SEPTEMBER 24, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

379,817 records on file
Page 1279 of 12,661
CVE ID Score Description
1mo ago
7.1

The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress plugin before 2.1.3 does not properly escape a user-supplied parameter before reflecting it into an HTML attribute on a non-nonce-protected AJAX response, allowing unauthenticated attackers to deliver Reflected Cross-Site Scripting against any authenticated user (including administrators) via a crafted URL.

1mo ago
5.9

The WP Magnific Popup WordPress plugin through 1.0 does not properly escape user-controlled link URLs before injecting them into the DOM when displaying image load error messages, allowing authenticated attackers with Author-level access or above to perform Stored Cross-Site Scripting attacks against any visiting user.

1mo ago
—

Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Packaged Air Conditioners (for Japan and outside Japan); Refrigerators (for Japan); Heat Pump Water Heaters / HEMS-Compatible Adapters / Wireless LAN Adapters (for Japan); Bathroom Dryer / Heater / Ventilation Systems (for Japan); Adapters for Airflow Ventilation Systems, Heat Pump Chilled / Hot Water Systems, and Ventilation / Air-Conditioning System Air Resorts (for Japan); Lossnay Central Ventilation Systems (for Japan); Smart Switches for Ventilation Fans and Lossnay (for Japan); IH Cooking Heaters (for Japan); and Rice Cookers (for Japan) allows an attacker within Wi-Fi radio range of an affected product to access the affected product using a hard-coded SSID and password, thereby obtaining device data such as operation status, room set temperature, and room temperature; changing the air-conditioner or Wi-Fi settings; or causing Wi-Fi communication to enter a denial-of-service (DoS) condition.

Exploit 1mo ago
5.8

sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows authentication bypass via certain zero values for lengths.

1mo ago
9.3

Unauthenticated SQL Injection in WP eMember < v10.9.4 versions.

1mo ago
9.8

Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions.

1mo ago
9.8

Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions.

1mo ago
8.8

Subscriber Privilege Escalation in Falang multilanguage <= 1.4.2 versions.

1mo ago
7.6

Subscriber Broken Authentication in Melhor Envio <= 2.16.3 versions.

1mo ago
9.8

Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.4 versions.

1mo ago
7.5

Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions.

1mo ago
6.8

Subscriber Privilege Escalation in JetFormBuilder <= 3.6.1 versions.

1mo ago
7.1

Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.0.1 versions.

1mo ago
9.8

Contributor PHP Object Injection in Fusion Builder <= 3.15.4 versions.

1mo ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Popup box <= 6.2.9 versions.

1mo ago
7.1

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.

1mo ago
7.1

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.

1mo ago
9.3

Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions.

1mo ago
9.3

Unauthenticated SQL Injection in JobSearch <= 3.2.9 versions.

1mo ago
8.5

Subscriber SQL Injection in Cornerstone < 7.8.8 versions.

1mo ago
8.2

Unauthenticated Insecure Direct Object References (IDOR) in Clean Login <= 1.15 versions.

1mo ago
7.2

RadiX AX6600 WiFi 6 Tri-Band Gaming Router contains an OS command injection vulnerability, which may lead to arbitrary command execution with the root privilege by a user who logs in to the web console as an administrator.

1mo ago
9.8

Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions.

1mo ago
9

Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI Generated Forms <= 1.4.5 versions.

1mo ago
7.4

Subscriber Sensitive Data Exposure in PushEngage – Web Push Notifications, eCommerce Automation &amp; Chat Widget <= 4.2.3 versions.

1mo ago
7.5

Unauthenticated Sensitive Data Exposure in JetBlog <= 2.4.8 versions.

Exploit 1mo ago
9.1

A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP server write files outside the configured local destination directory via crafted directory-entry names. No Airflow account is required — the attack surface is any deployment downloading directories from an untrusted SFTP server. Upgrade `apache-airflow-providers-sftp` to 5.8.1 or later.

1mo ago
7.1

Unauthenticated Cross Site Scripting (XSS) in WPFunnels Pro <= 2.9.4 versions.

1mo ago
9.8

Unauthenticated Broken Authentication in wpForo Forum <= 3.1.0 versions.

Exploit 1mo ago
8.5

Subscriber Arbitrary Code Execution in Cornerstone < 7.8.8 versions.