Количество 386 296
Количество 386 296
CVE-2026-57631
Administrator SQL Injection in Popup box <= 6.0.1 versions.
CVE-2026-57630
Unauthenticated Insecure Direct Object References (IDOR) in Blocksy Companion Pro <= 2.1.46 versions.
CVE-2026-5762
Allocation of resources without limits or throttling vulnerability in Wikimedia Foundation MediaWiki - ReportIncident Extension allows HTTP DoS. This issue was remediated only on the `master` branch.
CVE-2026-57629
Contributor Cross Site Scripting (XSS) in StatCounter <= 2.1.1 versions.
CVE-2026-57628
Administrator SQL Injection in WP All Import <= 4.0.1 versions.
CVE-2026-57627
Subscriber Server Side Request Forgery (SSRF) in Kirki <= 6.0.11 versions.
CVE-2026-57626
Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This issue affects MailPoet: from 5.30.0 through 5.33.0.
CVE-2026-57625
Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro <= 8.8.5 versions.
CVE-2026-57624
Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.
CVE-2026-57623
Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions.
CVE-2026-57622
Subscriber Broken Access Control in WPCafe <= 3.0.14 versions.
CVE-2026-57621
Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.
CVE-2026-57620
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allows Stored XSS. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.8.
CVE-2026-57619
Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions.
CVE-2026-57618
Contributor Cross Site Scripting (XSS) in Neve PRO <= 3.1.2 versions.
CVE-2026-57617
Contributor Cross Site Scripting (XSS) in SeedProd Pro < 6.19.5 versions.
CVE-2026-5760
SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is loaded, as the Jinja2 chat templates are rendered using an unsandboxed jinja2.Environment().
CVE-2026-57600
Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sensitive data.
CVE-2026-57599
There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the device program, attackers can escalate privileges and gain full control of the device after authenticating via SSH.
CVE-2026-5758
JavaScript is vulnerable to prototype pollution in Mafintosh's protocol-buffers-schema Version 3.6.0, where an attacker may alter the application logic, bypass security checks, cause a DoS or achieve remote code execution.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-57631 Administrator SQL Injection in Popup box <= 6.0.1 versions. | CVSS3: 7.6 | 0% Низкий | 2 месяца назад | |
CVE-2026-57630 Unauthenticated Insecure Direct Object References (IDOR) in Blocksy Companion Pro <= 2.1.46 versions. | CVSS3: 5.3 | 0% Низкий | 2 месяца назад | |
CVE-2026-5762 Allocation of resources without limits or throttling vulnerability in Wikimedia Foundation MediaWiki - ReportIncident Extension allows HTTP DoS. This issue was remediated only on the `master` branch. | 0% Низкий | 5 месяцев назад | ||
CVE-2026-57629 Contributor Cross Site Scripting (XSS) in StatCounter <= 2.1.1 versions. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-57628 Administrator SQL Injection in WP All Import <= 4.0.1 versions. | CVSS3: 7.6 | 0% Низкий | 2 месяца назад | |
CVE-2026-57627 Subscriber Server Side Request Forgery (SSRF) in Kirki <= 6.0.11 versions. | CVSS3: 4.9 | 0% Низкий | 2 месяца назад | |
CVE-2026-57626 Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This issue affects MailPoet: from 5.30.0 through 5.33.0. | CVSS3: 7.1 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-57625 Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro <= 8.8.5 versions. | CVSS3: 9.6 | 0% Низкий | 2 месяца назад | |
CVE-2026-57624 Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions. | CVSS3: 10 | 1% Низкий | 2 месяца назад | |
CVE-2026-57623 Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions. | CVSS3: 9 | 1% Низкий | 2 месяца назад | |
CVE-2026-57622 Subscriber Broken Access Control in WPCafe <= 3.0.14 versions. | CVSS3: 4.3 | 0% Низкий | 2 месяца назад | |
CVE-2026-57621 Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions. | CVSS3: 9.8 | 1% Низкий | 2 месяца назад | |
CVE-2026-57620 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allows Stored XSS. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.8. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-57619 Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-57618 Contributor Cross Site Scripting (XSS) in Neve PRO <= 3.1.2 versions. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-57617 Contributor Cross Site Scripting (XSS) in SeedProd Pro < 6.19.5 versions. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-5760 SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is loaded, as the Jinja2 chat templates are rendered using an unsandboxed jinja2.Environment(). | CVSS3: 9.8 | 1% Низкий | 5 месяцев назад | |
CVE-2026-57600 Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sensitive data. | CVSS3: 7.5 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-57599 There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the device program, attackers can escalate privileges and gain full control of the device after authenticating via SSH. | CVSS3: 6.6 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-5758 JavaScript is vulnerable to prototype pollution in Mafintosh's protocol-buffers-schema Version 3.6.0, where an attacker may alter the application logic, bypass security checks, cause a DoS or achieve remote code execution. | CVSS3: 6.5 | 1% Низкий | 5 месяцев назад |
Уязвимостей на страницу