Total
398697 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-73340 | 2026-08-14 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions. | |||||
| CVE-2026-66467 | 2026-08-14 | N/A | 6.5 MEDIUM | ||
| Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions. | |||||
| CVE-2026-19789 | 2026-08-14 | 9.0 HIGH | 8.8 HIGH | ||
| A vulnerability was determined in Tenda AC1206 15.03.06.23_multi_TD01. This vulnerability affects the function set_wl_guest_iplist of the file /goform/WifiGuestSet of the component httpd web management interface. This manipulation of the argument shareSpeed causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. | |||||
| CVE-2026-66478 | 2026-08-14 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions. | |||||
| CVE-2026-73401 | 2026-08-14 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions. | |||||
| CVE-2026-66464 | 2026-08-14 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Broken Access Control in Internal Link Optimiser <= 5.2.7 versions. | |||||
| CVE-2026-19824 | 2026-08-14 | 9.0 HIGH | 8.8 HIGH | ||
| A weakness has been identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. The affected element is the function ipMacBindListStore of the file /goform/addIpMacBind. Executing a manipulation of the argument IPMacBindRule can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. | |||||
| CVE-2026-19750 | 2026-08-14 | 7.6 HIGH | 8.1 HIGH | ||
| A flaw has been found in Tenda CH, CP and TX3 V21.x/V22.x/V25.x/V26.x/V27.x. Affected by this issue is some unknown functionality of the component SSH. Executing a manipulation can lead to use of hard-coded password. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitation is known to be difficult. The exploit has been published and may be used. | |||||
| CVE-2026-66657 | 2026-08-14 | N/A | 8.1 HIGH | ||
| Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions. | |||||
| CVE-2026-19752 | 2026-08-14 | 6.5 MEDIUM | 6.3 MEDIUM | ||
| A vulnerability was found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477c8f9c82. This affects the function parse-pdf of the file src/index.ts of the component PDF Parsing. Performing a manipulation of the argument pdfUrl results in server-side request forgery. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet. | |||||
| CVE-2026-66468 | 2026-08-14 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versions. | |||||
| CVE-2026-28157 | 2026-08-14 | N/A | 7.5 HIGH | ||
| Subscriber Path Traversal in Do Lasso <= 358 versions. | |||||
| CVE-2026-28161 | 2026-08-14 | N/A | 8.8 HIGH | ||
| Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions. | |||||
| CVE-2026-66454 | 2026-08-14 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versions. | |||||
| CVE-2026-66431 | 2026-08-14 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions. | |||||
| CVE-2026-28185 | 2026-08-14 | N/A | 9.8 CRITICAL | ||
| Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions. | |||||
| CVE-2026-28142 | 2026-08-14 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions. | |||||
| CVE-2026-28181 | 2026-08-14 | N/A | 6.5 MEDIUM | ||
| Subscriber Broken Access Control in AcyMailing SMTP Newsletter <= 10.11.1 versions. | |||||
| CVE-2026-66455 | 2026-08-14 | N/A | 6.0 MEDIUM | ||
| Subscriber Broken Access Control in ReactPress <= 3.4.0 versions. | |||||
| CVE-2026-28148 | 2026-08-14 | N/A | 9.8 CRITICAL | ||
| Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions. | |||||
