Live feed

CVE Feed

Last 30 days — 12,488 matching across all industries.

Showing 40

Auto-refreshupdated 6s ago
CVE-2026-65562
MEDIUM· 6.5

Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions.

29d ago
CVE-2026-65561
MEDIUM· 6.5

Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.

29d ago
CVE-2026-65558
MEDIUM· 5.4

Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions.

29d ago
CVE-2026-65557
MEDIUM· 5.9

Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.

29d ago
CVE-2026-65436
MEDIUM· 6.8

Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions.

29d ago
CVE-2026-65435
MEDIUM· 6.5

Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions.

29d ago
CVE-2026-65434
MEDIUM· 6.5

Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions.

29d ago
CVE-2026-65433
MEDIUM· 6.5

Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg <= 1.5.1 versions.

29d ago
CVE-2026-59560
MEDIUM· 6.5

Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.

29d ago
CVE-2026-59559
MEDIUM· 6.5

Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg <= 1.5.1 versions.

29d ago
CVE-2026-59558
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.

29d ago
CVE-2026-59557
MEDIUM· 6.5

Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.

29d ago
CVE-2026-59556
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions.

29d ago
CVE-2026-59553
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.

29d ago
CVE-2026-59552
HIGH· 7.2

Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer &amp; Embedder <= 1.4.2 versions.

29d ago
CVE-2026-59551
HIGH· 8.5

Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.

29d ago
CVE-2026-59550
CRITICAL· 9.3

Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions.

29d ago
CVE-2026-59549
CRITICAL· 9.3

Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.

29d ago
CVE-2026-59548
HIGH· 7.5

Unauthenticated Sensitive Data Exposure in Byteflows Travel &amp; Hotel Booking <= 1.0.0 versions.

29d ago
CVE-2026-59546
HIGH· 7.4

Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions.

29d ago
CVE-2026-59539
HIGH· 7.5

Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions.

29d ago
CVE-2026-59538
CRITICAL· 9.3

Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.

29d ago
CVE-2026-59537
HIGH· 7.6

Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versions.

29d ago
CVE-2026-59536
HIGH· 7.5

Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.

29d ago
CVE-2026-59535
HIGH· 7.3

Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.

29d ago
CVE-2026-59534
HIGH· 7.5

Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.

29d ago
CVE-2026-59533
CRITICAL· 9.3

Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.

29d ago
CVE-2026-59532
HIGH· 7.5

Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions.

29d ago
CVE-2026-59531
HIGH· 7.5

Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions.

29d ago
CVE-2026-59530
HIGH· 7.5

Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.

29d ago
CVE-2026-59529
HIGH· 7.5

Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.

29d ago
CVE-2026-59528
HIGH· 7.5

Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.

29d ago
CVE-2026-59527
CRITICAL· 9.3

Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.

29d ago
CVE-2026-10819
MEDIUM· 6.5

Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file size cap on animated GIF uploads, which allows an authenticated attacker to cause a denial of service via a crafted animated GIF uploaded as a custom emoji.. Mattermost Advisory ID: MMSA-2026-00695

mattermost
29d ago
CVE-2026-10600
MEDIUM· 4.3

Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document content extraction which allows an authenticated user with file-upload permission to degrade file uploads for all users on the server via repeatedly uploading small documents that are cheap to upload but expensive to extract, saturating the shared extraction worker pool.. Mattermost Advisory ID: MMSA-2026-00694

mattermost
29d ago
CVE-2025-59181
NONE

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuration Management that could allow an attacker to change directory permissions, denying access to legitimate users.

29d ago
CVE-2025-59180
NONE

Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with knowledge of the hardcoded credential can read alarm and alert information.

29d ago
CVE-2025-59178
NONE

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other users on the system.

29d ago
CVE-2025-59177
NONE

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability in Configuration Management, allowing an attacker to execute specifically crafted commands to reveal system secret through error messages.

29d ago
CVE-2025-59172
NONE

Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vulnerability allowing an attacker to execute arbitrary code as root.

29d ago
Feedback

How was this page?

Spotted something off, or have an idea? Let us know.

0/1000