OCTOBER 8, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

150,913 records on file
Page 44 of 5,031
CVE ID Score Description
1h ago
7.1

Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 5.6.7 versions.

1h ago
7.1

Unauthenticated Cross Site Scripting (XSS) in YITH WooCommerce Ajax Search <= 2.28.0 versions.

1h ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 6.1.3 versions.

1h ago
7.5

Unauthenticated Broken Access Control in Bookly <= 28.2 versions.

1h ago
7.6

Author SQL Injection in WP ERP <= 1.17.9 versions.

1h ago
7.6

Administrator SQL Injection in Estatik <= 4.3.5 versions.

1h ago
7.2

Custom role PHP Object Injection in eCommerce Product Catalog <= 3.6.0 versions.

1h ago
7.2

Custom role PHP Object Injection in WP ERP <= 1.17.9 versions.

1h ago
7.5

An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF; WSS4J decodes this while resolving the signature's key reference, before the message is authenticated, so an eleven-byte extension triggers a 2 GB allocation. Repeated requests exhaust server memory. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.

1h ago
7.5

Unauthenticated Broken Access Control in Hostinger Migrator <= 1.0 versions.

1h ago
8.8

Subscriber PHP Object Injection in Conversational Forms for ChatBot <= 1.5.0 versions.

1h ago
8.8

Contributor PHP Object Injection in DesignSetGo <= 2.8.0 versions.

1h ago
8.8

Contributor PHP Object Injection in Go Live Update Urls <= 7.0.8 versions.

1h ago
7.2

Shop manager PHP Object Injection in Kadence WooCommerce Email Designer <= 1.5.19.1 versions.

1h ago
7.1

Subscriber Broken Access Control in FormGent <= 1.12.2 versions.

1h ago
7.5

Subscriber Privilege Escalation in Import and export users and customers <= 2.5.2 versions.

1h ago
8.5

Unauthenticated SQL Injection in GamiPress <= 8.0.2 versions.

1h ago
7.5

Unauthenticated Arbitrary File Download in NextGEN Gallery <= 4.5.0 versions.

1h ago
7.2

Editor PHP Object Injection in Responsive Slider Gallery <= 1.5.5 versions.

1h ago
8.8

Contributor PHP Object Injection in 10Web Booster – Website speed optimization, Cache & Page Speed optimizer <= 2.33.6 versions.

1h ago
7.5

Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms <= 2.7.2 versions.

1h ago
8.5

Contributor SQL Injection in Easy Pricing Tables <= 4.1.2 versions.

1h ago
7.6

Author SQL Injection in Quiz Cat <= 3.1.1 versions.

1h ago
7.1

Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions.

1h ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.3.1 versions.

1h ago
8.8

Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions.

1h ago
7.2

Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions.

1h ago
7.1

Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.13 versions.

1h ago
7.2

Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions.

1h ago
7.2

Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions.