Vulnerabilities (CVE)

Total 398490 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-76997 2026-08-24 6.5 MEDIUM 6.3 MEDIUM
A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=save_category. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
CVE-2026-70889 1 Oracle 1 Hyperion Data Relationship Management 2026-08-24 N/A 7.5 HIGH
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
CVE-2026-78279 2026-08-24 N/A 5.4 MEDIUM
Unauthenticated Cross Site Request Forgery (CSRF) in Fluent Support Pro <= 2.3.1 versions.
CVE-2026-28153 2026-08-24 N/A 7.5 HIGH
Unauthenticated Broken Access Control in Notification Master &#8211; Real-Time WordPress Notifications With Email, SMS, Webhooks &amp; More <= 1.7.1 versions.
CVE-2026-78290 2026-08-24 N/A 6.5 MEDIUM
Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions.
CVE-2026-77031 2026-08-24 6.5 MEDIUM 7.4 HIGH
A vulnerability has been found in Tenda CH22 1.0.0.1. The affected element is the function formcreateFileName of the file /goform/formcreateFileName. The manipulation of the argument fileNameMit leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2026-28165 2026-08-24 N/A 9.8 CRITICAL
Unauthenticated Privilege Escalation in Digits <= 9.2 versions.
CVE-2026-28166 2026-08-24 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions.
CVE-2026-74011 2026-08-24 N/A 7.6 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx InfiniteWP Client allows Blind SQL Injection. This issue affects InfiniteWP Client: from n/a through 1.13.9.
CVE-2026-76999 2026-08-24 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects the function add_grade of the file /index.php. Performing a manipulation of the argument student_id results in improper authorization. The attack can be initiated remotely.
CVE-2026-77391 2026-08-24 5.0 MEDIUM 4.3 MEDIUM
A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This affects an unknown function. The manipulation results in cross-site request forgery. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
CVE-2026-66584 2026-08-24 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions.
CVE-2026-78278 2026-08-24 N/A 5.3 MEDIUM
Subscriber Insecure Direct Object References (IDOR) in Fluent Boards Pro <= 2.0.11 versions.
CVE-2026-66670 2026-08-24 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Måne <= 1.7 versions.
CVE-2026-66648 2026-08-24 N/A 9.8 CRITICAL
Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.
CVE-2026-28167 2026-08-24 N/A 7.5 HIGH
Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions.
CVE-2026-78272 2026-08-24 N/A 5.4 MEDIUM
Subscriber Broken Access Control in Fluent Support Pro <= 2.3.1 versions.
CVE-2026-28162 2026-08-24 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions.
CVE-2026-28152 2026-08-24 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions.
CVE-2026-66623 2026-08-24 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions.