AUGUST 31, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

367,275 records on file
Page 476 of 12,243
CVE ID Score Description
5d ago
6.5

Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.

5d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions.

5d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.

5d ago
7.2

Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer &amp; Embedder <= 1.4.2 versions.

5d ago
8.5

Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.

5d ago
9.3

Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions.

5d ago
9.3

Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.

5d ago
7.5

Unauthenticated Sensitive Data Exposure in Byteflows Travel &amp; Hotel Booking <= 1.0.0 versions.

5d ago
7.4

Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions.

5d ago
7.5

Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions.

5d ago
9.3

Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.

5d ago
7.6

Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versions.

5d ago
7.5

Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.

5d ago
7.3

Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.

5d ago
7.5

Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.

5d ago
9.3

Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.

5d ago
7.5

Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions.

5d ago
7.5

Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions.

5d ago
7.5

Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.

5d ago
7.5

Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.

5d ago
7.5

Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.

5d ago
9.3

Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.

5d ago
6.5

Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file size cap on animated GIF uploads, which allows an authenticated attacker to cause a denial of service via a crafted animated GIF uploaded as a custom emoji.. Mattermost Advisory ID: MMSA-2026-00695

5d ago
4.3

Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document content extraction which allows an authenticated user with file-upload permission to degrade file uploads for all users on the server via repeatedly uploading small documents that are cheap to upload but expensive to extract, saturating the shared extraction worker pool.. Mattermost Advisory ID: MMSA-2026-00694

5d ago
4.8

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuration Management that could allow an attacker to change directory permissions, denying access to legitimate users.

5d ago
5.1

Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with knowledge of the hardcoded credential can read alarm and alert information.

5d ago
4.8

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other users on the system.

5d ago
6.8

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability in Configuration Management, allowing an attacker to execute specifically crafted commands to reveal system secret through error messages.

5d ago
8.5

Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vulnerability allowing an attacker to execute arbitrary code as root.

5d ago
9.8

Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms.