AUGUST 17, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

164,222 records on file
Page 99 of 5,475
CVE ID Score Description
8m ago
6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery allows Stored XSS. This issue affects Modula Image Gallery: from 2.14.25 through 2.14.30.

8m ago
5.3

Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.

8m ago
6.5

Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12 versions.

8m ago
5.3

Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.

8m ago
6.5

Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions.

8m ago
5.3

Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions.

8m ago
5.3

Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions.

8m ago
4.9

Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.

8m ago
4.9

Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions.

8m ago
6.5

Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions.

8m ago
5.4

Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions.

8m ago
5.4

Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.

8m ago
4.3

Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions.

8m ago
4.3

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Chouby Polylang and Chouby Polylang Pro allows Retrieve Embedded Sensitive Data. This issue affects Polylang: through 3.8.5; Polylang Pro: through 3.8.5.

8m ago
4.3

Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions.

8m ago
4.3

Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions.

8m ago
5.3

Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.

8m ago
5.3

Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.

8m ago
6.5

Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions.

8m ago
4.3

In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking

8m ago
5.4

Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.

8m ago
4.3

Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.

8m ago
5.3

Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.

8m ago
6.5

Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.

8m ago
6.5

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6.

8m ago
6.5

Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.

8m ago
6.5

Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.

8m ago
6.5

Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions.

8m ago
6.5

Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions.

8m ago
6.5

Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions.