Total
398520 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-32475 | 2026-08-20 | N/A | 9.0 CRITICAL | ||
| Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1. | |||||
| CVE-2024-14045 | 2026-08-20 | 6.5 MEDIUM | 6.3 MEDIUM | ||
| A weakness has been identified in OpenBoxes up to 0.9.2. This vulnerability affects unknown code of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Product Supplier Edit Controller. Executing a manipulation can lead to improper authorization. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. Upgrading to version 0.9.3 is able to resolve this issue. This patch is called f767ac1a5987d4865d9f158c6a967680f8e45468. It is suggested to upgrade the affected component. | |||||
| CVE-2026-75774 | 2026-08-20 | 2.6 LOW | 3.7 LOW | ||
| A vulnerability was determined in karakeep-app karakeep up to 0.32.0. The impacted element is an unknown function of the file apps/web/server/auth.ts of the component OAuth Sign-In. This manipulation causes improper authentication. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is regarded as difficult. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. | |||||
| CVE-2026-32466 | 2026-08-20 | N/A | 8.5 HIGH | ||
| Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions. | |||||
| CVE-2026-19923 | 2026-08-20 | 6.5 MEDIUM | 6.3 MEDIUM | ||
| A weakness has been identified in code-projects Online Shopping System 1.0. This affects an unknown part of the file /checkout_process.php. Executing a manipulation of the argument total_count can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. | |||||
| CVE-2026-68568 | 2026-08-20 | N/A | 6.3 MEDIUM | ||
| Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions. | |||||
| CVE-2026-73181 | 2026-08-20 | N/A | 7.5 HIGH | ||
| Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions. | |||||
| CVE-2026-66640 | 2026-08-20 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions. | |||||
| CVE-2026-19893 | 2026-08-20 | 2.1 LOW | 3.1 LOW | ||
| A vulnerability was identified in D-Link DIR-842 2.01.B04. This impacts an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Such manipulation leads to incorrect default permissions. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult. | |||||
| CVE-2026-73383 | 2026-08-20 | N/A | 4.9 MEDIUM | ||
| Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions. | |||||
| CVE-2026-75079 | 2026-08-20 | 7.5 HIGH | 7.3 HIGH | ||
| A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /edit_subject2.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. | |||||
| CVE-2026-73381 | 2026-08-20 | N/A | 9.1 CRITICAL | ||
| Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions. | |||||
| CVE-2026-73356 | 2026-08-20 | N/A | 8.2 HIGH | ||
| Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions. | |||||
| CVE-2026-32547 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions. | |||||
| CVE-2026-32467 | 2026-08-20 | N/A | 6.0 MEDIUM | ||
| Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions. | |||||
| CVE-2026-32473 | 2026-08-20 | N/A | 7.2 HIGH | ||
| Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions. | |||||
| CVE-2026-73190 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions. | |||||
| CVE-2026-73343 | 2026-08-20 | N/A | 10.0 CRITICAL | ||
| Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions. | |||||
| CVE-2026-73345 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions. | |||||
| CVE-2026-75013 | 2026-08-20 | 6.8 MEDIUM | 6.5 MEDIUM | ||
| A vulnerability was detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. This affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi. The manipulation results in null pointer dereference. The attack can be launched remotely. The exploit is now public and may be used. | |||||
