Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 389 959

Количество 389 959

nvd логотип

CVE-2026-57756

2 месяца назад

Contributor SQL Injection in nicen-localize-image <= 1.4.9 versions.

CVSS3: 8.5
EPSS: Низкий
nvd логотип

CVE-2026-57755

2 месяца назад

Contributor Cross Site Scripting (XSS) in Mosaic Gallery &#8211; Advanced Gallery <= 1.2.0 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57754

2 месяца назад

Contributor Cross Site Scripting (XSS) in Livemesh Addons for WPBakery Page Builder <= 3.9.4 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57753

2 месяца назад

Unauthenticated Sensitive Data Exposure in Kit (formerly ConvertKit) for WooCommerce <= 2.1.5 versions.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-57752

2 месяца назад

Contributor SQL Injection in iNET Webkit 1.2.4 versions.

CVSS3: 8.5
EPSS: Низкий
nvd логотип

CVE-2026-57751

2 месяца назад

Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1.1.39 versions.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-57750

2 месяца назад

Unauthenticated Broken Access Control in ez Form Calculator Premium <= 2.14.1.2 versions.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-5774

5 месяцев назад

Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow an authenticated user to possibly cause a denial of service on the server or possibly reuse a single-use discharge token.

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2026-57749

2 месяца назад

Contributor Local File Inclusion in SportsPress Pro <= 2.7.29 versions.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-57748

2 месяца назад

Contributor Local File Inclusion in Shopify <= 1.0.0 versions.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-57747

2 месяца назад

Unauthenticated Cross Site Request Forgery (CSRF) in Booked <= 3.0.0 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57746

2 месяца назад

Subscriber Broken Access Control in Booked <= 3.0.0 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57745

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Reflected XSS.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57744

2 месяца назад

Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-57743

2 месяца назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows PHP Local File Inclusion.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-57741

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Stored XSS.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.0.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57740

2 месяца назад

Missing Authorization vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.1.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-5773

4 месяца назад

libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a network transfer operation that was requested by an application could wrongfully reuse an existing SMB connection to the same server that was using a different 'share' than the new subsequent transfer should. This could in unlucky situations lead to the download of the wrong file or the upload of a file to the wrong place. When this happens, the same credentials are used and the server name is the same.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-57739

2 месяца назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Blind SQL Injection.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.0.

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2026-57738

2 месяца назад

Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1.13.0.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-57756

Contributor SQL Injection in nicen-localize-image <= 1.4.9 versions.

CVSS3: 8.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57755

Contributor Cross Site Scripting (XSS) in Mosaic Gallery &#8211; Advanced Gallery <= 1.2.0 versions.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57754

Contributor Cross Site Scripting (XSS) in Livemesh Addons for WPBakery Page Builder <= 3.9.4 versions.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57753

Unauthenticated Sensitive Data Exposure in Kit (formerly ConvertKit) for WooCommerce <= 2.1.5 versions.

CVSS3: 5.3
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57752

Contributor SQL Injection in iNET Webkit 1.2.4 versions.

CVSS3: 8.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57751

Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1.1.39 versions.

CVSS3: 8.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57750

Unauthenticated Broken Access Control in ez Form Calculator Premium <= 2.14.1.2 versions.

CVSS3: 5.3
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-5774

Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow an authenticated user to possibly cause a denial of service on the server or possibly reuse a single-use discharge token.

CVSS3: 6.4
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-57749

Contributor Local File Inclusion in SportsPress Pro <= 2.7.29 versions.

CVSS3: 7.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57748

Contributor Local File Inclusion in Shopify <= 1.0.0 versions.

CVSS3: 7.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57747

Unauthenticated Cross Site Request Forgery (CSRF) in Booked <= 3.0.0 versions.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57746

Subscriber Broken Access Control in Booked <= 3.0.0 versions.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57745

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Reflected XSS.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57744

Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.

CVSS3: 9.8
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57743

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows PHP Local File Inclusion.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.

CVSS3: 8.1
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57741

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Stored XSS.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.0.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57740

Missing Authorization vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.1.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-5773

libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a network transfer operation that was requested by an application could wrongfully reuse an existing SMB connection to the same server that was using a different 'share' than the new subsequent transfer should. This could in unlucky situations lead to the download of the wrong file or the upload of a file to the wrong place. When this happens, the same credentials are used and the server name is the same.

CVSS3: 7.5
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-57739

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Blind SQL Injection.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.0.

CVSS3: 9.3
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57738

Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1.13.0.

CVSS3: 9.8
1%
Низкий
2 месяца назад

Уязвимостей на страницу