Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 390 627

Количество 390 627

nvd логотип

CVE-2026-57741

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Stored XSS.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.0.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57740

2 месяца назад

Missing Authorization vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.1.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-5773

4 месяца назад

libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a network transfer operation that was requested by an application could wrongfully reuse an existing SMB connection to the same server that was using a different 'share' than the new subsequent transfer should. This could in unlucky situations lead to the download of the wrong file or the upload of a file to the wrong place. When this happens, the same credentials are used and the server name is the same.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-57739

2 месяца назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Blind SQL Injection.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.0.

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2026-57738

2 месяца назад

Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1.13.0.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-57737

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta LTD Shortcodes and extra features for Phlox theme allows DOM-Based XSS. This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.17.16.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57736

2 месяца назад

Insertion of Sensitive Information Into Sent Data vulnerability in HubSpot allows Retrieve Embedded Sensitive Data. This issue affects HubSpot: from n/a through 11.3.51.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2026-57735

около 2 месяцев назад

Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57734

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows Reflected XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.3.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57733

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Cloud Library td-cloud-library allows DOM-Based XSS.This issue affects tagDiv Cloud Library: from n/a through <= 3.9.4.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57732

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Opt-In Builder td-subscription allows DOM-Based XSS.This issue affects tagDiv Opt-In Builder: from n/a through <= 1.7.4.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57731

2 месяца назад

Contributor Broken Access Control in Flatsome <= 3.20.5 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57730

2 месяца назад

Subscriber Broken Access Control in Flatsome <= 3.20.5 versions.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-5772

5 месяцев назад

A 1-byte stack buffer over-read was identified in the MatchDomainName function (src/internal.c) during wildcard hostname validation when the LEFT_MOST_WILDCARD_ONLY flag is active. If a wildcard * exhausts the entire hostname string, the function reads one byte past the buffer without a bounds check, which could cause a crash.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-57729

2 месяца назад

Missing Authorization vulnerability in UX-themes Flatsome flatsome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flatsome: from n/a through <= 3.20.5.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-57728

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UX-themes Flatsome flatsome allows Reflected XSS.This issue affects Flatsome: from n/a through <= 3.20.5.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57727

2 месяца назад

Missing Authorization vulnerability in Themeum Kirki kirki allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kirki: from n/a through <= 6.0.13.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-57726

2 месяца назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Kirki kirki allows Blind SQL Injection.This issue affects Kirki: from n/a through <= 6.0.12.

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2026-57725

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Kirki kirki allows Stored XSS.This issue affects Kirki: from n/a through <= 6.0.11.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57724

2 месяца назад

Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-57741

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Stored XSS.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.0.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57740

Missing Authorization vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.1.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-5773

libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a network transfer operation that was requested by an application could wrongfully reuse an existing SMB connection to the same server that was using a different 'share' than the new subsequent transfer should. This could in unlucky situations lead to the download of the wrong file or the upload of a file to the wrong place. When this happens, the same credentials are used and the server name is the same.

CVSS3: 7.5
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-57739

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Blind SQL Injection.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.0.

CVSS3: 9.3
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57738

Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1.13.0.

CVSS3: 9.8
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57737

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta LTD Shortcodes and extra features for Phlox theme allows DOM-Based XSS. This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.17.16.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57736

Insertion of Sensitive Information Into Sent Data vulnerability in HubSpot allows Retrieve Embedded Sensitive Data. This issue affects HubSpot: from n/a through 11.3.51.

CVSS3: 7.4
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57735

Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions.

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57734

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows Reflected XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.3.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57733

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Cloud Library td-cloud-library allows DOM-Based XSS.This issue affects tagDiv Cloud Library: from n/a through <= 3.9.4.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57732

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Opt-In Builder td-subscription allows DOM-Based XSS.This issue affects tagDiv Opt-In Builder: from n/a through <= 1.7.4.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57731

Contributor Broken Access Control in Flatsome <= 3.20.5 versions.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57730

Subscriber Broken Access Control in Flatsome <= 3.20.5 versions.

CVSS3: 4.3
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-5772

A 1-byte stack buffer over-read was identified in the MatchDomainName function (src/internal.c) during wildcard hostname validation when the LEFT_MOST_WILDCARD_ONLY flag is active. If a wildcard * exhausts the entire hostname string, the function reads one byte past the buffer without a bounds check, which could cause a crash.

CVSS3: 5.3
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-57729

Missing Authorization vulnerability in UX-themes Flatsome flatsome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flatsome: from n/a through <= 3.20.5.

CVSS3: 7.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57728

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UX-themes Flatsome flatsome allows Reflected XSS.This issue affects Flatsome: from n/a through <= 3.20.5.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57727

Missing Authorization vulnerability in Themeum Kirki kirki allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kirki: from n/a through <= 6.0.13.

CVSS3: 7.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57726

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Kirki kirki allows Blind SQL Injection.This issue affects Kirki: from n/a through <= 6.0.12.

CVSS3: 9.3
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57725

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Kirki kirki allows Stored XSS.This issue affects Kirki: from n/a through <= 6.0.11.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57724

Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.

CVSS3: 9.8
1%
Низкий
2 месяца назад

Уязвимостей на страницу