Vulnerabilities (CVE)

Total 398520 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-73366 2026-08-20 N/A 9.8 CRITICAL
Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
CVE-2026-66679 2026-08-20 N/A 6.5 MEDIUM
Unauthenticated Broken Access Control in Appointment Hour Booking <= 1.5.91 versions.
CVE-2026-19918 2026-08-20 5.8 MEDIUM 6.3 MEDIUM
A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This affects the function get_status of the component gRPC Management Interface. The manipulation leads to improper access controls. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-73400 2026-08-20 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.
CVE-2026-73398 2026-08-20 N/A 6.5 MEDIUM
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
CVE-2026-73395 2026-08-20 N/A 6.5 MEDIUM
Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions.
CVE-2026-73996 2026-08-20 N/A 9.8 CRITICAL
Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.
CVE-2026-74008 2026-08-20 N/A 5.3 MEDIUM
Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17.22 versions.
CVE-2026-19956 2026-08-20 6.5 MEDIUM 6.3 MEDIUM
A vulnerability has been found in gomarble-ai facebook-ads-mcp-server 0.1.0. The impacted element is the function fetch_pagination_url of the file server.py. Such manipulation leads to server-side request forgery. The attack can be launched remotely. The name of the patch is 4e53875aa22e8991c2fa4a7660d86e1caba66659. Applying a patch is advised to resolve this issue.
CVE-2026-75773 2026-08-20 2.6 LOW 3.7 LOW
A vulnerability was found in karakeep-app karakeep up to 0.32.0. The affected element is the function authorize of the file apps/web/server/auth.ts of the component Login Endpoint. The manipulation results in improper restriction of excessive authentication attempts. The attack may be performed from remote. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit has been made public and could be used. Upgrading to version 0.33.0 is sufficient to fix this issue. The patch is identified as f7d042971d0d2bcc7119654830cf1eb93eabbf24. It is advisable to upgrade the affected component.
CVE-2026-19980 2026-08-20 6.5 MEDIUM 7.4 HIGH
A security flaw has been discovered in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000 and XE3000 up to 4.8.x. Affected by this issue is the function ui.update_langs of the component Language Update. Performing a manipulation of the argument hour/min/week results in code injection. The attack can be initiated remotely. The vendor explains: "After our investigation, we have confirmed that the vulnerability described (...) does indeed exist."
CVE-2026-73997 2026-08-20 N/A 7.5 HIGH
Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions.
CVE-2026-75087 2026-08-20 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /viewdepartment.php. Performing a manipulation of the argument delid results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.
CVE-2026-28568 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions.
CVE-2026-73361 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Recipe Card Blocks for Gutenberg & Elementor <= 3.4.18 versions.
CVE-2026-73367 2026-08-20 N/A 7.2 HIGH
Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.
CVE-2026-19921 2026-08-20 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was identified in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /homeaction.php. Such manipulation of the argument cat_id leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
CVE-2026-73377 2026-08-20 N/A 7.5 HIGH
Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions.
CVE-2026-73187 2026-08-20 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.
CVE-2026-74009 2026-08-20 N/A 5.3 MEDIUM
Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions.