AUGUST 31, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

367,275 records on file
Page 475 of 12,243
CVE ID Score Description
Exploit 5d ago
9.1

SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.5.1. The vulnerability arises from unsanitized user input passed to the order_by method of the CodeIgniter Query Builder, enabling attackers to perform time-based queries and schema enumeration. Under certain MySQL configurations, the flaw may lead to remote code execution by writing a PHP shell using INTO OUTFILE.

5d ago
5.3

Unauthenticated Broken Access Control in Gillion <= 4.13 versions.

5d ago
4.9

Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions.

5d ago
5.9

Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce &#8211; Checkout Manager <= 3.0.5 versions.

5d ago
4.3

Unauthenticated Cross Site Request Forgery (CSRF) in Insert Headers and Footers Code – HT Script <= 1.1.8 versions.

5d ago
6.5

Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions.

5d ago
6.5

Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions.

5d ago
5.4

Subscriber Broken Access Control in YayPricing <= 3.5.6 versions.

5d ago
5.3

Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor <= 2.8.0 versions.

5d ago
4.9

Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions.

5d ago
6.5

Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions.

5d ago
6.5

Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions.

5d ago
4.3

Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.

5d ago
7.6

Administrator SQL Injection in WP Google Review Slider <= 18.4 versions.

Exploit 5d ago
7.5

NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows unauthenticated attackers on the same network to write arbitrary files by sending a crafted filename containing directory traversal sequences in the JSON item header name field. Attackers can exploit the lack of path validation to write files outside the transfer root directory to arbitrary locations the current user has write access, including the Windows Startup folder, enabling persistent code execution on the next user login.

5d ago
5

Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions.

5d ago
5.3

Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions.

5d ago
5.3

Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions.

5d ago
5.9

Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions.

5d ago
6.5

Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions.

5d ago
6.5

Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.

5d ago
5.4

Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions.

5d ago
5.9

Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.

5d ago
6.8

Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions.

5d ago
6.5

Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions.

5d ago
6.5

Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions.

5d ago
6.5

Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg <= 1.5.1 versions.

5d ago
6.5

Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.

5d ago
6.5

Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg <= 1.5.1 versions.

5d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.