Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 570

Количество 373 570

nvd логотип

CVE-2026-66476

11 дней назад

Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions.

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2026-66475

11 дней назад

Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce &#8211; Checkout Manager <= 3.0.5 versions.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2026-66474

11 дней назад

Unauthenticated Cross Site Request Forgery (CSRF) in Insert Headers and Footers Code – HT Script <= 1.1.8 versions.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-66473

11 дней назад

Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-6646

3 месяца назад

The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dt_default_button' shortcode in all versions up to, and including, 14.3.2. This is due to insufficient input sanitization and output escaping on the 'title' component of the 'link' shortcode parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2026-6645

около 2 месяцев назад

An insecure process execution vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy Client for Windows. The application, which typically operates with high-level system privileges, attempts to perform an internal validation check by invoking a secondary system utility using an unqualified file reference. Because the application does not specify an absolute path to this utility, it relies on the operating system's default search order to locate the executable. Under specific conditions, a local attacker with the ability to modify directories within the system's search path could plant a malicious binary that mimics the expected utility. This could result in the malicious code being executed with SYSTEM privileges, leading to a full compromise of the affected host.

EPSS: Низкий
nvd логотип

CVE-2026-6644

4 месяца назад

A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the restricted web environment and execute arbitrary code on the underlying operating system. This occurs due to insufficient validation of user-supplied input before it is passed to a system shell. Successful exploitation allows an attacker to achieve Remote Code Execution (RCE) and fully compromise the system. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RR42 as well as from ADM 5.0.0 through ADM 5.1.2.REO1.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2026-66448

11 дней назад

Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-66445

11 дней назад

Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-66442

11 дней назад

Subscriber Broken Access Control in YayPricing <= 3.5.6 versions.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-6643

4 месяца назад

A stack-based buffer overflow vulnerability was found in the VPN Clients on the ADM. The issue stems from the use of unbounded sscanf() and passing user-controlled data directly to printf(). Due to the lack of PIE and Stack Canary protections, an authenticated remote attacker can exploit these to execute arbitrary code as the web server user. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RR42 as well as from ADM 5.0.0 through ADM 5.1.2.REO1.

CVSS3: 9.9
EPSS: Низкий
nvd логотип

CVE-2026-66438

11 дней назад

Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor <= 2.8.0 versions.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-66437

11 дней назад

Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions.

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2026-66434

11 дней назад

Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-66433

11 дней назад

Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-66428

11 дней назад

Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-66427

11 дней назад

Administrator SQL Injection in WP Google Review Slider <= 18.4 versions.

CVSS3: 7.6
EPSS: Низкий
nvd логотип

CVE-2026-66421

8 дней назад

OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript messages processed through the sessions API. Attackers can craft a message containing inline event handler payloads such as an img tag with an onerror attribute within the 60-character rendering budget, which is stored in the session transcript and interpolated unsanitized into innerHTML on the default landing page, allowing theft of session tokens and unauthorized calls to authenticated administrative endpoints including agent instruction file modification.

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2026-66420

8 дней назад

MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early return in the CheckWebServerOriginName() function within webserver.js when self-signed certificates are in use. Attackers can open cross-origin WebSocket connections to any of the twelve WebSocket endpoints, send crafted action commands to exfiltrate the server sessionKey used to sign session cookies, forge session tokens as arbitrary users, and gain full remote control of all managed devices governed by the MeshCentral instance.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-66418

8 дней назад

OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, which is recorded verbatim in the audit log. When an administrator opens the notification panel, the unescaped log entry is rendered via innerHTML with a permissive Content-Security-Policy allowing inline event handlers, enabling the attacker-supplied payload to execute in the administrator's session and interact with authenticated endpoints including agent instruction file editing and configuration changes.

CVSS3: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-66476

Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions.

CVSS3: 4.9
0%
Низкий
11 дней назад
nvd логотип
CVE-2026-66475

Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce &#8211; Checkout Manager <= 3.0.5 versions.

CVSS3: 5.9
0%
Низкий
11 дней назад
nvd логотип
CVE-2026-66474

Unauthenticated Cross Site Request Forgery (CSRF) in Insert Headers and Footers Code – HT Script <= 1.1.8 versions.

CVSS3: 4.3
0%
Низкий
11 дней назад
nvd логотип
CVE-2026-66473

Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.

CVSS3: 7.5
0%
Низкий
11 дней назад
nvd логотип
CVE-2026-6646

The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dt_default_button' shortcode in all versions up to, and including, 14.3.2. This is due to insufficient input sanitization and output escaping on the 'title' component of the 'link' shortcode parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-6645

An insecure process execution vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy Client for Windows. The application, which typically operates with high-level system privileges, attempts to perform an internal validation check by invoking a secondary system utility using an unqualified file reference. Because the application does not specify an absolute path to this utility, it relies on the operating system's default search order to locate the executable. Under specific conditions, a local attacker with the ability to modify directories within the system's search path could plant a malicious binary that mimics the expected utility. This could result in the malicious code being executed with SYSTEM privileges, leading to a full compromise of the affected host.

0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-6644

A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the restricted web environment and execute arbitrary code on the underlying operating system. This occurs due to insufficient validation of user-supplied input before it is passed to a system shell. Successful exploitation allows an attacker to achieve Remote Code Execution (RCE) and fully compromise the system. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RR42 as well as from ADM 5.0.0 through ADM 5.1.2.REO1.

CVSS3: 9.1
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-66448

Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions.

CVSS3: 6.5
0%
Низкий
11 дней назад
nvd логотип
CVE-2026-66445

Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions.

CVSS3: 6.5
0%
Низкий
11 дней назад
nvd логотип
CVE-2026-66442

Subscriber Broken Access Control in YayPricing <= 3.5.6 versions.

CVSS3: 5.4
0%
Низкий
11 дней назад
nvd логотип
CVE-2026-6643

A stack-based buffer overflow vulnerability was found in the VPN Clients on the ADM. The issue stems from the use of unbounded sscanf() and passing user-controlled data directly to printf(). Due to the lack of PIE and Stack Canary protections, an authenticated remote attacker can exploit these to execute arbitrary code as the web server user. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RR42 as well as from ADM 5.0.0 through ADM 5.1.2.REO1.

CVSS3: 9.9
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-66438

Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor <= 2.8.0 versions.

CVSS3: 5.3
0%
Низкий
11 дней назад
nvd логотип
CVE-2026-66437

Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions.

CVSS3: 4.9
0%
Низкий
11 дней назад
nvd логотип
CVE-2026-66434

Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions.

CVSS3: 6.5
0%
Низкий
11 дней назад
nvd логотип
CVE-2026-66433

Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions.

CVSS3: 6.5
0%
Низкий
11 дней назад
nvd логотип
CVE-2026-66428

Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.

CVSS3: 4.3
0%
Низкий
11 дней назад
nvd логотип
CVE-2026-66427

Administrator SQL Injection in WP Google Review Slider <= 18.4 versions.

CVSS3: 7.6
0%
Низкий
11 дней назад
nvd логотип
CVE-2026-66421

OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript messages processed through the sessions API. Attackers can craft a message containing inline event handler payloads such as an img tag with an onerror attribute within the 60-character rendering budget, which is stored in the session transcript and interpolated unsanitized into innerHTML on the default landing page, allowing theft of session tokens and unauthorized calls to authenticated administrative endpoints including agent instruction file modification.

CVSS3: 9.3
0%
Низкий
8 дней назад
nvd логотип
CVE-2026-66420

MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early return in the CheckWebServerOriginName() function within webserver.js when self-signed certificates are in use. Attackers can open cross-origin WebSocket connections to any of the twelve WebSocket endpoints, send crafted action commands to exfiltrate the server sessionKey used to sign session cookies, forge session tokens as arbitrary users, and gain full remote control of all managed devices governed by the MeshCentral instance.

CVSS3: 8.8
0%
Низкий
8 дней назад
nvd логотип
CVE-2026-66418

OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, which is recorded verbatim in the audit log. When an administrator opens the notification panel, the unescaped log entry is rendered via innerHTML with a permissive Content-Security-Policy allowing inline event handlers, enabling the attacker-supplied payload to execute in the administrator's session and interact with authenticated endpoints including agent instruction file editing and configuration changes.

CVSS3: 9.3
0%
Низкий
8 дней назад

Уязвимостей на страницу