Unauthenticated Arbitrary File Deletion in ShortPixel Adaptive Images <= 3.11.4 versions. |
| 1mo ago | 8.5 | Subscriber SQL Injection in Tourfic <= 2.22.5 versions. |
| 1mo ago | 8.3 | Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions. |