Vulnerabilities (CVE)

Total 397443 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-81762 2026-09-01 N/A 6.5 MEDIUM
Subscriber Broken Access Control in Booking and Rental Manager <= 2.7.6 versions.
CVE-2026-82221 2026-09-01 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions.
CVE-2026-82549 2026-09-01 7.5 HIGH 8.3 HIGH
A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component SecurityModeComplete Handler. Such manipulation leads to improper validation of integrity check value. The attack may be launched remotely. The exploit is publicly available and might be used.
CVE-2026-81290 2026-09-01 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & Newsletters <= 5.9.33 versions.
CVE-2026-81778 2026-09-01 N/A 6.5 MEDIUM
Subscriber Cross Site Scripting (XSS) in Kalles Addons <= 1.0.6 versions.
CVE-2026-81763 2026-09-01 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.
CVE-2026-82801 2026-09-01 7.5 HIGH 7.3 HIGH
A vulnerability was detected in NASA earthdata-search 1.0.0. Affected by this vulnerability is the function scaleImage of the file serverless/src/scaleImage/handler.js of the component scale Endpoint. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-81278 2026-09-01 N/A 5.4 MEDIUM
Missing Authorization vulnerability in WPExperts Post SMTP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Post SMTP: from 4.0.0 through beta.1.
CVE-2026-81296 2026-09-01 N/A 7.5 HIGH
Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions.
CVE-2026-81758 2026-09-01 N/A 6.3 MEDIUM
Subscriber Broken Access Control in OwnerRez API <= 1.2.6 versions.
CVE-2026-82228 2026-09-01 N/A 8.1 HIGH
Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions.
CVE-2026-81293 2026-09-01 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.
CVE-2026-82479 2026-09-01 5.8 MEDIUM 6.3 MEDIUM
A vulnerability was identified in NASA cFS up to 7.0.1. Impacted is the function OS_read of the file modules/protocol/tcp/fsw/src/sbn_tcp_if.c of the component SBN TCP Module. Such manipulation of the argument MsgSz leads to buffer overflow. The attack must be carried out from within the local network. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-81768 2026-09-01 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions.
CVE-2026-82914 2026-09-01 7.5 HIGH 7.3 HIGH
A security flaw has been discovered in kishan0725 Hospital-Management-System 1.0. This vulnerability affects unknown code of the file /search.php. The manipulation of the argument Contact results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-81287 2026-09-01 N/A 8.5 HIGH
Subscriber SQL Injection in Charitable <= 1.8.12.1 versions.
CVE-2026-84109 2026-09-01 6.5 MEDIUM 6.3 MEDIUM
A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.6. Affected by this issue is the function getOrder of the file webmain/webmainAction.php. Executing a manipulation of the argument highorder can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-82809 2026-09-01 5.0 MEDIUM 4.3 MEDIUM
A security flaw has been discovered in vidIQ Vision for YouTube Extension 3.199.0 on Chrome. The affected element is the function window.addEventListener of the component postMessage Handler. Performing a manipulation of the argument vidiqEvent results in information disclosure. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor explains: "At this time, vidIQ does not accept security vulnerability submissions, and we do not have a bug bounty program in place."
CVE-2026-82225 2026-09-01 N/A 7.4 HIGH
Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions.
CVE-2026-83743 2026-09-01 6.5 MEDIUM 6.3 MEDIUM
A weakness has been identified in invoiceninja Invoice Ninja up to 5.13.26. This affects an unknown part of the file /vedor/profile/ of the component Vendor Portal Profile Update. Executing a manipulation of the argument vendor_contact can lead to authorization bypass. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. Upgrading to version 5.13.27 is able to mitigate this issue. This patch is called f86fd9697ce7bd0d28adbe2e6c5890780482ea90. The affected component should be upgraded.