AUGUST 28, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

143,229 records on file
Page 348 of 4,775
CVE ID Score Description
23d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Popup box <= 6.2.9 versions.

23d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.

23d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.

23d ago
8.5

Subscriber SQL Injection in Cornerstone < 7.8.8 versions.

23d ago
8.2

Unauthenticated Insecure Direct Object References (IDOR) in Clean Login <= 1.15 versions.

23d ago
7.2

RadiX AX6600 WiFi 6 Tri-Band Gaming Router contains an OS command injection vulnerability, which may lead to arbitrary command execution with the root privilege by a user who logs in to the web console as an administrator.

23d ago
7.4

Subscriber Sensitive Data Exposure in PushEngage – Web Push Notifications, eCommerce Automation &amp; Chat Widget <= 4.2.3 versions.

23d ago
7.5

Unauthenticated Sensitive Data Exposure in JetBlog <= 2.4.8 versions.

23d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in WPFunnels Pro <= 2.9.4 versions.

Exploit 23d ago
8.5

Subscriber Arbitrary Code Execution in Cornerstone < 7.8.8 versions.

23d ago
8.2

Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.12 versions.

23d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.9.1 versions.

23d ago
8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpWax Directorist Booking allows Blind SQL Injection. This issue affects Directorist Booking: from n/a through 3.0.3.

23d ago
7.5

Unauthenticated Broken Access Control in JobSearch <= 3.2.7 versions.

23d ago
8.5

Subscriber SQL Injection in Geo Mashup <= 1.13.19 versions.

Exploit 23d ago
7.5

Rocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to unauthenticated file deletion. The deleteFileMessage Meteor method permanently deletes any uploaded file by ID without requiring authentication. When called via an unauthenticated DDP WebSocket connection, Meteor.userId() returns null, causing the authorization check to be skipped. Execution falls through to FileUpload.getStore('Uploads').deleteById(fileID), which removes the file from storage and database unconditionally. File IDs are discoverable from public channel message payloads and download URLs.

23d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Enfold <= 7.1.4 versions.

Exploit 23d ago
8.2

Remark42 is a self-hosted comment engine for blogs, articles, or any other place where readers can add comments. Versions 1.6.0 through 1.15.0 contain a Cross-Site Scripting (XSS) vulnerability exploitable through content-type spoofing. The Remark42 image proxy fetches an arbitrary remote URL and re-serves the response from Remark42's own origin. During the download phase, the proxy determines whether the resource is an image by inspecting only the Content-Type header advertised by the remote server, never examining the actual bytes; during the serving phase, it instead derives the response Content-Type by sniffing those bytes with http.DetectContentType. An attacker can exploit this inconsistency by hosting a URL that advertises Content-Type: image/png while returning an HTML/JavaScript body: the download check accepts it as an image, the serving path sniffs the body and emits Content-Type: text/html, and the browser renders the attacker-controlled HTML/JavaScript as a document within Remark42's origin. Exploitation requires no Remark42 account on the target instance; the attacker only needs to host the malicious upstream URL and deliver the proxy link to a victim by any means, such as email, direct message, or a link on another website. This issue has been fixed in version 1.16.0.

Exploit 23d ago
7.5

ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally small fragments and data chunks, with modest network traffic, to force the remote peer into allocating and holding structural wrappers that consume far more memory than the default documented message-size limit, leading to process termination due to OOM. This issue has been fixed in versions 5.2.5, 6.2.4, 7.5.11, and 8.21.0.

23d ago
8.8

Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2.13.0 versions.

23d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Profile Builder Pro <= 3.15.0 versions.

23d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Kapee < 1.7.1 versions.

23d ago
7.3

Unauthenticated Insecure Direct Object References (IDOR) in Salon booking system <= 10.30.24 versions.

23d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in collectchat <= 2.4.9 versions.

23d ago
8.1

Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions.

23d ago
8.1

Unauthenticated PHP Object Injection in Behold <= 1.5 versions.

23d ago
8.1

Unauthenticated PHP Object Injection in Esmée <= 1.4 versions.

23d ago
8.1

Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions.

23d ago
8.1

Unauthenticated PHP Object Injection in TechLink <= 1.3 versions.

23d ago
8.1

Unauthenticated PHP Object Injection in Roisin <= 1.4 versions.