Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 390 627

Количество 390 627

nvd логотип

CVE-2026-57703

около 2 месяцев назад

Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions.

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2026-57702

2 месяца назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Melograno Venture Studio Amelia ameliabooking allows Blind SQL Injection.This issue affects Amelia: from n/a through <= 2.4.2.

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2026-57701

около 2 месяцев назад

Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57700

3 месяца назад

Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This issue affects OMGF Pro: from n/a through 5.2.6.

CVSS3: 10
EPSS: Низкий
nvd логотип

CVE-2026-57699

около 2 месяцев назад

Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57698

2 месяца назад

Authentication Bypass Using an Alternate Path or Channel vulnerability in VillaTheme Abandoned Cart Recovery for WooCommerce woo-abandoned-cart-recovery allows Authentication Abuse.This issue affects Abandoned Cart Recovery for WooCommerce: from n/a through <= 1.1.12.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57697

2 месяца назад

Authentication Bypass Using an Alternate Path or Channel vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Password Recovery Exploitation.This issue affects ProfileGrid : from n/a through <= 5.9.9.6.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-57696

около 2 месяцев назад

Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57695

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Rossiter Document Gallery document-gallery allows Reflected XSS.This issue affects Document Gallery: from n/a through <= 5.1.0.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57694

2 месяца назад

Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.13.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57693

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spacetime Ad Inserter ad-inserter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ad Inserter: from n/a through <= 2.8.11.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57692

2 месяца назад

Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. This issue affects PrivateContent: from n/a through 9.9.2.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-57691

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eli Anti-Malware Security and Brute-Force Firewall gotmls allows Reflected XSS.This issue affects Anti-Malware Security and Brute-Force Firewall: from n/a through <= 4.23.89.

CVSS3: 5.8
EPSS: Низкий
nvd логотип

CVE-2026-57690

2 месяца назад

Unauthenticated Cross Site Request Forgery (CSRF) in Werkstatt <= 4.7.2 versions.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-5768

4 месяца назад

The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range to perform unauthorized control of device functions, including starting/stopping activities, triggering vibrations, causing denial-of-service conditions, and fuzzing characteristic values to induce unexpected behavior. Additionally, the Frontier X mobile application lacks proper BLE device authentication, allowing attackers to impersonate a legitimate Frontier X2 device and connect to the application. By cloning BLE advertisements and exposing expected GATT characteristics, attackers can manipulate activity states and inject fabricated health telemetry such as breathing rate, heart rate, strain, and other health-related data into the mobile application.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-57689

2 месяца назад

Subscriber Broken Access Control in Werkstatt <= 4.7.2 versions.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-57688

2 месяца назад

Unauthenticated Broken Access Control in POS Entegratör <= 3.7.103 versions.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2026-57687

2 месяца назад

Contributor SQL Injection in Custom Field Template <= 2.7.8 versions.

CVSS3: 8.5
EPSS: Низкий
nvd логотип

CVE-2026-57686

2 месяца назад

Unauthenticated Cross Site Scripting (XSS) in WowAddons <= 1.6.14 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57685

2 месяца назад

Subscriber Broken Access Control in Martfury - WooCommerce Marketplace WordPress Theme <= 3.2.8 versions.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-57703

Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions.

CVSS3: 6.3
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57702

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Melograno Venture Studio Amelia ameliabooking allows Blind SQL Injection.This issue affects Amelia: from n/a through <= 2.4.2.

CVSS3: 9.3
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57701

Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions.

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57700

Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This issue affects OMGF Pro: from n/a through 5.2.6.

CVSS3: 10
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-57699

Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions.

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57698

Authentication Bypass Using an Alternate Path or Channel vulnerability in VillaTheme Abandoned Cart Recovery for WooCommerce woo-abandoned-cart-recovery allows Authentication Abuse.This issue affects Abandoned Cart Recovery for WooCommerce: from n/a through <= 1.1.12.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57697

Authentication Bypass Using an Alternate Path or Channel vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Password Recovery Exploitation.This issue affects ProfileGrid : from n/a through <= 5.9.9.6.

CVSS3: 7.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57696

Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions.

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57695

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Rossiter Document Gallery document-gallery allows Reflected XSS.This issue affects Document Gallery: from n/a through <= 5.1.0.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57694

Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.13.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57693

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spacetime Ad Inserter ad-inserter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ad Inserter: from n/a through <= 2.8.11.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57692

Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. This issue affects PrivateContent: from n/a through 9.9.2.

CVSS3: 9.8
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57691

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eli Anti-Malware Security and Brute-Force Firewall gotmls allows Reflected XSS.This issue affects Anti-Malware Security and Brute-Force Firewall: from n/a through <= 4.23.89.

CVSS3: 5.8
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57690

Unauthenticated Cross Site Request Forgery (CSRF) in Werkstatt <= 4.7.2 versions.

CVSS3: 4.3
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-5768

The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range to perform unauthorized control of device functions, including starting/stopping activities, triggering vibrations, causing denial-of-service conditions, and fuzzing characteristic values to induce unexpected behavior. Additionally, the Frontier X mobile application lacks proper BLE device authentication, allowing attackers to impersonate a legitimate Frontier X2 device and connect to the application. By cloning BLE advertisements and exposing expected GATT characteristics, attackers can manipulate activity states and inject fabricated health telemetry such as breathing rate, heart rate, strain, and other health-related data into the mobile application.

CVSS3: 8.8
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-57689

Subscriber Broken Access Control in Werkstatt <= 4.7.2 versions.

CVSS3: 4.3
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57688

Unauthenticated Broken Access Control in POS Entegratör <= 3.7.103 versions.

CVSS3: 8.2
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57687

Contributor SQL Injection in Custom Field Template <= 2.7.8 versions.

CVSS3: 8.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57686

Unauthenticated Cross Site Scripting (XSS) in WowAddons <= 1.6.14 versions.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57685

Subscriber Broken Access Control in Martfury - WooCommerce Marketplace WordPress Theme <= 3.2.8 versions.

CVSS3: 4.3
0%
Низкий
2 месяца назад

Уязвимостей на страницу