CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 13d ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions. |
| 13d ago | 7.1 | Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions. |
| 13d ago | 4.3 | Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions. |
| 13d ago | 5.3 | Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions. |
| 13d ago | 5.3 | Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions. |
| 13d ago | 6.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub Lite allows Stored XSS. This issue affects Hubbub Lite: from n/a through 1.36.3. |
| 13d ago | 5.3 | Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions. |
| 13d ago | 4.3 | Contributor Broken Access Control in uListing <= 2.2.0 versions. |
| 13d ago | 5.4 | Subscriber Broken Access Control in uListing <= 2.2.0 versions. |
| 13d ago | 6.7 | Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions. |
| 13d ago | 6.5 | Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions. |
| 13d ago | 5.3 | Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions. |
| 13d ago | 9.1 | Editor Arbitrary File Upload in Mailster <= 4.1.17 versions. |
| 13d ago | 5.3 | Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions. |
| 13d ago | 5.4 | Subscriber Broken Access Control in eRoom <= 1.7.1 versions. |
| 13d ago | 4.3 | Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions. |
| 13d ago | 8.5 | Contributor SQL Injection in eRoom <= 1.7.1 versions. |
| 13d ago | 4.4 | Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions. |
| 13d ago | 5.9 | Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions. |
| 13d ago | 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in John-Michael L'Allier Create allows Blind SQL Injection. This issue affects Create: from n/a through 2.5.3. |
| 13d ago | 4.3 | Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions. |
| 13d ago | 5.9 | Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions. |
| Exploit 13d ago | 7.5 | A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer advertisement, leading to denial of service. |
| Exploit 13d ago | 8.8 | A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure. |
| 13d ago | 8.2 | Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions. |
| 13d ago | 8.1 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - The editor popup could expose restricted module data to authenticated users without the required module permissions or valid request tokens. |
| 13d ago | 6.1 | Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitrary inline JavaScript. |
| 13d ago | 7.5 | Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension - Date-sensitive query cache keys did not retain a bounded time component. Cached results could remain active across future publication or expiry boundaries, potentially exposing content after it should become unavailable. |
| 13d ago | 7.5 | Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the site directory. |
| 13d ago | 6.5 | Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension - Modals gallery paths could enumerate unintended directories. |