Vulnerabilities (CVE)

Total 398520 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-32475 2026-08-20 N/A 9.0 CRITICAL
Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1.
CVE-2024-14045 2026-08-20 6.5 MEDIUM 6.3 MEDIUM
A weakness has been identified in OpenBoxes up to 0.9.2. This vulnerability affects unknown code of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Product Supplier Edit Controller. Executing a manipulation can lead to improper authorization. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. Upgrading to version 0.9.3 is able to resolve this issue. This patch is called f767ac1a5987d4865d9f158c6a967680f8e45468. It is suggested to upgrade the affected component.
CVE-2026-75774 2026-08-20 2.6 LOW 3.7 LOW
A vulnerability was determined in karakeep-app karakeep up to 0.32.0. The impacted element is an unknown function of the file apps/web/server/auth.ts of the component OAuth Sign-In. This manipulation causes improper authentication. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is regarded as difficult. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-32466 2026-08-20 N/A 8.5 HIGH
Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.
CVE-2026-19923 2026-08-20 6.5 MEDIUM 6.3 MEDIUM
A weakness has been identified in code-projects Online Shopping System 1.0. This affects an unknown part of the file /checkout_process.php. Executing a manipulation of the argument total_count can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
CVE-2026-68568 2026-08-20 N/A 6.3 MEDIUM
Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions.
CVE-2026-73181 2026-08-20 N/A 7.5 HIGH
Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions.
CVE-2026-66640 2026-08-20 N/A 6.5 MEDIUM
Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions.
CVE-2026-19893 2026-08-20 2.1 LOW 3.1 LOW
A vulnerability was identified in D-Link DIR-842 2.01.B04. This impacts an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Such manipulation leads to incorrect default permissions. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult.
CVE-2026-73383 2026-08-20 N/A 4.9 MEDIUM
Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions.
CVE-2026-75079 2026-08-20 7.5 HIGH 7.3 HIGH
A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /edit_subject2.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
CVE-2026-73381 2026-08-20 N/A 9.1 CRITICAL
Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.
CVE-2026-73356 2026-08-20 N/A 8.2 HIGH
Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions.
CVE-2026-32547 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions.
CVE-2026-32467 2026-08-20 N/A 6.0 MEDIUM
Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions.
CVE-2026-32473 2026-08-20 N/A 7.2 HIGH
Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions.
CVE-2026-73190 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions.
CVE-2026-73343 2026-08-20 N/A 10.0 CRITICAL
Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
CVE-2026-73345 2026-08-20 N/A 7.1 HIGH
Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions.
CVE-2026-75013 2026-08-20 6.8 MEDIUM 6.5 MEDIUM
A vulnerability was detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. This affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi. The manipulation results in null pointer dereference. The attack can be launched remotely. The exploit is now public and may be used.