Vulnerabilities (CVE)

Total 398517 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-32470 2026-08-20 N/A 9.8 CRITICAL
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
CVE-2026-19964 2026-08-20 6.5 MEDIUM 5.5 MEDIUM
A vulnerability was found in Jij-Inc Jij-MCP-Server 0.1.0. This affects the function PythonREPL.run of the file jij_mcp/python_repr.py of the component jm_check. The manipulation of the argument code results in code injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-27365 2026-08-20 N/A 5.9 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress PublishPress Series allows Stored XSS. This issue affects PublishPress Series: from n/a through 2.17.0.
CVE-2026-73359 2026-08-20 N/A 6.5 MEDIUM
Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions.
CVE-2026-74007 2026-08-20 N/A 5.3 MEDIUM
Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions.
CVE-2026-66622 2026-08-20 N/A 7.5 HIGH
Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions.
CVE-2026-73342 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 2.4.31 versions.
CVE-2026-32333 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 versions.
CVE-2026-73364 2026-08-20 N/A 9.8 CRITICAL
Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.
CVE-2026-19934 2026-08-20 6.5 MEDIUM 6.3 MEDIUM
A vulnerability has been found in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /vieworder.php. The manipulation of the argument delid leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
CVE-2026-73355 2026-08-20 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions.
CVE-2026-66635 2026-08-20 N/A 7.4 HIGH
Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions.
CVE-2026-66596 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 versions.
CVE-2026-66633 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions.
CVE-2026-66637 2026-08-20 N/A 6.5 MEDIUM
Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions.
CVE-2026-19994 2026-08-20 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/configuration/cache-management/execute of the component Configuration Management. The manipulation of the argument action results in authorization bypass. The attack may be launched remotely. The exploit has been made public and could be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
CVE-2026-73376 2026-08-20 N/A 9.8 CRITICAL
Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.
CVE-2026-32475 2026-08-20 N/A 9.0 CRITICAL
Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1.
CVE-2024-14045 2026-08-20 6.5 MEDIUM 6.3 MEDIUM
A weakness has been identified in OpenBoxes up to 0.9.2. This vulnerability affects unknown code of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Product Supplier Edit Controller. Executing a manipulation can lead to improper authorization. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. Upgrading to version 0.9.3 is able to resolve this issue. This patch is called f767ac1a5987d4865d9f158c6a967680f8e45468. It is suggested to upgrade the affected component.
CVE-2026-75774 2026-08-20 2.6 LOW 3.7 LOW
A vulnerability was determined in karakeep-app karakeep up to 0.32.0. The impacted element is an unknown function of the file apps/web/server/auth.ts of the component OAuth Sign-In. This manipulation causes improper authentication. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is regarded as difficult. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.