47974+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.
Subscriber Cross Site Scripting (XSS) in oik <= 4.15.4 versions.
Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versions.
Subscriber Broken Access Control in MakeCommerce for WooCommerce <= 4.1.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Trusted Shops Easy Integration for WooCommerce <= 2.0.6 versions.
Custom role Privilege Escalation in Vitepos <= 3.5.0 versions.
Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 5.6.7 versions.
Unauthenticated Cross Site Scripting (XSS) in YITH WooCommerce Ajax Search <= 2.28.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 6.1.3 versions.
Unauthenticated Broken Access Control in Bookly <= 28.2 versions.
Author SQL Injection in WP ERP <= 1.17.9 versions.
Administrator SQL Injection in Estatik <= 4.3.5 versions.
Custom role PHP Object Injection in eCommerce Product Catalog <= 3.6.0 versions.
Custom role PHP Object Injection in WP ERP <= 1.17.9 versions.
An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 …
Unauthenticated Broken Access Control in Hostinger Migrator <= 1.0 versions.
Subscriber PHP Object Injection in Conversational Forms for ChatBot <= 1.5.0 versions.
Contributor PHP Object Injection in DesignSetGo <= 2.8.0 versions.
Contributor PHP Object Injection in Go Live Update Urls <= 7.0.8 versions.
Shop manager PHP Object Injection in Kadence WooCommerce Email Designer <= 1.5.19.1 versions.
Subscriber Broken Access Control in FormGent <= 1.12.2 versions.
Subscriber Privilege Escalation in Import and export users and customers <= 2.5.2 versions.
Unauthenticated SQL Injection in GamiPress <= 8.0.2 versions.
Unauthenticated Arbitrary File Download in NextGEN Gallery <= 4.5.0 versions.
Editor PHP Object Injection in Responsive Slider Gallery <= 1.5.5 versions.
Contributor PHP Object Injection in 10Web Booster – Website speed optimization, Cache & Page Speed optimizer <= 2.33.6 versions.
Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms <= 2.7.2 versions.
Contributor SQL Injection in Easy Pricing Tables <= 4.1.2 versions.
Author SQL Injection in Quiz Cat <= 3.1.1 versions.
Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.3.1 versions.
Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions.
Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions.
Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.13 versions.
Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions.
Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions.
Unauthenticated SQL Injection in WP Data Access <= 5.5.84 versions.
Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5.2 versions.
Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions.
In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside signed content" flag permanently set. The WS-SecurityPolicy enforcer …
Administrator SQL Injection in WP Activity Log <= 5.6.6 versions.
Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.13.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic <= 1.5.5 versions.
Unauthenticated Cross Site Scripting (XSS) in Easy Google Maps <= 1.14.6 versions.
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.
Unauthenticated Cross Site Scripting (XSS) in If-So Dynamic Content Personalization <= 1.10.1 versions.
Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. This could permit cryptographically weak keys or excessive CPU and memory consumption when processing …
A trust-boundary flaw in CRI-O's sandbox state persistence allows attacker-influenced pod metadata to overwrite CRI-O's own reserved sandbox bookkeeping; once reloaded as trusted after a …
A heap-based buffer overflow flaw was found in rpm. RPMTAG_FILESIGNATURES in a crafted, unsigned RPM package's main header is declared with the wrong header type, …
The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker …
Free website and port scanning — find vulnerabilities before attackers do.