Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 570

Количество 373 570

nvd логотип

CVE-2026-65528

16 дней назад

Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-65527

16 дней назад

Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-65526

16 дней назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer allows Blind SQL Injection. This issue affects Visualizer: from n/a through 4.0.1.

CVSS3: 8.5
EPSS: Низкий
nvd логотип

CVE-2026-65525

16 дней назад

Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-65524

16 дней назад

Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-65522

16 дней назад

Contributor Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-65521

16 дней назад

Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-6551

3 месяца назад

The Timeline Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' attribute of the timeline-blocks/tb-timeline-blocks block in all versions up to, and including, 1.1.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2026-65519

16 дней назад

Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-65518

16 дней назад

Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-65516

16 дней назад

Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.

CVSS3: 7.2
EPSS: Низкий
nvd логотип

CVE-2026-65514

16 дней назад

Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-65512

16 дней назад

Cross-Site request forgery (CSRF) vulnerability in Melapress WP Activity Log and Melapress WP Activity Log Premium allows Cross Site Request Forgery. This issue affects WP Activity Log: through 5.6.4; WP Activity Log Premium: through 5.6.4.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-65511

16 дней назад

Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-65510

16 дней назад

Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-6550

4 месяца назад

Cryptographic algorithm downgrade in the caching layer of Amazon AWS Encryption SDK for Python before version 3.3.1 and before version 4.0.5 might allow an authenticated local threat actor to bypass key commitment policy enforcement via a shared key cache, resulting in ciphertext that can be decrypted to multiple different plaintexts. To remediate this issue, users should upgrade to version 3.3.1, 4.0.5 or above.

CVSS3: 4.7
EPSS: Низкий
nvd логотип

CVE-2026-65506

16 дней назад

Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-65505

16 дней назад

Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-65503

16 дней назад

Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-65501

16 дней назад

Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0 versions.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-65528

Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions.

CVSS3: 6.5
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65527

Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions.

CVSS3: 6.5
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65526

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer allows Blind SQL Injection. This issue affects Visualizer: from n/a through 4.0.1.

CVSS3: 8.5
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65525

Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.

CVSS3: 5.3
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65524

Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.

CVSS3: 4.3
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65522

Contributor Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.

CVSS3: 6.5
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65521

Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions.

CVSS3: 5.3
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-6551

The Timeline Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' attribute of the timeline-blocks/tb-timeline-blocks block in all versions up to, and including, 1.1.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-65519

Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions.

CVSS3: 6.5
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65518

Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions.

CVSS3: 6.5
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65516

Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.

CVSS3: 7.2
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65514

Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions.

CVSS3: 6.5
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65512

Cross-Site request forgery (CSRF) vulnerability in Melapress WP Activity Log and Melapress WP Activity Log Premium allows Cross Site Request Forgery. This issue affects WP Activity Log: through 5.6.4; WP Activity Log Premium: through 5.6.4.

CVSS3: 5.4
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65511

Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.

CVSS3: 7.1
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65510

Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions.

CVSS3: 7.1
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-6550

Cryptographic algorithm downgrade in the caching layer of Amazon AWS Encryption SDK for Python before version 3.3.1 and before version 4.0.5 might allow an authenticated local threat actor to bypass key commitment policy enforcement via a shared key cache, resulting in ciphertext that can be decrypted to multiple different plaintexts. To remediate this issue, users should upgrade to version 3.3.1, 4.0.5 or above.

CVSS3: 4.7
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-65506

Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions.

CVSS3: 5.3
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65505

Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.

CVSS3: 5.3
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65503

Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.

CVSS3: 6.5
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65501

Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0 versions.

CVSS3: 5.3
0%
Низкий
16 дней назад

Уязвимостей на страницу