Total
398094 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-81271 | 2026-08-28 | N/A | 8.8 HIGH | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions. | |||||
| CVE-2026-78281 | 2026-08-28 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions. | |||||
| CVE-2026-78261 | 2026-08-28 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions. | |||||
| CVE-2026-27330 | 2026-08-28 | N/A | 8.6 HIGH | ||
| Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions. | |||||
| CVE-2026-81277 | 2026-08-28 | N/A | 8.5 HIGH | ||
| Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions. | |||||
| CVE-2026-32564 | 2026-08-28 | N/A | 8.5 HIGH | ||
| Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. | |||||
| CVE-2026-78292 | 2026-08-28 | N/A | 9.8 CRITICAL | ||
| Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions. | |||||
| CVE-2026-78283 | 2026-08-28 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions. | |||||
| CVE-2026-78293 | 2026-08-28 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions. | |||||
| CVE-2026-81274 | 2026-08-28 | N/A | 5.3 MEDIUM | ||
| Subscriber Broken Access Control in Ditty <= 3.1.67 versions. | |||||
| CVE-2026-81491 | 2026-08-28 | 7.5 HIGH | 7.3 HIGH | ||
| A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_notes/teleport_notes/sync_notes/project_folder of the file src/index.ts. Executing a manipulation can lead to path traversal. It is possible to launch the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. | |||||
| CVE-2026-81279 | 2026-08-28 | N/A | 5.4 MEDIUM | ||
| Subscriber Broken Access Control in Push Notification for Post and BuddyPress <= 3.20 versions. | |||||
| CVE-2026-78257 | 2026-08-28 | N/A | 8.8 HIGH | ||
| Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions. | |||||
| CVE-2026-78271 | 2026-08-28 | N/A | 7.2 HIGH | ||
| Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions. | |||||
| CVE-2026-81202 | 2026-08-28 | 7.5 HIGH | 7.3 HIGH | ||
| A flaw has been found in itsourcecode Payroll System 1.0. The impacted element is the function create/read/update/delete of the file ajax.php of the component CRUD Operation Handler. Executing a manipulation of the argument action can lead to missing authentication. The attack may be performed from remote. The exploit has been published and may be used. | |||||
| CVE-2026-78289 | 2026-08-28 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions. | |||||
| CVE-2026-5097 | 2026-08-28 | N/A | 7.5 HIGH | ||
| The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'referer' parameter in all versions up to, and including, 2.4.17. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | |||||
| CVE-2026-78274 | 2026-08-28 | N/A | 9.1 CRITICAL | ||
| Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions. | |||||
| CVE-2026-81273 | 2026-08-28 | N/A | 8.1 HIGH | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions. | |||||
| CVE-2026-81562 | 2026-08-28 | 4.3 MEDIUM | 5.3 MEDIUM | ||
| A security flaw has been discovered in AlexGladkov claude-in-mobile 3.10.2. This affects the function execSync of the file src/adb/client.ts. Performing a manipulation results in os command injection. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. Upgrading to version 3.10.3 is able to mitigate this issue. The patch is named a86d9e55694c98a122943eeff859461d0b9aa6d6. It is suggested to upgrade the affected component. | |||||
