CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 58m ago | 5.3 | Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions. |
| 58m ago | 5.9 | Author Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions. |
| 58m ago | 6.5 | Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions. |
| Exploit 58m ago | 5.4 | basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager and Prometheus proxy controllers. An unauthenticated attacker can induce a logged-in user's browser to submit requests that are forwarded to enabled upstream write or management endpoints, such as creating an Alertmanager silence or requesting a Prometheus reload. The final impact depends on the APIs enabled by the upstream services. |
| 58m ago | 6.5 | Subscriber Broken Access Control in Motors <= 1.4.113 versions. |
| 58m ago | 6.3 | Unauthenticated Broken Access Control in Anti Spam and list cleaner – AcyChecker <= 2.0.0 versions. |
| 58m ago | 6.5 | Customer Cross Site Scripting (XSS) in WpBookingly <= 1.3.2 versions. |
| 58m ago | 6.5 | Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions. |
| 58m ago | 6 | Subscriber Server Side Request Forgery (SSRF) in Vehica Core <= 1.0.104 versions. |
| 58m ago | 6.5 | Subscriber Cross Site Scripting (XSS) in Accordion <= 3.0.6 versions. |
| 58m ago | 6.5 | Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions. |
| 58m ago | 6.5 | Unauthenticated Broken Access Control in Internal Link Optimiser <= 5.2.7 versions. |
| 58m ago | 6.5 | Subscriber Cross Site Scripting (XSS) in AfterShip Tracking <= 1.18.1 versions. |
| 58m ago | 6.5 | Unauthenticated Broken Access Control in AI for SEO <= 2.4.2 versions. |
| 58m ago | 6.5 | Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions. |
| 58m ago | 6 | Subscriber Broken Access Control in ReactPress <= 3.4.0 versions. |
| 58m ago | 6.5 | Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versions. |
| 58m ago | 6.5 | Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions. |
| 58m ago | 6.5 | Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions. |
| 58m ago | 6.5 | Subscriber Cross Site Scripting (XSS) in AcyMailing SMTP Newsletter <= 10.11.1 versions. |
| 58m ago | 6.5 | Subscriber Broken Access Control in AcyMailing SMTP Newsletter <= 10.11.1 versions. |
| 58m ago | 6.5 | Customer Sensitive Data Exposure in WP Event SOlution <= 4.1.18 versions. |
| 58m ago | 6.5 | Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions. |
| 58m ago | 6.5 | Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso <= 358 versions. |
| 58m ago | 6.5 | Subscriber Broken Access Control in Tourfic <= 2.23.1 versions. |
| 58m ago | 6.5 | Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.11.2 versions. |
| 58m ago | 4.3 | HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security impact under certain conditions. |
| Exploit 58m ago | 5.1 | Stored Cross-site Scripting (CWE-79) in the user management component in maalfer Pentestify before 1.1.1 allows an authenticated attacker to execute arbitrary JavaScript in the browser of another authenticated user via a crafted username, because the frontend escapes the username with escapeHTML() before interpolating it into the onclick attribute of the account deletion button, but the browser HTML-decodes attribute values before the JavaScript engine parses the handler, allowing an encoded single quote (') to break out of the string literal and inject arbitrary JavaScript that executes when the victim clicks the delete button for that account. |
| 58m ago | 5.6 | HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or scripted requests may be submitted without adequate rate limiting or challenge mechanisms, potentially resulting in unintended behavior or security impact under certain conditions. |
| Exploit 58m ago | 6.3 | A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a local unprivileged user to perform a symlink attack. By creating a symlink in a world-writable directory, an attacker can redirect privileged writes to an arbitrary file during script execution in a privileged context. This can lead to the overwrite of root-owned files, potentially disrupting system services or operation. Exploitation is conditional on the script running with elevated privileges and may be mitigated by sticky-directory symlink protections. |