CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 1mo ago | 7.1 | The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress plugin before 2.1.3 does not properly escape a user-supplied parameter before reflecting it into an HTML attribute on a non-nonce-protected AJAX response, allowing unauthenticated attackers to deliver Reflected Cross-Site Scripting against any authenticated user (including administrators) via a crafted URL. |
| 1mo ago | 5.9 | The WP Magnific Popup WordPress plugin through 1.0 does not properly escape user-controlled link URLs before injecting them into the DOM when displaying image load error messages, allowing authenticated attackers with Author-level access or above to perform Stored Cross-Site Scripting attacks against any visiting user. |
| 1mo ago | — | Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Packaged Air Conditioners (for Japan and outside Japan); Refrigerators (for Japan); Heat Pump Water Heaters / HEMS-Compatible Adapters / Wireless LAN Adapters (for Japan); Bathroom Dryer / Heater / Ventilation Systems (for Japan); Adapters for Airflow Ventilation Systems, Heat Pump Chilled / Hot Water Systems, and Ventilation / Air-Conditioning System Air Resorts (for Japan); Lossnay Central Ventilation Systems (for Japan); Smart Switches for Ventilation Fans and Lossnay (for Japan); IH Cooking Heaters (for Japan); and Rice Cookers (for Japan) allows an attacker within Wi-Fi radio range of an affected product to access the affected product using a hard-coded SSID and password, thereby obtaining device data such as operation status, room set temperature, and room temperature; changing the air-conditioner or Wi-Fi settings; or causing Wi-Fi communication to enter a denial-of-service (DoS) condition. |
| Exploit 1mo ago | 5.8 | sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows authentication bypass via certain zero values for lengths. |
| 1mo ago | 9.3 | Unauthenticated SQL Injection in WP eMember < v10.9.4 versions. |
| 1mo ago | 9.8 | Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions. |
| 1mo ago | 9.8 | Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions. |
| 1mo ago | 8.8 | Subscriber Privilege Escalation in Falang multilanguage <= 1.4.2 versions. |
| 1mo ago | 7.6 | Subscriber Broken Authentication in Melhor Envio <= 2.16.3 versions. |
| 1mo ago | 9.8 | Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.4 versions. |
| 1mo ago | 7.5 | Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions. |
| 1mo ago | 6.8 | Subscriber Privilege Escalation in JetFormBuilder <= 3.6.1 versions. |
| 1mo ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.0.1 versions. |
| 1mo ago | 9.8 | Contributor PHP Object Injection in Fusion Builder <= 3.15.4 versions. |
| 1mo ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Popup box <= 6.2.9 versions. |
| 1mo ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions. |
| 1mo ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions. |
| 1mo ago | 9.3 | Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions. |
| 1mo ago | 9.3 | Unauthenticated SQL Injection in JobSearch <= 3.2.9 versions. |
| 1mo ago | 8.5 | Subscriber SQL Injection in Cornerstone < 7.8.8 versions. |
| 1mo ago | 8.2 | Unauthenticated Insecure Direct Object References (IDOR) in Clean Login <= 1.15 versions. |
| 1mo ago | 7.2 | RadiX AX6600 WiFi 6 Tri-Band Gaming Router contains an OS command injection vulnerability, which may lead to arbitrary command execution with the root privilege by a user who logs in to the web console as an administrator. |
| 1mo ago | 9.8 | Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions. |
| 1mo ago | 9 | Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI Generated Forms <= 1.4.5 versions. |
| 1mo ago | 7.4 | Subscriber Sensitive Data Exposure in PushEngage – Web Push Notifications, eCommerce Automation & Chat Widget <= 4.2.3 versions. |
| 1mo ago | 7.5 | Unauthenticated Sensitive Data Exposure in JetBlog <= 2.4.8 versions. |
| Exploit 1mo ago | 9.1 | A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP server write files outside the configured local destination directory via crafted directory-entry names. No Airflow account is required — the attack surface is any deployment downloading directories from an untrusted SFTP server. Upgrade `apache-airflow-providers-sftp` to 5.8.1 or later. |
| 1mo ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in WPFunnels Pro <= 2.9.4 versions. |
| 1mo ago | 9.8 | Unauthenticated Broken Authentication in wpForo Forum <= 3.1.0 versions. |
| Exploit 1mo ago | 8.5 | Subscriber Arbitrary Code Execution in Cornerstone < 7.8.8 versions. |