OCTOBER 8, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

150,883 records on file
Page 42 of 5,030
CVE ID Score Description
5h ago
8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Blind SQL Injection.This issue affects Event Tickets: from n/a through 5.29.5.

5h ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Premmerce Permalink Manager for WooCommerce <= 2.3.13 versions.

5h ago
7.1

Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions.

5h ago
7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kreatura LayerSlider allows Reflected XSS. This issue affects LayerSlider: from n/a through 8.4.0.

5h ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.

5h ago
7.2

Shop Worker Privilege Escalation in SureCart <= 4.7.2 versions.

5h ago
7.5

Contributor Path Traversal in Creator LMS <= 1.2.19 versions.

5h ago
7.5

Unauthenticated Sensitive Data Exposure in BackupEase <= 2.2.2 versions.

5h ago
7.5

Unauthenticated Sensitive Data Exposure in StifLi Backup Tools <= 2.2.7 versions.

5h ago
7.1

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions.

5h ago
7.1

Unauthenticated Cross Site Scripting (XSS) in ThemeREX Addons < 2.45.0 versions.

5h ago
7.5

Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions.

5h ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Ad Inserter <= 2.8.18 versions.

5h ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Happyforms <= 1.26.15 versions.

5h ago
8.8

Unauthenticated Cross Site Request Forgery (CSRF) in Blacklist Manager &#8211; WooCommerce Anti-Fraud, Blacklist &amp; Checkout Verification <= 2.3.1 versions.

Exploit 5h ago
8.8

Contributor Remote Code Execution (RCE) in CartFlows <= 3.2.0 versions.

5h ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Parsi Date <= 6.3 versions.

5h ago
7.2

Editor PHP Object Injection in Ultimate Addons for Contact Form 7 <= 3.5.51 versions.

5h ago
7.2

Shop manager PHP Object Injection in Content Egg <= 6.3.1 versions.

5h ago
8.8

Contributor PHP Object Injection in Themify Builder <= 7.8.1 versions.

5h ago
7.1

Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.9 versions.

5h ago
7.6

Administrator SQL Injection in Category Discount Woocommerce <= 5.18 versions.

5h ago
7.6

Administrator SQL Injection in Admin Notices Manager <= 1.6.0 versions.

5h ago
7.5

Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions.

5h ago
7.1

Subscriber Cross Site Scripting (XSS) in Awesome Support <= 6.3.9 versions.

5h ago
7.1

Subscriber Cross Site Scripting (XSS) in oik <= 4.15.4 versions.

5h ago
7.5

Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versions.

5h ago
8.2

Subscriber Broken Access Control in MakeCommerce for WooCommerce <= 4.1.0 versions.

5h ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Trusted Shops Easy Integration for WooCommerce <= 2.0.6 versions.

5h ago
7.2

Custom role Privilege Escalation in Vitepos <= 3.5.0 versions.