Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 386 296

Количество 386 296

nvd логотип

CVE-2026-59523

около 2 месяцев назад

Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.11.11.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-59522

около 1 месяца назад

Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-59521

около 2 месяцев назад

Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Injection.This issue affects Real Testimonials: from n/a through <= 3.1.15.

CVSS3: 7.2
EPSS: Низкий
nvd логотип

CVE-2026-59520

2 месяца назад

Cross-Site Request Forgery (CSRF) vulnerability in properfraction CrawlWP SEO allows Cross Site Request Forgery. This issue affects CrawlWP SEO: from n/a through 3.0.16.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-59519

2 месяца назад

Insertion of Sensitive Information Into Sent Data vulnerability in Softaculous FormLayer allows Retrieve Embedded Sensitive Data. This issue affects FormLayer: from n/a through 1.0.6.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-59518

около 2 месяцев назад

Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-59517

около 1 месяца назад

Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-59516

около 2 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Room 34 Creative Services, LLC ICS Calendar ics-calendar allows Reflected XSS.This issue affects ICS Calendar: from n/a through <= 12.1.1.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-59515

около 2 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sergey AIWU ai-copilot-content-generator allows Blind SQL Injection.This issue affects AIWU: from n/a through <= 1.5.4.

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2026-59514

около 1 месяца назад

Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions.

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2026-59513

около 1 месяца назад

Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-59512

около 1 месяца назад

Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-59511

2 месяца назад

Insertion of Sensitive Information Into Sent Data vulnerability in Tim Strifler Exclusive Addons Elementor allows Retrieve Embedded Sensitive Data. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.9.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-59510

2 месяца назад

AIL Framework contains a path traversal vulnerability in its PDF object handling. Prior to commit 14c618fce4d1df02358717c48ea903706abecdf2, the PDF.get_filepath() function constructed a file path by joining the configured PDF storage directory with a path derived from a PDF object identifier, without verifying that the resolved path remained within the intended PDF_FOLDER directory. An authenticated attacker able to invoke PDF object operations with a crafted identifier could use relative traversal sequences or absolute path components to cause AIL Framework to open files located outside the PDF storage directory. This could allow disclosure of files readable by the AIL process, including application configuration, credentials, or other sensitive local data. This vulnerability is potential due to additional errors before being able to be executed. The fix canonicalises the resulting path with os.path.realpath() and rejects paths whose common directory is outside the configured PDF di

EPSS: Низкий
nvd логотип

CVE-2026-5950

4 месяца назад

An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry conditions. This issue affects BIND 9 versions 9.18.36 through 9.18.48, 9.20.8 through 9.20.22, 9.21.7 through 9.21.21, 9.18.36-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-59509

2 месяца назад

An unauthenticated improper input validation vulnerability in the POST /fetch_cve_data endpoint in cve-search. A remote attacker can manipulate request parameters controlling the MongoDB collection, projected fields, and regular-expression filters to read arbitrary application MongoDB collections. This can expose administrative usernames and password hashes from the mgmt_users collection, enabling offline password cracking and potential administrative account compromise.

EPSS: Низкий
nvd логотип

CVE-2026-59507

22 дня назад

: Use of Hard-coded Credentials : Exposure of Sensitive Information to an Unauthorized Actor : Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2026-59506

22 дня назад

: Missing Authentication for Critical Function vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2026-59505

22 дня назад

: Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.

CVSS3: 8.6
EPSS: Низкий
nvd логотип

CVE-2026-59504

22 дня назад

: Client-Side Enforcement of Server-Side Security vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-59523

Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.11.11.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-59522

Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-59521

Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Injection.This issue affects Real Testimonials: from n/a through <= 3.1.15.

CVSS3: 7.2
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-59520

Cross-Site Request Forgery (CSRF) vulnerability in properfraction CrawlWP SEO allows Cross Site Request Forgery. This issue affects CrawlWP SEO: from n/a through 3.0.16.

CVSS3: 4.3
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-59519

Insertion of Sensitive Information Into Sent Data vulnerability in Softaculous FormLayer allows Retrieve Embedded Sensitive Data. This issue affects FormLayer: from n/a through 1.0.6.

CVSS3: 5.3
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-59518

Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2.

CVSS3: 9.8
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-59517

Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions.

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-59516

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Room 34 Creative Services, LLC ICS Calendar ics-calendar allows Reflected XSS.This issue affects ICS Calendar: from n/a through <= 12.1.1.

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-59515

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sergey AIWU ai-copilot-content-generator allows Blind SQL Injection.This issue affects AIWU: from n/a through <= 1.5.4.

CVSS3: 9.3
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-59514

Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions.

CVSS3: 9.3
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-59513

Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-59512

Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions.

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-59511

Insertion of Sensitive Information Into Sent Data vulnerability in Tim Strifler Exclusive Addons Elementor allows Retrieve Embedded Sensitive Data. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.9.

CVSS3: 5.3
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-59510

AIL Framework contains a path traversal vulnerability in its PDF object handling. Prior to commit 14c618fce4d1df02358717c48ea903706abecdf2, the PDF.get_filepath() function constructed a file path by joining the configured PDF storage directory with a path derived from a PDF object identifier, without verifying that the resolved path remained within the intended PDF_FOLDER directory. An authenticated attacker able to invoke PDF object operations with a crafted identifier could use relative traversal sequences or absolute path components to cause AIL Framework to open files located outside the PDF storage directory. This could allow disclosure of files readable by the AIL process, including application configuration, credentials, or other sensitive local data. This vulnerability is potential due to additional errors before being able to be executed. The fix canonicalises the resulting path with os.path.realpath() and rejects paths whose common directory is outside the configured PDF di

1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-5950

An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry conditions. This issue affects BIND 9 versions 9.18.36 through 9.18.48, 9.20.8 through 9.20.22, 9.21.7 through 9.21.21, 9.18.36-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.

CVSS3: 5.3
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-59509

An unauthenticated improper input validation vulnerability in the POST /fetch_cve_data endpoint in cve-search. A remote attacker can manipulate request parameters controlling the MongoDB collection, projected fields, and regular-expression filters to read arbitrary application MongoDB collections. This can expose administrative usernames and password hashes from the mgmt_users collection, enabling offline password cracking and potential administrative account compromise.

1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-59507

: Use of Hard-coded Credentials : Exposure of Sensitive Information to an Unauthorized Actor : Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.

CVSS3: 9.3
0%
Низкий
22 дня назад
nvd логотип
CVE-2026-59506

: Missing Authentication for Critical Function vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.

CVSS3: 9.3
0%
Низкий
22 дня назад
nvd логотип
CVE-2026-59505

: Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.

CVSS3: 8.6
0%
Низкий
22 дня назад
nvd логотип
CVE-2026-59504

: Client-Side Enforcement of Server-Side Security vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.

CVSS3: 9.1
0%
Низкий
22 дня назад

Уязвимостей на страницу