CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 22d ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.3 versions. |
| 22d ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Automatic < 3.135.1 versions. |
| 22d ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Blog2Social <= 8.9.2 versions. |
| 22d ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions. |
| 22d ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Responsive Lightbox <= 2.7.6 versions. |
| 22d ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Gutenverse Form <= 2.4.7 versions. |
| 22d ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Quick Interest Slider <= 3.1.6 versions. |
| 22d ago | 8.8 | Contributor Privilege Escalation in Frisbii Pay <= 1.8.2 versions. |
| 22d ago | 8.6 | Unauthenticated Multiple Vulnerabilities in BitFire Security <= 5.0.3 versions. |
| 22d ago | 8.1 | Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions. |
| 22d ago | 7.5 | Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2.7.4 versions. |
| 22d ago | 7.5 | Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions. |
| 22d ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in MapPress Maps for WordPress <= 2.97.3 versions. |
| 22d ago | 8.8 | Subscriber Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions. |
| 22d ago | 8.8 | Contributor Privilege Escalation in Fusion Builder <= 3.15.4 versions. |
| 22d ago | 7.5 | Unauthenticated Broken Access Control in Stylish Cost Calculator <= 8.3.9 versions. |
| 22d ago | 7.5 | Unauthenticated Broken Access Control in Syncee Premium Dropshipping & Wholesale <= 1.0.27 versions. |
| 22d ago | 7.3 | Unauthenticated Broken Access Control in Newsletters <= 4.13 versions. |
| 22d ago | 7.5 | Unauthenticated Sensitive Data Exposure in Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups <= 2.0.9 versions. |
| 22d ago | 7.5 | Unauthenticated Broken Access Control in Intranet & Private Site – All-In-One Intranet <= 1.8.1 versions. |
| 22d ago | 7.5 | Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions. |
| 22d ago | 7.5 | Unauthenticated Sensitive Data Exposure in Object Cache 4 everyone <= 2.3.2 versions. |
| 22d ago | 7.4 | Unauthenticated Backdoor in Enable CORS <= 2.0.3 versions. |
| 22d ago | 7.5 | Unauthenticated Broken Access Control in Gutenverse Companion <= 2.5.0 versions. |
| 22d ago | 7.6 | Subscriber Insecure Direct Object References (IDOR) in SupportCandy <= 3.4.6 versions. |
| 22d ago | 7.5 | Unauthenticated Sensitive Data Exposure in Ads by WPQuads <= 3.0.3 versions. |
| 22d ago | 7.8 | The KTLS receive path decrypted each record in place, assuming that the mbufs holding received data were anonymous and safe to modify. This assumption does not hold for data placed on a socket by sendfile(2), which can reference file-backed memory directly through non-anonymous M_EXTPG pages or EXT_SFBUF mbufs. When the sender transmits such data over a loopback connection without enabling KTLS on the transmit side, the file-backed mbufs reach the receiver's decryption path unchanged. Decrypting a record in place then overwrites the backing file's page cache instead of a private copy of the data. An unprivileged local user who can read a file can overwrite its contents with data of their choosing by sending the file over a loopback connection on which they have enabled KTLS receive. The write modifies the page cache directly, so it bypasses file flags such as schg and is written back to disk. By overwriting a setuid binary or other trusted file, a local user can escalate privileges, potentially gaining full control of the affected system. |
| 22d ago | 7.5 | An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via supplying a crafted PSD file. |
| 22d ago | 7.5 | Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions. |
| 22d ago | 7.5 | Contributor Local File Inclusion in Splash - Sport Club WordPress Theme for Basketball, Football, Hockey <= 4.4.3 versions. |