AUGUST 26, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

142,802 records on file
Page 302 of 4,761
CVE ID Score Description
22d ago
8.5

Contributor SQL Injection in Recipe Maker For Your Food Blog from Zip Recipes <= 8.2.7 versions.

22d ago
8.5

Contributor SQL Injection in Contest Gallery <= 30.0.0 versions.

22d ago
8.8

Unauthenticated Cross Site Request Forgery (CSRF) in Paid Memberships Pro - Add Member From Admin <= 0.7.2 versions.

22d ago
8.2

Unauthenticated Cross Site Request Forgery (CSRF) in Child Theme Wizard <= 1.4 versions.

22d ago
8.5

Contributor SQL Injection in WP Job Portal <= 2.5.2 versions.

22d ago
7.5

Contributor Local File Inclusion in Panorama Viewer – 360 Degree Image + Video Viewer <= 1.6.1 versions.

22d ago
8.1

newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions.

22d ago
8.5

Contributor SQL Injection in Restaurant Menu by MotoPress <= 2.4.10 versions.

22d ago
8.5

Contributor SQL Injection in WP Post Author <= 3.9.1 versions.

22d ago
8.5

Contributor SQL Injection in Gallery <= 4.7.8 versions.

22d ago
8.5

Contributor SQL Injection in wpForo Forum <= 3.0.9 versions.

22d ago
7.6

Administrator SQL Injection in Popup box <= 6.0.1 versions.

22d ago
7.6

Administrator SQL Injection in WP All Import <= 4.0.1 versions.

Exploit 22d ago
8.8

Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability that allows attackers who control a proxied web server to achieve arbitrary code execution by embedding a malicious serialized Java object in the javax.faces.ViewState HTTP response parameter. The JSFViewState.decode() method base64-decodes the ViewState value and passes it directly to ObjectInputStream.readObject() without a deserialization filter, allowlist, or type restriction, causing the malicious object to be deserialized within the ZAP JVM when the Desktop UI renders the ViewState panel.

22d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in NanoMag <= 1.8 versions.

22d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in weMail <= 2.1.2 versions.

22d ago
7.1

Contributor Arbitrary File Deletion in H5P <= 1.17.7 versions.

22d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in FOX <= 1.4.8 versions.

22d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 versions.

Exploit 22d ago
8.5

Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.45 versions.

22d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in SureCart <= 4.3.2 versions.

22d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Everest Forms <= 3.4.8 versions.

Exploit 22d ago
8.8

Teable's v2 REST API controller lacks @Permissions metadata on ORPC endpoints, allowing any authenticated user to bypass authorization checks. Attackers can read table schemas, create tables, and modify or delete records across bases and tables via endpoints like GET /api/v2/tables/get and POST /api/v2/tables/updateRecords.

22d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in WoodMart <= 8.5.3 versions.

22d ago
7.5

Unauthenticated Insecure Direct Object References (IDOR) in Toolset Forms <= 2.6.24 versions.

22d ago
8.5

Subscriber SQL Injection in Tourfic <= 2.22.5 versions.

22d ago
8.3

Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions.

22d ago
7.5

Unauthenticated Broken Access Control in Subscriptions for WooCommerce <= 1.9.5 versions.

22d ago
7.5

Unauthenticated Sensitive Data Exposure in Print Invoice & Delivery Notes for WooCommerce <= 7.1.1 versions.

22d ago
8.8

Subscriber PHP Object Injection in RealHomes <= 4.5.3 versions.