Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 396 015

Количество 396 015

nvd логотип

CVE-2026-56053

3 месяца назад

Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-56052

3 месяца назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Funnel Builder by FunnelKit allows Blind SQL Injection. This issue affects Funnel Builder by FunnelKit: from n/a through 3.15.0.5.

CVSS3: 7.6
EPSS: Низкий
nvd логотип

CVE-2026-56051

3 месяца назад

Unauthenticated Cross Site Scripting (XSS) in TablePress <= 3.3.1 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-56050

3 месяца назад

Improper Access Control vulnerability in Themeisle PPOM for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PPOM for WooCommerce: from n/a through 33.0.18.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-5604

6 месяцев назад

A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formCertLocalPrecreate of the file /goform/CertLocalPrecreate of the component Parameter Handler. Performing a manipulation of the argument standard results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-56049

3 месяца назад

Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions.

CVSS3: 8.5
EPSS: Низкий
nvd логотип

CVE-2026-56048

3 месяца назад

Unauthenticated Insecure Direct Object References (IDOR) in Payment Gateway Based Fees and Discounts for WooCommerce <= 3.0.0 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-56047

3 месяца назад

Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.3 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-56046

3 месяца назад

Subscriber Cross Site Scripting (XSS) in ListingPro <= 2.9.11 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-56045

3 месяца назад

Unauthenticated Cross Site Scripting (XSS) in Automatic < 3.135.1 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-56044

3 месяца назад

Unauthenticated Cross Site Scripting (XSS) in Blog2Social <= 8.9.2 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-56043

3 месяца назад

Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-56042

3 месяца назад

Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-56041

3 месяца назад

Unauthenticated Cross Site Scripting (XSS) in Responsive Lightbox <= 2.7.6 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-56040

3 месяца назад

Unauthenticated Cross Site Scripting (XSS) in Gutenverse Form <= 2.4.7 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-5603

6 месяцев назад

A vulnerability was identified in elgentos magento2-dev-mcp up to 1.0.2. The affected element is the function executeMagerun2Command of the file src/index.ts. Such manipulation leads to os command injection. An attack has to be approached locally. The exploit is publicly available and might be used. The name of the patch is aa1ffcc0aea1b212c69787391783af27df15ae9d. A patch should be applied to remediate this issue.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-56039

3 месяца назад

Unauthenticated Cross Site Scripting (XSS) in Quick Interest Slider <= 3.1.6 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-56038

3 месяца назад

Contributor Privilege Escalation in Frisbii Pay <= 1.8.2 versions.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-56037

3 месяца назад

Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection. This issue affects Themify Popup: from n/a through 1.4.3.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-56036

3 месяца назад

Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions.

CVSS3: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-56053

Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions.

CVSS3: 8.8
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56052

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Funnel Builder by FunnelKit allows Blind SQL Injection. This issue affects Funnel Builder by FunnelKit: from n/a through 3.15.0.5.

CVSS3: 7.6
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56051

Unauthenticated Cross Site Scripting (XSS) in TablePress <= 3.3.1 versions.

CVSS3: 7.1
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56050

Improper Access Control vulnerability in Themeisle PPOM for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PPOM for WooCommerce: from n/a through 33.0.18.

CVSS3: 6.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-5604

A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formCertLocalPrecreate of the file /goform/CertLocalPrecreate of the component Parameter Handler. Performing a manipulation of the argument standard results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.

CVSS3: 8.8
1%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-56049

Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions.

CVSS3: 8.5
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56048

Unauthenticated Insecure Direct Object References (IDOR) in Payment Gateway Based Fees and Discounts for WooCommerce <= 3.0.0 versions.

CVSS3: 6.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56047

Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.3 versions.

CVSS3: 7.1
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56046

Subscriber Cross Site Scripting (XSS) in ListingPro <= 2.9.11 versions.

CVSS3: 6.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56045

Unauthenticated Cross Site Scripting (XSS) in Automatic < 3.135.1 versions.

CVSS3: 7.1
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56044

Unauthenticated Cross Site Scripting (XSS) in Blog2Social <= 8.9.2 versions.

CVSS3: 7.1
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56043

Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions.

CVSS3: 7.1
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56042

Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions.

CVSS3: 7.1
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56041

Unauthenticated Cross Site Scripting (XSS) in Responsive Lightbox <= 2.7.6 versions.

CVSS3: 7.1
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56040

Unauthenticated Cross Site Scripting (XSS) in Gutenverse Form <= 2.4.7 versions.

CVSS3: 7.1
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-5603

A vulnerability was identified in elgentos magento2-dev-mcp up to 1.0.2. The affected element is the function executeMagerun2Command of the file src/index.ts. Such manipulation leads to os command injection. An attack has to be approached locally. The exploit is publicly available and might be used. The name of the patch is aa1ffcc0aea1b212c69787391783af27df15ae9d. A patch should be applied to remediate this issue.

CVSS3: 5.3
1%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-56039

Unauthenticated Cross Site Scripting (XSS) in Quick Interest Slider <= 3.1.6 versions.

CVSS3: 7.1
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56038

Contributor Privilege Escalation in Frisbii Pay <= 1.8.2 versions.

CVSS3: 8.8
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56037

Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection. This issue affects Themify Popup: from n/a through 1.4.3.

CVSS3: 8.8
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56036

Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions.

CVSS3: 9.3
0%
Низкий
3 месяца назад

Уязвимостей на страницу