Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 570

Количество 373 570

nvd логотип

CVE-2026-65562

12 дней назад

Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-65561

12 дней назад

Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-6555

3 месяца назад

The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an array validation mismatch where only the first file in the upload array undergoes extension and MIME type validation, while all files are processed and uploaded to a web-accessible directory. This makes it possible for unauthenticated attackers to upload malicious PHP files and achieve remote code execution by sending a valid first file followed by a malicious file.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-65558

12 дней назад

Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-65557

12 дней назад

Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2026-65550

16 дней назад

Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2026-65540

16 дней назад

Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-6553

4 месяца назад

Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings fields of the be_users database table. This issue affects TYPO3 CMS version 14.2.0.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-65539

16 дней назад

Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-65538

16 дней назад

Author Cross Site Scripting (XSS) in Machete <= 5.2 versions.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2026-65537

16 дней назад

Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-65536

16 дней назад

Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-65535

16 дней назад

Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-65534

16 дней назад

Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2026-65533

16 дней назад

Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-65532

16 дней назад

Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions.

CVSS3: 7.6
EPSS: Низкий
nvd логотип

CVE-2026-65531

16 дней назад

Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2026-65530

16 дней назад

Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-6552

около 2 месяцев назад

Rejected reason: This CVE ID has been rejected. GitLab determined that the reported behavior does not constitute a vulnerability: linking a group SAML identity requires the user to explicitly consent to that group controlling their GitLab account for sign-in, and management of group SAML identities by a group Owner is therefore expected behavior rather than an authorization bypass. No GitLab version was affected.

EPSS: Низкий
nvd логотип

CVE-2026-65529

16 дней назад

Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-65562

Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions.

CVSS3: 6.5
0%
Низкий
12 дней назад
nvd логотип
CVE-2026-65561

Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.

CVSS3: 6.5
0%
Низкий
12 дней назад
nvd логотип
CVE-2026-6555

The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an array validation mismatch where only the first file in the upload array undergoes extension and MIME type validation, while all files are processed and uploaded to a web-accessible directory. This makes it possible for unauthenticated attackers to upload malicious PHP files and achieve remote code execution by sending a valid first file followed by a malicious file.

CVSS3: 9.8
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-65558

Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions.

CVSS3: 5.4
0%
Низкий
12 дней назад
nvd логотип
CVE-2026-65557

Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.

CVSS3: 5.9
0%
Низкий
12 дней назад
nvd логотип
CVE-2026-65550

Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.

CVSS3: 5.9
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65540

Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions.

CVSS3: 7.1
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-6553

Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings fields of the be_users database table. This issue affects TYPO3 CMS version 14.2.0.

CVSS3: 7.5
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-65539

Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.

CVSS3: 7.1
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65538

Author Cross Site Scripting (XSS) in Machete <= 5.2 versions.

CVSS3: 5.9
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65537

Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.

CVSS3: 4.3
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65536

Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions.

CVSS3: 6.5
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65535

Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.

CVSS3: 4.3
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65534

Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions.

CVSS3: 5.9
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65533

Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions.

CVSS3: 6.5
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65532

Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions.

CVSS3: 7.6
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65531

Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.

CVSS3: 4.8
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65530

Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions.

CVSS3: 4.3
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-6552

Rejected reason: This CVE ID has been rejected. GitLab determined that the reported behavior does not constitute a vulnerability: linking a group SAML identity requires the user to explicitly consent to that group controlling their GitLab account for sign-in, and management of group SAML identities by a group Owner is therefore expected behavior rather than an authorization bypass. No GitLab version was affected.

около 2 месяцев назад
nvd логотип
CVE-2026-65529

Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions.

CVSS3: 5.3
0%
Низкий
16 дней назад

Уязвимостей на страницу