Total
398490 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-76997 | 2026-08-24 | 6.5 MEDIUM | 6.3 MEDIUM | ||
| A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=save_category. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. | |||||
| CVE-2026-70889 | 1 Oracle | 1 Hyperion Data Relationship Management | 2026-08-24 | N/A | 7.5 HIGH |
| Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). | |||||
| CVE-2026-78279 | 2026-08-24 | N/A | 5.4 MEDIUM | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in Fluent Support Pro <= 2.3.1 versions. | |||||
| CVE-2026-28153 | 2026-08-24 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More <= 1.7.1 versions. | |||||
| CVE-2026-78290 | 2026-08-24 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions. | |||||
| CVE-2026-77031 | 2026-08-24 | 6.5 MEDIUM | 7.4 HIGH | ||
| A vulnerability has been found in Tenda CH22 1.0.0.1. The affected element is the function formcreateFileName of the file /goform/formcreateFileName. The manipulation of the argument fileNameMit leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |||||
| CVE-2026-28165 | 2026-08-24 | N/A | 9.8 CRITICAL | ||
| Unauthenticated Privilege Escalation in Digits <= 9.2 versions. | |||||
| CVE-2026-28166 | 2026-08-24 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions. | |||||
| CVE-2026-74011 | 2026-08-24 | N/A | 7.6 HIGH | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx InfiniteWP Client allows Blind SQL Injection. This issue affects InfiniteWP Client: from n/a through 1.13.9. | |||||
| CVE-2026-76999 | 2026-08-24 | 6.5 MEDIUM | 6.3 MEDIUM | ||
| A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects the function add_grade of the file /index.php. Performing a manipulation of the argument student_id results in improper authorization. The attack can be initiated remotely. | |||||
| CVE-2026-77391 | 2026-08-24 | 5.0 MEDIUM | 4.3 MEDIUM | ||
| A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This affects an unknown function. The manipulation results in cross-site request forgery. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. | |||||
| CVE-2026-66584 | 2026-08-24 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions. | |||||
| CVE-2026-78278 | 2026-08-24 | N/A | 5.3 MEDIUM | ||
| Subscriber Insecure Direct Object References (IDOR) in Fluent Boards Pro <= 2.0.11 versions. | |||||
| CVE-2026-66670 | 2026-08-24 | N/A | 8.1 HIGH | ||
| Unauthenticated Local File Inclusion in Måne <= 1.7 versions. | |||||
| CVE-2026-66648 | 2026-08-24 | N/A | 9.8 CRITICAL | ||
| Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions. | |||||
| CVE-2026-28167 | 2026-08-24 | N/A | 7.5 HIGH | ||
| Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions. | |||||
| CVE-2026-78272 | 2026-08-24 | N/A | 5.4 MEDIUM | ||
| Subscriber Broken Access Control in Fluent Support Pro <= 2.3.1 versions. | |||||
| CVE-2026-28162 | 2026-08-24 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions. | |||||
| CVE-2026-28152 | 2026-08-24 | N/A | 8.1 HIGH | ||
| Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions. | |||||
| CVE-2026-66623 | 2026-08-24 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions. | |||||
