Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 382 285

Количество 382 285

nvd логотип

CVE-2026-5957

4 месяца назад

The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to and including 1.6.5. This is due to a flawed path traversal validation in the create_template() method of the CheckForm class, where realpath() is called on the allowed base directory (wp-content/uploads/emailkit/templates/) which may not exist, causing it to return false. In PHP 8.x, strpos($real_path, false) implicitly converts false to an empty string, and strpos() with an empty needle always returns 0, causing the check strpos(...) !== 0 to evaluate to false and bypassing the path validation entirely. This makes it possible for authenticated attackers, with Author-level access and above, to read arbitrary files from the server, including sensitive files such as wp-config.php, by supplying an absolute path to the emailkit-editor-template REST API parameter.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-59568

3 дня назад

Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2026-59567

3 дня назад

Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a privileged context.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-59566

3 дня назад

A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Client Connector on Android and ChromeOS.

CVSS3: 8.4
EPSS: Низкий
nvd логотип

CVE-2026-59565

3 дня назад

A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of Zscaler Client Connector on Windows.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-59564

3 дня назад

An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2026-59561

3 дня назад

Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed to edit a file in a crafted directory, arbitrary OS command may be executed on the user's PC when the user invokes "Open Terminal".

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-59560

около 1 месяца назад

Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-5955

около 2 месяцев назад

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software and Internet Services BiEticaret allows SQL Injection. This issue affects BiEticaret: before v3.3.57.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-59559

около 1 месяца назад

Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg <= 1.5.1 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-59558

около 1 месяца назад

Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-59557

около 1 месяца назад

Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-59556

около 1 месяца назад

Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-59555

около 1 месяца назад

Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.

CVSS3: 10
EPSS: Низкий
nvd логотип

CVE-2026-59554

около 1 месяца назад

Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-59553

около 1 месяца назад

Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-59552

около 1 месяца назад

Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer &amp; Embedder <= 1.4.2 versions.

CVSS3: 7.2
EPSS: Низкий
nvd логотип

CVE-2026-59551

около 1 месяца назад

Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.

CVSS3: 8.5
EPSS: Низкий
nvd логотип

CVE-2026-59550

около 1 месяца назад

Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions.

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2026-59549

около 1 месяца назад

Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.

CVSS3: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-5957

The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to and including 1.6.5. This is due to a flawed path traversal validation in the create_template() method of the CheckForm class, where realpath() is called on the allowed base directory (wp-content/uploads/emailkit/templates/) which may not exist, causing it to return false. In PHP 8.x, strpos($real_path, false) implicitly converts false to an empty string, and strpos() with an empty needle always returns 0, causing the check strpos(...) !== 0 to evaluate to false and bypassing the path validation entirely. This makes it possible for authenticated attackers, with Author-level access and above, to read arbitrary files from the server, including sensitive files such as wp-config.php, by supplying an absolute path to the emailkit-editor-template REST API parameter.

CVSS3: 6.5
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-59568

Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.

CVSS3: 9.1
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-59567

Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a privileged context.

CVSS3: 8.8
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-59566

A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Client Connector on Android and ChromeOS.

CVSS3: 8.4
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-59565

A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of Zscaler Client Connector on Windows.

CVSS3: 8.8
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-59564

An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal.

CVSS3: 9.1
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-59561

Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed to edit a file in a crafted directory, arbitrary OS command may be executed on the user's PC when the user invokes "Open Terminal".

CVSS3: 7.8
1%
Низкий
3 дня назад
nvd логотип
CVE-2026-59560

Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-5955

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software and Internet Services BiEticaret allows SQL Injection. This issue affects BiEticaret: before v3.3.57.

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-59559

Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg <= 1.5.1 versions.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-59558

Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-59557

Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-59556

Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions.

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-59555

Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.

CVSS3: 10
1%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-59554

Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-59553

Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-59552

Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer &amp; Embedder <= 1.4.2 versions.

CVSS3: 7.2
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-59551

Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.

CVSS3: 8.5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-59550

Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions.

CVSS3: 9.3
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-59549

Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.

CVSS3: 9.3
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу