Vulnerabilities (CVE)

Total 398490 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-78270 2026-08-24 N/A 7.6 HIGH
Author SQL Injection in FluentCRM Pro <= 3.1.12 versions.
CVE-2026-32558 2026-08-24 N/A 9.8 CRITICAL
Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions.
CVE-2026-77004 2026-08-24 6.5 MEDIUM 7.4 HIGH
A flaw has been found in Comfast CF-N1-S 2.6.0.1. This impacts the function sprintf of the file /cgi-bin/mbox-config?method=SET&section=ptest_sn. Executing a manipulation of the argument sn can lead to command injection. The attack can be launched remotely. The exploit has been published and may be used.
CVE-2026-66671 2026-08-24 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions.
CVE-2026-66610 2026-08-24 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions.
CVE-2026-28164 2026-08-24 N/A 9.6 CRITICAL
Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. This issue affects Easy Elementor Addons: from n/a through 2.3.7.
CVE-2026-76998 2026-08-24 7.5 HIGH 7.3 HIGH
A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/ajax.php?action=delete_category. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
CVE-2026-78269 2026-08-24 N/A 6.4 MEDIUM
Contributor Server Side Request Forgery (SSRF) in Shared Files <= 1.7.69 versions.
CVE-2026-32471 2026-08-24 N/A 8.5 HIGH
Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions.
CVE-2026-28171 2026-08-24 N/A 8.6 HIGH
Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions.
CVE-2026-78258 2026-08-24 N/A 5.3 MEDIUM
Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.5 versions.
CVE-2026-77148 2026-08-24 9.0 HIGH 9.9 CRITICAL
A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET&section=ptest_channel of the component Web Management. The manipulation results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.
CVE-2026-66650 2026-08-24 N/A 9.8 CRITICAL
Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.
CVE-2026-76995 2026-08-24 5.8 MEDIUM 4.7 MEDIUM
A vulnerability was identified in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /admin/ajax.php?action=save_menu. The manipulation of the argument img leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
CVE-2026-28190 2026-08-24 N/A 7.1 HIGH
Subscriber Broken Access Control in ProLancer Element <= 1.4.8 versions.
CVE-2026-32477 2026-08-24 N/A 8.6 HIGH
Unauthenticated Arbitrary File Deletion in ShopBuilder Pro – Elementor WooCommerce Builder Addons <= 2.2.0 versions.
CVE-2026-66599 2026-08-24 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 2.9.5.6 versions.
CVE-2026-76993 2026-08-24 5.1 MEDIUM 5.0 MEDIUM
A vulnerability was determined in GreyDGL PentestGPT up to 1.0.0. This vulnerability affects unknown code of the component Web-Page Crawling. Executing a manipulation of the argument Traceback can lead to injection. The attack can be executed remotely. A high complexity level is associated with this attack. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. The reported GitHub issue was closed with the label "not planned".
CVE-2026-76987 2026-08-24 7.5 HIGH 7.3 HIGH
A security flaw has been discovered in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. The impacted element is the function CipAttribute::GetAttrData/CipAttribute::SetAttrData of the file ciptypes.h of the component Generic Attribute Logic. Performing a manipulation results in memory corruption. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The patch is named e745d9d4a8ca3a13689066983a1269fe1e567674. It is suggested to install a patch to address this issue.
CVE-2026-77025 2026-08-24 6.5 MEDIUM 6.3 MEDIUM
A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /viewappointmentpending.php. This manipulation of the argument delid causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.