Количество 390 981
Количество 390 981
CVE-2026-56060
Unauthenticated Sensitive Data Exposure in Print Invoice & Delivery Notes for WooCommerce <= 7.1.1 versions.
CVE-2026-5605
A weakness has been identified in Tenda CH22 1.0.0.1. This affects the function formWrlExtraSet of the file /goform/WrlExtraSet. Executing a manipulation of the argument GO can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
CVE-2026-56059
Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions.
CVE-2026-56058
Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions.
CVE-2026-56057
Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions.
CVE-2026-56055
Subscriber PHP Object Injection in RealHomes <= 4.5.3 versions.
CVE-2026-56054
Subscriber Arbitrary File Deletion in JS Help Desk <= 3.1.1 versions.
CVE-2026-56053
Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions.
CVE-2026-56052
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Funnel Builder by FunnelKit allows Blind SQL Injection. This issue affects Funnel Builder by FunnelKit: from n/a through 3.15.0.5.
CVE-2026-56051
Unauthenticated Cross Site Scripting (XSS) in TablePress <= 3.3.1 versions.
CVE-2026-56050
Improper Access Control vulnerability in Themeisle PPOM for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PPOM for WooCommerce: from n/a through 33.0.18.
CVE-2026-5604
A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formCertLocalPrecreate of the file /goform/CertLocalPrecreate of the component Parameter Handler. Performing a manipulation of the argument standard results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
CVE-2026-56049
Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions.
CVE-2026-56048
Unauthenticated Insecure Direct Object References (IDOR) in Payment Gateway Based Fees and Discounts for WooCommerce <= 3.0.0 versions.
CVE-2026-56047
Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.3 versions.
CVE-2026-56046
Subscriber Cross Site Scripting (XSS) in ListingPro <= 2.9.11 versions.
CVE-2026-56045
Unauthenticated Cross Site Scripting (XSS) in Automatic < 3.135.1 versions.
CVE-2026-56044
Unauthenticated Cross Site Scripting (XSS) in Blog2Social <= 8.9.2 versions.
CVE-2026-56043
Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions.
CVE-2026-56042
Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-56060 Unauthenticated Sensitive Data Exposure in Print Invoice & Delivery Notes for WooCommerce <= 7.1.1 versions. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-5605 A weakness has been identified in Tenda CH22 1.0.0.1. This affects the function formWrlExtraSet of the file /goform/WrlExtraSet. Executing a manipulation of the argument GO can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. | CVSS3: 8.8 | 1% Низкий | 5 месяцев назад | |
CVE-2026-56059 Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions. | CVSS3: 9.9 | 0% Низкий | 3 месяца назад | |
CVE-2026-56058 Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions. | CVSS3: 9.9 | 0% Низкий | 3 месяца назад | |
CVE-2026-56057 Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions. | CVSS3: 9.8 | 1% Низкий | 3 месяца назад | |
CVE-2026-56055 Subscriber PHP Object Injection in RealHomes <= 4.5.3 versions. | CVSS3: 8.8 | 1% Низкий | 3 месяца назад | |
CVE-2026-56054 Subscriber Arbitrary File Deletion in JS Help Desk <= 3.1.1 versions. | CVSS3: 7.7 | 0% Низкий | 3 месяца назад | |
CVE-2026-56053 Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions. | CVSS3: 8.8 | 1% Низкий | 3 месяца назад | |
CVE-2026-56052 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Funnel Builder by FunnelKit allows Blind SQL Injection. This issue affects Funnel Builder by FunnelKit: from n/a through 3.15.0.5. | CVSS3: 7.6 | 0% Низкий | 3 месяца назад | |
CVE-2026-56051 Unauthenticated Cross Site Scripting (XSS) in TablePress <= 3.3.1 versions. | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
CVE-2026-56050 Improper Access Control vulnerability in Themeisle PPOM for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PPOM for WooCommerce: from n/a through 33.0.18. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-5604 A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formCertLocalPrecreate of the file /goform/CertLocalPrecreate of the component Parameter Handler. Performing a manipulation of the argument standard results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. | CVSS3: 8.8 | 1% Низкий | 5 месяцев назад | |
CVE-2026-56049 Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions. | CVSS3: 8.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-56048 Unauthenticated Insecure Direct Object References (IDOR) in Payment Gateway Based Fees and Discounts for WooCommerce <= 3.0.0 versions. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-56047 Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.3 versions. | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
CVE-2026-56046 Subscriber Cross Site Scripting (XSS) in ListingPro <= 2.9.11 versions. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-56045 Unauthenticated Cross Site Scripting (XSS) in Automatic < 3.135.1 versions. | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
CVE-2026-56044 Unauthenticated Cross Site Scripting (XSS) in Blog2Social <= 8.9.2 versions. | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
CVE-2026-56043 Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions. | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
CVE-2026-56042 Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions. | CVSS3: 7.1 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу