CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| Exploit 4h ago | 9.8 | Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying operating system with root privileges. Exploitation may lead to a complete system takeover by an attacker. This vulnerability is considered critical as it allows an unauthenticated remote attacker to achieve arbitrary code execution as root, potentially compromising the entire VSI deployment and underlying infrastructure. Dell recommends customers to upgrade at the earliest opportunity. |
| 4h ago | 7.5 | Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions. |
| 4h ago | 7.1 | Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency <= 5.5.6 versions. |
| 4h ago | 8.1 | Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions. |
| Exploit 4h ago | 9.1 | Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions. |
| 4h ago | 8.2 | Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions. |
| 4h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions. |
| 4h ago | 5.9 | Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions. |
| 4h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions. |
| 4h ago | 6.5 | Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions. |
| 4h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions. |
| 4h ago | 5.3 | Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions. |
| 4h ago | 5.3 | Custom role Broken Access Control in Dokan <= 5.0.10 versions. |
| 4h ago | 4.3 | Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions. |
| 4h ago | 6.5 | Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions. |
| 4h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions. |
| 4h ago | 4.3 | Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions. |
| 4h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions. |
| 4h ago | 6.5 | Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions. |
| 4h ago | 6.5 | Unauthenticated Cross Site Request Forgery (CSRF) in Plugins Garbage Collector (Database Cleanup) <= 0.14 versions. |
| 4h ago | 5.3 | Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions. |
| 4h ago | 5.3 | Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions. |
| 4h ago | 5.3 | Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions. |
| 4h ago | 4.3 | Unauthenticated Cross Site Request Forgery (CSRF) in Theme My Login <= 7.1.14 versions. |
| 4h ago | 4.3 | Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions. |
| 4h ago | 10 | Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions. |
| 4h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions. |
| 4h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions. |
| 4h ago | 9.8 | Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions. |
| 4h ago | 7.1 | Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions. |