CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 23d ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in SweetDate Core < 1.1.5 versions. |
| 23d ago | 8.8 | Subscriber PHP Object Injection in Entrepreneur - Booking for Small Businesses WordPress Theme <= 3.1.3 versions. |
| 23d ago | 8.6 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in EMV JobCareer allows Path Traversal. This issue affects JobCareer: from n/a through 7.3. |
| 23d ago | 8.1 | Unauthenticated Local File Inclusion in Fortius <= 2.3.0 versions. |
| 23d ago | 8.1 | Unauthenticated Local File Inclusion in Snow Club <= 1.1 versions. |
| 23d ago | 8.1 | Unauthenticated Local File Inclusion in Dazzle <= 1.0.0 versions. |
| 23d ago | 8.1 | Unauthenticated Local File Inclusion in LuxMed | Medicine & Healthcare Doctor WordPress Theme <= 1.2.2 versions. |
| 23d ago | 8.1 | Unauthenticated Local File Inclusion in Imba <= 1.5.0 versions. |
| 23d ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Avante < 3.0.5 versions. |
| Exploit 23d ago | 8.8 | In Citrix Cloud through 2025-11-10, an account with read-only access can trigger the beginning of a workflow for write operations, e.g., the system will send a one-time password to an attacker-controlled email address when the attacker attempts to reset the password of a user account. |
| 23d ago | 7.5 | Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4.0.1 versions. |
| 23d ago | 7.1 | The Taskbuilder WordPress plugin before 5.0.8 does not properly sanitise a URL parameter before echoing it into inline JavaScript on a frontend page containing one of its shortcodes, leading to a Reflected Cross-Site Scripting vulnerability that can be triggered against any logged-in user. |
| 23d ago | 7.1 | The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress plugin before 2.1.3 does not properly escape a user-supplied parameter before reflecting it into an HTML attribute on a non-nonce-protected AJAX response, allowing unauthenticated attackers to deliver Reflected Cross-Site Scripting against any authenticated user (including administrators) via a crafted URL. |
| 23d ago | 8.8 | Subscriber Privilege Escalation in Falang multilanguage <= 1.4.2 versions. |
| 23d ago | 7.6 | Subscriber Broken Authentication in Melhor Envio <= 2.16.3 versions. |
| 23d ago | 7.5 | Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions. |
| 23d ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.0.1 versions. |
| 23d ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Popup box <= 6.2.9 versions. |
| 23d ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions. |
| 23d ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions. |
| 23d ago | 8.5 | Subscriber SQL Injection in Cornerstone < 7.8.8 versions. |
| 23d ago | 8.2 | Unauthenticated Insecure Direct Object References (IDOR) in Clean Login <= 1.15 versions. |
| 23d ago | 7.2 | RadiX AX6600 WiFi 6 Tri-Band Gaming Router contains an OS command injection vulnerability, which may lead to arbitrary command execution with the root privilege by a user who logs in to the web console as an administrator. |
| 23d ago | 7.4 | Subscriber Sensitive Data Exposure in PushEngage – Web Push Notifications, eCommerce Automation & Chat Widget <= 4.2.3 versions. |
| 23d ago | 7.5 | Unauthenticated Sensitive Data Exposure in JetBlog <= 2.4.8 versions. |
| 23d ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in WPFunnels Pro <= 2.9.4 versions. |
| Exploit 23d ago | 8.5 | Subscriber Arbitrary Code Execution in Cornerstone < 7.8.8 versions. |
| 23d ago | 8.2 | Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.12 versions. |
| 23d ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.9.1 versions. |
| 23d ago | 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpWax Directorist Booking allows Blind SQL Injection. This issue affects Directorist Booking: from n/a through 3.0.3. |