60353+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.
A vulnerability was detected in GraphicsMagick up to 1.3.47. Affected by this vulnerability is the function ExtractPostscript of the file coders/wpg.c of the component WPG …
Unauthenticated Sensitive Data Exposure in MPG <= 4.2.3 versions.
Contributor Cross Site Scripting (XSS) in Cool Formkit Lite <= 2.7.8 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Razorpay Payment Links for WooCommerce <= 2.1.5 versions.
Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.86 versions.
Author Cross Site Scripting (XSS) in YITH WooCommerce Tab Manager <= 2.15.0 versions.
Contributor Cross Site Scripting (XSS) in OAuth Server <= 4.5.1 versions.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Strong Testimonials strong-testimonials allows Stored XSS.This issue affects Strong Testimonials: from …
Contributor Broken Access Control in The Events Calendar <= 6.17.5 versions.
Unauthenticated Insecure Direct Object References (IDOR) in Review Schema <= 3.1.0 versions.
Contributor Cross Site Scripting (XSS) in Polylang <= 3.8.9 versions.
Subscriber Cross Site Scripting (XSS) in CMB2 <= 2.13.0 versions.
Subscriber Broken Access Control in Prevent files / folders access <= 2.6.7 versions.
Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12.1 versions.
Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.2 versions.
Unauthenticated Sensitive Data Exposure in Notivo <= 1.4.2 versions.
Unauthenticated Bypass Vulnerability in Paid Member Subscriptions <= 3.0.9 versions.
Unauthenticated Broken Access Control in Blocksy Companion <= 2.1.55 versions.
Subscriber PHP Object Injection in ShortPixel Image Optimizer <= 6.5.5 versions.
Subscriber Broken Access Control in AllAble Connector <= 0.13.4 versions.
Author Arbitrary File Deletion in WEBO MCP <= 3.0.18 versions.
Subscriber Broken Access Control in MCP Content Manager Lite <= 1.1.0 versions.
Subscriber Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions.
Subscriber Cross Site Scripting (XSS) in ThemeREX Addons < 2.45.0 versions.
Subscriber Insecure Direct Object References (IDOR) in Webba Booking <= 6.5.0 versions.
Unauthenticated Insecure Direct Object References (IDOR) in Client Invoicing by Sprout Invoices <= 20.8.17 versions.
Subscriber Insecure Direct Object References (IDOR) in Newsletters, Email Marketing, SMS and Popups by Omnisend <= 1.9.0 versions.
Contributor Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.7 versions.
Unauthenticated Insecure Direct Object References (IDOR) in GiveWP <= 4.16.9 versions.
Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.85 versions.
Subscriber Sensitive Data Exposure in GiveWP <= 4.16.9 versions.
Contributor Cross Site Scripting (XSS) in The Plus Addons for Elementor Page Builder Lite <= 6.5.1 versions.
Subscriber Bypass Vulnerability in All In One WP Security & Firewall <= 5.4.8 versions.
Editor Arbitrary File Deletion in Template Kit – Import <= 1.0.16 versions.
Subscriber Privilege Escalation in FluentBoards <= 2.0.12 versions.
Contributor Cross Site Scripting (XSS) in pixfort Core < 4.3.3 versions.
Subscriber Insecure Direct Object References (IDOR) in Bookly <= 28.2 versions.
Subscriber Cross Site Scripting (XSS) in Profile Builder <= 4.0.2 versions.
Unauthenticated Denial of Service Attack in WP Store Locator < 3.0.0 versions.
Contributor Cross Site Scripting (XSS) in Pixel Manager for WooCommerce <= 1.69.0 versions.
Unauthenticated Insecure Direct Object References (IDOR) in Simply Schedule Appointments <= 1.6.12.31 versions.
Contributor Insecure Direct Object References (IDOR) in Safe SVG <= 2.5.0 versions.
Contributor Insecure Direct Object References (IDOR) in Business Directory <= 6.4.27 versions.
Contributor Cross Site Scripting (XSS) in Safe SVG <= 2.5.0 versions.
Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions.
Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, …
Observable response discrepancy vulnerability in Maksisoft Technology, IT, and Software Industry and Trade Inc. Maksisoft Gym allows Account Footprinting. This issue affects Maksisoft Gym: from …
Subscriber Other Vulnerability Type in Creator LMS <= 1.2.19 versions.
Contributor Insecure Direct Object References (IDOR) in Flexible PDF Coupons <= 1.14.11 versions.
Contributor Cross Site Scripting (XSS) in Happy Addons for Elementor <= 3.23.1 versions.
Free website and port scanning — find vulnerabilities before attackers do.