Vulnerabilities (CVE)

Total 398504 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-76372 2026-08-20 N/A 6.6 MEDIUM
In Nmap Scanner versions below 3.0.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR could run the scan network action in a Safe Mode playbook while that action is listed as read-only, which could allow for command execution or other changes on a target system through Nmap Scripting Engine scripts. The vulnerability is possible because the Nmap Scanner connector action manifest classifies the scan network action as read-only even though the action accepts script parameters that can perform write operations. For more information see Manage settings for a playbook in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-cloud/build-playbooks/manage-playbooks-and-playbook-settings/manage-settings-for-a-playbook-in-splunk-soar-cloud) in the Splunk documentation.
CVE-2026-76371 2026-08-20 N/A 2.7 LOW
In FireAMP versions below 2.1.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR could run the add listitem action in a Safe Mode playbook while that action is listed as read-only, which could allow for unauthorized changes to file lists. The vulnerability is possible because the FireAMP connector action manifest classifies the add listitem action as read-only even though the action updates file lists. For more information see Manage settings for a playbook in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-cloud/build-playbooks/manage-playbooks-and-playbook-settings/manage-settings-for-a-playbook-in-splunk-soar-cloud) in the Splunk documentation.
CVE-2026-74014 2026-08-20 N/A 9.9 CRITICAL
Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.
CVE-2026-74001 2026-08-20 N/A 9.8 CRITICAL
Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
CVE-2026-73993 2026-08-20 N/A 9.8 CRITICAL
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
CVE-2026-73992 2026-08-20 N/A 9.9 CRITICAL
Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.
CVE-2026-72845 2026-08-20 N/A N/A
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-68566 2026-08-20 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.
CVE-2026-66682 2026-08-20 N/A 9.8 CRITICAL
Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
CVE-2026-66673 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions.
CVE-2026-66649 2026-08-20 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.
CVE-2026-66615 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Podlove Podcast Publisher <= 4.5.4 versions.
CVE-2026-66605 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 versions.
CVE-2026-66600 2026-08-20 N/A 9.1 CRITICAL
Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions.
CVE-2026-66597 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.4 versions.
CVE-2026-66593 2026-08-20 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.
CVE-2026-66590 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions.
CVE-2026-66582 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions.
CVE-2026-54118 1 Microsoft 5 Sql Server 2016, Sql Server 2017, Sql Server 2019 and 2 more 2026-08-20 N/A 9.8 CRITICAL
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
CVE-2026-54117 1 Microsoft 5 Sql Server 2016, Sql Server 2017, Sql Server 2019 and 2 more 2026-08-20 N/A 9.8 CRITICAL
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.