Vulnerabilities (CVE)

Total 398517 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-19926 2026-08-20 7.5 HIGH 7.3 HIGH
A vulnerability has been found in Evergreen up to 3.14.11/3.15.11/3.16.5/3.17-beta1. The affected element is an unknown function of the file /osrf-gateway-v1 of the component open-ils.fielder OpenSRF Service. Such manipulation leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.14.12, 3.15.12, 3.16.6 and 3.17-beta2 is sufficient to fix this issue. The affected component should be upgraded.
CVE-2026-73404 2026-08-20 N/A 6.5 MEDIUM
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.
CVE-2026-76050 2026-08-20 7.5 HIGH 7.3 HIGH
A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This impacts an unknown function of the file /admin/ajax.php?action=delete_menu. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.
CVE-2026-68567 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 1.0.1 versions.
CVE-2026-73396 2026-08-20 N/A 7.1 HIGH
Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.
CVE-2026-73375 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions.
CVE-2026-73348 2026-08-20 N/A 6.5 MEDIUM
Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.
CVE-2026-75080 2026-08-20 7.5 HIGH 7.3 HIGH
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This issue affects some unknown processing of the file /edit_subject1.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
CVE-2026-73382 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions.
CVE-2024-14046 2026-08-20 6.5 MEDIUM 6.3 MEDIUM
A security vulnerability has been detected in OpenBoxes up to 0.9.1. This issue affects the function DocumentController of the file grails-app/controllers/org/pih/warehouse/core/DocumentController.groovy of the component Document Upload Controller. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 0.9.2 is capable of addressing this issue. The identifier of the patch is e945d6bfcec29642f514e7d298dfba2cc6cd7cd4. Upgrading the affected component is recommended.
CVE-2026-73388 2026-08-20 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions.
CVE-2026-28570 2026-08-20 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions.
CVE-2026-73379 2026-08-20 N/A 6.5 MEDIUM
Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.
CVE-2026-19970 2026-08-20 7.5 HIGH 6.3 MEDIUM
A vulnerability was detected in Open Asset Import Library Assimp 17c12da. This affects the function Assimp::MDLImporter::AddBonesToNodeGraph_3DGS_MDL7 of the file code/AssetLib/MDL/MDLLoader.cpp of the component Node Parser. The manipulation of the argument bones_num results in heap-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-74003 2026-08-20 N/A 4.3 MEDIUM
Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions.
CVE-2026-32553 2026-08-20 N/A 7.2 HIGH
Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions.
CVE-2026-66644 2026-08-20 N/A 6.5 MEDIUM
Contributor Cross Site Scripting (XSS) in Typing Effect <= 1.3.7 versions.
CVE-2026-73351 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions.
CVE-2026-75876 2026-08-20 6.5 MEDIUM 6.3 MEDIUM
A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is some unknown functionality of the file ModuleController.java of the component Move Operations. Such manipulation of the argument sourcePath leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-66629 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions.