Total
398490 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-78270 | 2026-08-24 | N/A | 7.6 HIGH | ||
| Author SQL Injection in FluentCRM Pro <= 3.1.12 versions. | |||||
| CVE-2026-32558 | 2026-08-24 | N/A | 9.8 CRITICAL | ||
| Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions. | |||||
| CVE-2026-77004 | 2026-08-24 | 6.5 MEDIUM | 7.4 HIGH | ||
| A flaw has been found in Comfast CF-N1-S 2.6.0.1. This impacts the function sprintf of the file /cgi-bin/mbox-config?method=SET§ion=ptest_sn. Executing a manipulation of the argument sn can lead to command injection. The attack can be launched remotely. The exploit has been published and may be used. | |||||
| CVE-2026-66671 | 2026-08-24 | N/A | 8.1 HIGH | ||
| Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions. | |||||
| CVE-2026-66610 | 2026-08-24 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions. | |||||
| CVE-2026-28164 | 2026-08-24 | N/A | 9.6 CRITICAL | ||
| Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. This issue affects Easy Elementor Addons: from n/a through 2.3.7. | |||||
| CVE-2026-76998 | 2026-08-24 | 7.5 HIGH | 7.3 HIGH | ||
| A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/ajax.php?action=delete_category. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. | |||||
| CVE-2026-78269 | 2026-08-24 | N/A | 6.4 MEDIUM | ||
| Contributor Server Side Request Forgery (SSRF) in Shared Files <= 1.7.69 versions. | |||||
| CVE-2026-32471 | 2026-08-24 | N/A | 8.5 HIGH | ||
| Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions. | |||||
| CVE-2026-28171 | 2026-08-24 | N/A | 8.6 HIGH | ||
| Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions. | |||||
| CVE-2026-78258 | 2026-08-24 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.5 versions. | |||||
| CVE-2026-77148 | 2026-08-24 | 9.0 HIGH | 9.9 CRITICAL | ||
| A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET§ion=ptest_channel of the component Web Management. The manipulation results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used. | |||||
| CVE-2026-66650 | 2026-08-24 | N/A | 9.8 CRITICAL | ||
| Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions. | |||||
| CVE-2026-76995 | 2026-08-24 | 5.8 MEDIUM | 4.7 MEDIUM | ||
| A vulnerability was identified in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /admin/ajax.php?action=save_menu. The manipulation of the argument img leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. | |||||
| CVE-2026-28190 | 2026-08-24 | N/A | 7.1 HIGH | ||
| Subscriber Broken Access Control in ProLancer Element <= 1.4.8 versions. | |||||
| CVE-2026-32477 | 2026-08-24 | N/A | 8.6 HIGH | ||
| Unauthenticated Arbitrary File Deletion in ShopBuilder Pro – Elementor WooCommerce Builder Addons <= 2.2.0 versions. | |||||
| CVE-2026-66599 | 2026-08-24 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 2.9.5.6 versions. | |||||
| CVE-2026-76993 | 2026-08-24 | 5.1 MEDIUM | 5.0 MEDIUM | ||
| A vulnerability was determined in GreyDGL PentestGPT up to 1.0.0. This vulnerability affects unknown code of the component Web-Page Crawling. Executing a manipulation of the argument Traceback can lead to injection. The attack can be executed remotely. A high complexity level is associated with this attack. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. The reported GitHub issue was closed with the label "not planned". | |||||
| CVE-2026-76987 | 2026-08-24 | 7.5 HIGH | 7.3 HIGH | ||
| A security flaw has been discovered in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. The impacted element is the function CipAttribute::GetAttrData/CipAttribute::SetAttrData of the file ciptypes.h of the component Generic Attribute Logic. Performing a manipulation results in memory corruption. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The patch is named e745d9d4a8ca3a13689066983a1269fe1e567674. It is suggested to install a patch to address this issue. | |||||
| CVE-2026-77025 | 2026-08-24 | 6.5 MEDIUM | 6.3 MEDIUM | ||
| A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /viewappointmentpending.php. This manipulation of the argument delid causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. | |||||
