CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 1h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 5.6.7 versions. |
| 1h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in YITH WooCommerce Ajax Search <= 2.28.0 versions. |
| 1h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 6.1.3 versions. |
| 1h ago | 7.5 | Unauthenticated Broken Access Control in Bookly <= 28.2 versions. |
| 1h ago | 7.6 | Author SQL Injection in WP ERP <= 1.17.9 versions. |
| 1h ago | 7.6 | Administrator SQL Injection in Estatik <= 4.3.5 versions. |
| 1h ago | 7.2 | Custom role PHP Object Injection in eCommerce Product Catalog <= 3.6.0 versions. |
| 1h ago | 7.2 | Custom role PHP Object Injection in WP ERP <= 1.17.9 versions. |
| 1h ago | 7.5 | An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF; WSS4J decodes this while resolving the signature's key reference, before the message is authenticated, so an eleven-byte extension triggers a 2 GB allocation. Repeated requests exhaust server memory. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue. |
| 1h ago | 7.5 | Unauthenticated Broken Access Control in Hostinger Migrator <= 1.0 versions. |
| 1h ago | 8.8 | Subscriber PHP Object Injection in Conversational Forms for ChatBot <= 1.5.0 versions. |
| 1h ago | 8.8 | Contributor PHP Object Injection in DesignSetGo <= 2.8.0 versions. |
| 1h ago | 8.8 | Contributor PHP Object Injection in Go Live Update Urls <= 7.0.8 versions. |
| 1h ago | 7.2 | Shop manager PHP Object Injection in Kadence WooCommerce Email Designer <= 1.5.19.1 versions. |
| 1h ago | 7.1 | Subscriber Broken Access Control in FormGent <= 1.12.2 versions. |
| 1h ago | 7.5 | Subscriber Privilege Escalation in Import and export users and customers <= 2.5.2 versions. |
| 1h ago | 8.5 | Unauthenticated SQL Injection in GamiPress <= 8.0.2 versions. |
| 1h ago | 7.5 | Unauthenticated Arbitrary File Download in NextGEN Gallery <= 4.5.0 versions. |
| 1h ago | 7.2 | Editor PHP Object Injection in Responsive Slider Gallery <= 1.5.5 versions. |
| 1h ago | 8.8 | Contributor PHP Object Injection in 10Web Booster – Website speed optimization, Cache & Page Speed optimizer <= 2.33.6 versions. |
| 1h ago | 7.5 | Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms <= 2.7.2 versions. |
| 1h ago | 8.5 | Contributor SQL Injection in Easy Pricing Tables <= 4.1.2 versions. |
| 1h ago | 7.6 | Author SQL Injection in Quiz Cat <= 3.1.1 versions. |
| 1h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions. |
| 1h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.3.1 versions. |
| 1h ago | 8.8 | Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions. |
| 1h ago | 7.2 | Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions. |
| 1h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.13 versions. |
| 1h ago | 7.2 | Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions. |
| 1h ago | 7.2 | Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions. |