Total
398517 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-19926 | 2026-08-20 | 7.5 HIGH | 7.3 HIGH | ||
| A vulnerability has been found in Evergreen up to 3.14.11/3.15.11/3.16.5/3.17-beta1. The affected element is an unknown function of the file /osrf-gateway-v1 of the component open-ils.fielder OpenSRF Service. Such manipulation leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.14.12, 3.15.12, 3.16.6 and 3.17-beta2 is sufficient to fix this issue. The affected component should be upgraded. | |||||
| CVE-2026-73404 | 2026-08-20 | N/A | 6.5 MEDIUM | ||
| Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions. | |||||
| CVE-2026-76050 | 2026-08-20 | 7.5 HIGH | 7.3 HIGH | ||
| A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This impacts an unknown function of the file /admin/ajax.php?action=delete_menu. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. | |||||
| CVE-2026-68567 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 1.0.1 versions. | |||||
| CVE-2026-73396 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions. | |||||
| CVE-2026-73375 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions. | |||||
| CVE-2026-73348 | 2026-08-20 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions. | |||||
| CVE-2026-75080 | 2026-08-20 | 7.5 HIGH | 7.3 HIGH | ||
| A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This issue affects some unknown processing of the file /edit_subject1.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. | |||||
| CVE-2026-73382 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions. | |||||
| CVE-2024-14046 | 2026-08-20 | 6.5 MEDIUM | 6.3 MEDIUM | ||
| A security vulnerability has been detected in OpenBoxes up to 0.9.1. This issue affects the function DocumentController of the file grails-app/controllers/org/pih/warehouse/core/DocumentController.groovy of the component Document Upload Controller. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 0.9.2 is capable of addressing this issue. The identifier of the patch is e945d6bfcec29642f514e7d298dfba2cc6cd7cd4. Upgrading the affected component is recommended. | |||||
| CVE-2026-73388 | 2026-08-20 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions. | |||||
| CVE-2026-28570 | 2026-08-20 | N/A | 8.1 HIGH | ||
| Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions. | |||||
| CVE-2026-73379 | 2026-08-20 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions. | |||||
| CVE-2026-19970 | 2026-08-20 | 7.5 HIGH | 6.3 MEDIUM | ||
| A vulnerability was detected in Open Asset Import Library Assimp 17c12da. This affects the function Assimp::MDLImporter::AddBonesToNodeGraph_3DGS_MDL7 of the file code/AssetLib/MDL/MDLLoader.cpp of the component Node Parser. The manipulation of the argument bones_num results in heap-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet. | |||||
| CVE-2026-74003 | 2026-08-20 | N/A | 4.3 MEDIUM | ||
| Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions. | |||||
| CVE-2026-32553 | 2026-08-20 | N/A | 7.2 HIGH | ||
| Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions. | |||||
| CVE-2026-66644 | 2026-08-20 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in Typing Effect <= 1.3.7 versions. | |||||
| CVE-2026-73351 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions. | |||||
| CVE-2026-75876 | 2026-08-20 | 6.5 MEDIUM | 6.3 MEDIUM | ||
| A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is some unknown functionality of the file ModuleController.java of the component Move Operations. Such manipulation of the argument sourcePath leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. | |||||
| CVE-2026-66629 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions. | |||||
