Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 386 296

Количество 386 296

nvd логотип

CVE-2026-5736

5 месяцев назад

A vulnerability was identified in PowerJob 5.1.0/5.1.1/5.1.2. Impacted is an unknown function of the file powerjob-server/powerjob-server-starter/src/main/java/tech/powerjob/server/web/controller/InstanceController.java of the component detailPlus Endpoint. The manipulation of the argument customQuery leads to sql injection. Remote exploitation of the attack is possible. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2026-57369

около 2 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Builder themify-builder allows Reflected XSS.This issue affects Themify Builder: from n/a through <= 7.7.4.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57368

около 2 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonster noo-jobmonster allows Reflected XSS.This issue affects Jobmonster: from n/a through <= 4.8.5.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57367

около 2 месяцев назад

Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57366

2 месяца назад

Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.1 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57365

около 2 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hitesh Chandwani reCAPTCHA (v2 &amp; v3) for Asgaros Forum recaptcha-for-asgaros-forum allows DOM-Based XSS.This issue affects reCAPTCHA (v2 &amp; v3) for Asgaros Forum: from n/a through <= 1.1.0.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57364

около 2 месяцев назад

Improper Validation of Specified Quantity in Input vulnerability in WPDeveloper Better Payment – Instant Payments, Donations, Fundraising with Subscriptions &amp; More better-payment allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Better Payment – Instant Payments, Donations, Fundraising with Subscriptions &amp; More: from n/a through <= 2.2.0.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57363

около 2 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot chatbot allows Stored XSS.This issue affects ChatBot: from n/a through <= 8.3.7.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57362

2 месяца назад

Unauthenticated Cross Site Scripting (XSS) in ChatBot <= 8.3.2 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57361

2 месяца назад

Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.2.5 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57360

2 месяца назад

Unauthenticated Cross Site Scripting (XSS) in eCommerce Product Catalog <= 3.5.4 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-5735

5 месяцев назад

Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2 and Thunderbird 149.0.2.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-57359

2 месяца назад

Unauthenticated Cross Site Scripting (XSS) in ReviewX <= 2.3.10 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57358

2 месяца назад

Unauthenticated Cross Site Scripting (XSS) in Customize My Account for WooCommerce <= 4.3.9 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57357

2 месяца назад

Unauthenticated Cross Site Scripting (XSS) in Search Atlas SEO <= 2.6.6 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57356

2 месяца назад

Unauthenticated Cross Site Scripting (XSS) in MC Woocommerce Wishlist <= 1.9.19 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57355

2 месяца назад

Subscriber Broken Access Control in Classified Listing <= 5.4.2 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57354

2 месяца назад

Subscriber Cross Site Scripting (XSS) in JetReviews <= 3.0.0.1 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57353

2 месяца назад

Subscriber Broken Access Control in Link Whisper Premium <= 2.9.0 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57352

2 месяца назад

Unauthenticated Broken Authentication in ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce <= 2.2.0 versions.

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-5736

A vulnerability was identified in PowerJob 5.1.0/5.1.1/5.1.2. Impacted is an unknown function of the file powerjob-server/powerjob-server-starter/src/main/java/tech/powerjob/server/web/controller/InstanceController.java of the component detailPlus Endpoint. The manipulation of the argument customQuery leads to sql injection. Remote exploitation of the attack is possible. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 7.3
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-57369

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Builder themify-builder allows Reflected XSS.This issue affects Themify Builder: from n/a through <= 7.7.4.

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57368

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonster noo-jobmonster allows Reflected XSS.This issue affects Jobmonster: from n/a through <= 4.8.5.

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57367

Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57366

Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.1 versions.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57365

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hitesh Chandwani reCAPTCHA (v2 &amp; v3) for Asgaros Forum recaptcha-for-asgaros-forum allows DOM-Based XSS.This issue affects reCAPTCHA (v2 &amp; v3) for Asgaros Forum: from n/a through <= 1.1.0.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57364

Improper Validation of Specified Quantity in Input vulnerability in WPDeveloper Better Payment – Instant Payments, Donations, Fundraising with Subscriptions &amp; More better-payment allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Better Payment – Instant Payments, Donations, Fundraising with Subscriptions &amp; More: from n/a through <= 2.2.0.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57363

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot chatbot allows Stored XSS.This issue affects ChatBot: from n/a through <= 8.3.7.

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57362

Unauthenticated Cross Site Scripting (XSS) in ChatBot <= 8.3.2 versions.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57361

Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.2.5 versions.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57360

Unauthenticated Cross Site Scripting (XSS) in eCommerce Product Catalog <= 3.5.4 versions.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-5735

Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2 and Thunderbird 149.0.2.

CVSS3: 9.8
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-57359

Unauthenticated Cross Site Scripting (XSS) in ReviewX <= 2.3.10 versions.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57358

Unauthenticated Cross Site Scripting (XSS) in Customize My Account for WooCommerce <= 4.3.9 versions.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57357

Unauthenticated Cross Site Scripting (XSS) in Search Atlas SEO <= 2.6.6 versions.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57356

Unauthenticated Cross Site Scripting (XSS) in MC Woocommerce Wishlist <= 1.9.19 versions.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57355

Subscriber Broken Access Control in Classified Listing <= 5.4.2 versions.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57354

Subscriber Cross Site Scripting (XSS) in JetReviews <= 3.0.0.1 versions.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57353

Subscriber Broken Access Control in Link Whisper Premium <= 2.9.0 versions.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57352

Unauthenticated Broken Authentication in ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce <= 2.2.0 versions.

CVSS3: 4.8
0%
Низкий
2 месяца назад

Уязвимостей на страницу