Количество 386 296
Количество 386 296
CVE-2026-57690
Unauthenticated Cross Site Request Forgery (CSRF) in Werkstatt <= 4.7.2 versions.
CVE-2026-5768
The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range to perform unauthorized control of device functions, including starting/stopping activities, triggering vibrations, causing denial-of-service conditions, and fuzzing characteristic values to induce unexpected behavior. Additionally, the Frontier X mobile application lacks proper BLE device authentication, allowing attackers to impersonate a legitimate Frontier X2 device and connect to the application. By cloning BLE advertisements and exposing expected GATT characteristics, attackers can manipulate activity states and inject fabricated health telemetry such as breathing rate, heart rate, strain, and other health-related data into the mobile application.
CVE-2026-57689
Subscriber Broken Access Control in Werkstatt <= 4.7.2 versions.
CVE-2026-57688
Unauthenticated Broken Access Control in POS Entegratör <= 3.7.103 versions.
CVE-2026-57687
Contributor SQL Injection in Custom Field Template <= 2.7.8 versions.
CVE-2026-57686
Unauthenticated Cross Site Scripting (XSS) in WowAddons <= 1.6.14 versions.
CVE-2026-57685
Subscriber Broken Access Control in Martfury - WooCommerce Marketplace WordPress Theme <= 3.2.8 versions.
CVE-2026-57684
Contributor Cross Site Scripting (XSS) in TheFox <= 3.9.70 versions.
CVE-2026-57683
Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions.
CVE-2026-57682
Unauthenticated Cross Site Scripting (XSS) in Simple Link Directory <= 15.0.5 versions.
CVE-2026-57681
Subscriber Server Side Request Forgery (SSRF) in GeoDirectory <= 2.8.161 versions.
CVE-2026-57680
Unauthenticated Insecure Direct Object References (IDOR) in Kirki <= 6.0.11 versions.
CVE-2026-5767
The SlideShowPro SC plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `slideShowProSC` shortcode in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-57679
Unauthenticated SQL Injection in GeekyBot <= 1.2.5 versions.
CVE-2026-57678
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemePunch Slider Revolution allows Reflected XSS. This issue affects Slider Revolution: from 7.0.0 through 7.0.16.
CVE-2026-57677
Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions.
CVE-2026-57676
Authorization Bypass Through User-Controlled Key vulnerability in Matteo Manna Simple User Avatar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple User Avatar: from n/a through 4.9.
CVE-2026-57675
Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.2.02.004 versions.
CVE-2026-57674
Unauthenticated Cross Site Scripting (XSS) in Timetics <= 1.0.58 versions.
CVE-2026-57673
Unauthenticated Cross Site Scripting (XSS) in Optimole <= 4.2.7 versions.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-57690 Unauthenticated Cross Site Request Forgery (CSRF) in Werkstatt <= 4.7.2 versions. | CVSS3: 4.3 | 0% Низкий | 2 месяца назад | |
CVE-2026-5768 The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range to perform unauthorized control of device functions, including starting/stopping activities, triggering vibrations, causing denial-of-service conditions, and fuzzing characteristic values to induce unexpected behavior. Additionally, the Frontier X mobile application lacks proper BLE device authentication, allowing attackers to impersonate a legitimate Frontier X2 device and connect to the application. By cloning BLE advertisements and exposing expected GATT characteristics, attackers can manipulate activity states and inject fabricated health telemetry such as breathing rate, heart rate, strain, and other health-related data into the mobile application. | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-57689 Subscriber Broken Access Control in Werkstatt <= 4.7.2 versions. | CVSS3: 4.3 | 0% Низкий | 2 месяца назад | |
CVE-2026-57688 Unauthenticated Broken Access Control in POS Entegratör <= 3.7.103 versions. | CVSS3: 8.2 | 0% Низкий | 2 месяца назад | |
CVE-2026-57687 Contributor SQL Injection in Custom Field Template <= 2.7.8 versions. | CVSS3: 8.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-57686 Unauthenticated Cross Site Scripting (XSS) in WowAddons <= 1.6.14 versions. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-57685 Subscriber Broken Access Control in Martfury - WooCommerce Marketplace WordPress Theme <= 3.2.8 versions. | CVSS3: 4.3 | 0% Низкий | 2 месяца назад | |
CVE-2026-57684 Contributor Cross Site Scripting (XSS) in TheFox <= 3.9.70 versions. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-57683 Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions. | CVSS3: 9.3 | 0% Низкий | 2 месяца назад | |
CVE-2026-57682 Unauthenticated Cross Site Scripting (XSS) in Simple Link Directory <= 15.0.5 versions. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-57681 Subscriber Server Side Request Forgery (SSRF) in GeoDirectory <= 2.8.161 versions. | CVSS3: 6.4 | 0% Низкий | 2 месяца назад | |
CVE-2026-57680 Unauthenticated Insecure Direct Object References (IDOR) in Kirki <= 6.0.11 versions. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-5767 The SlideShowPro SC plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `slideShowProSC` shortcode in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS3: 6.4 | 0% Низкий | 5 месяцев назад | |
CVE-2026-57679 Unauthenticated SQL Injection in GeekyBot <= 1.2.5 versions. | CVSS3: 9.3 | 0% Низкий | 2 месяца назад | |
CVE-2026-57678 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemePunch Slider Revolution allows Reflected XSS. This issue affects Slider Revolution: from 7.0.0 through 7.0.16. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-57677 Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions. | CVSS3: 9.8 | 1% Низкий | 2 месяца назад | |
CVE-2026-57676 Authorization Bypass Through User-Controlled Key vulnerability in Matteo Manna Simple User Avatar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple User Avatar: from n/a through 4.9. | CVSS3: 4.3 | 0% Низкий | 2 месяца назад | |
CVE-2026-57675 Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.2.02.004 versions. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-57674 Unauthenticated Cross Site Scripting (XSS) in Timetics <= 1.0.58 versions. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-57673 Unauthenticated Cross Site Scripting (XSS) in Optimole <= 4.2.7 versions. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад |
Уязвимостей на страницу