Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 361 564

Количество 361 564

nvd логотип

CVE-2026-56035

около 1 месяца назад

Unauthenticated Multiple Vulnerabilities in BitFire Security <= 5.0.3 versions.

CVSS3: 8.6
EPSS: Низкий
nvd логотип

CVE-2026-56034

около 1 месяца назад

Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions.

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2026-56033

около 1 месяца назад

Unauthenticated Privilege Escalation in Dokan Pro <= 5.0.4 versions.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-56032

около 1 месяца назад

Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-56031

около 1 месяца назад

Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-56030

около 1 месяца назад

Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-5602

4 месяца назад

A vulnerability was determined in Nor2-io heim-mcp up to 0.1.3. Impacted is the function registerTools of the file src/tools.ts of the component new_heim_application/deploy_heim_application/deploy_heim_application_to_cloud. This manipulation causes os command injection. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Patch name: c321d8af25f77668781e6ccb43a1336f9185df37. It is suggested to install a patch to address this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-56029

около 1 месяца назад

Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2.7.4 versions.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-56028

около 1 месяца назад

Unauthenticated Privilege Escalation in Easy Elements for Elementor &#8211; Addons &amp; Website Templates <= 1.4.9 versions.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-56027

около 1 месяца назад

Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.

CVSS3: 9.9
EPSS: Низкий
nvd логотип

CVE-2026-56026

около 1 месяца назад

Subscriber Server Side Request Forgery (SSRF) in utm.codes <= 1.9.0 versions.

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2026-56025

около 1 месяца назад

Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-56024

около 2 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery. This issue affects WP EasyPay: from n/a through 4.4.0.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-56023

около 1 месяца назад

Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-56022

около 2 месяцев назад

Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, allowing bypass of additional MFA requirements. Fixed in 2.641.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-56021

около 2 месяцев назад

Webmin allows unauthenticated attackers to read the contents of any file ending in .conf within module directories, due to a bypassable regex pattern.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-56020

около 2 месяцев назад

The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL client certificate by sending a forged HTTP header. A remote attacker can spoof certificate DNs and authenticate as any user. Fixed in 2.641.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-5601

4 месяца назад

A vulnerability was found in Acrel Electrical Prepaid Cloud Platform 1.0. This issue affects some unknown processing of the file /bin.rar of the component Backup File Handler. The manipulation results in information disclosure. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-56014

около 1 месяца назад

Unauthenticated Cross Site Scripting (XSS) in Master Slider <= 3.11.2 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-56013

около 1 месяца назад

Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-56035

Unauthenticated Multiple Vulnerabilities in BitFire Security <= 5.0.3 versions.

CVSS3: 8.6
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-56034

Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions.

CVSS3: 9.3
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-56033

Unauthenticated Privilege Escalation in Dokan Pro <= 5.0.4 versions.

CVSS3: 9.8
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-56032

Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions.

CVSS3: 9.8
1%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-56031

Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions.

CVSS3: 8.1
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-56030

Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions.

CVSS3: 9.8
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-5602

A vulnerability was determined in Nor2-io heim-mcp up to 0.1.3. Impacted is the function registerTools of the file src/tools.ts of the component new_heim_application/deploy_heim_application/deploy_heim_application_to_cloud. This manipulation causes os command injection. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Patch name: c321d8af25f77668781e6ccb43a1336f9185df37. It is suggested to install a patch to address this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

CVSS3: 5.3
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-56029

Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2.7.4 versions.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-56028

Unauthenticated Privilege Escalation in Easy Elements for Elementor &#8211; Addons &amp; Website Templates <= 1.4.9 versions.

CVSS3: 9.8
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-56027

Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.

CVSS3: 9.9
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-56026

Subscriber Server Side Request Forgery (SSRF) in utm.codes <= 1.9.0 versions.

CVSS3: 6.4
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-56025

Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-56024

Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery. This issue affects WP EasyPay: from n/a through 4.4.0.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-56023

Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions.

CVSS3: 5.4
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-56022

Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, allowing bypass of additional MFA requirements. Fixed in 2.641.

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-56021

Webmin allows unauthenticated attackers to read the contents of any file ending in .conf within module directories, due to a bypassable regex pattern.

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-56020

The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL client certificate by sending a forged HTTP header. A remote attacker can spoof certificate DNs and authenticate as any user. Fixed in 2.641.

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-5601

A vulnerability was found in Acrel Electrical Prepaid Cloud Platform 1.0. This issue affects some unknown processing of the file /bin.rar of the component Backup File Handler. The manipulation results in information disclosure. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.3
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-56014

Unauthenticated Cross Site Scripting (XSS) in Master Slider <= 3.11.2 versions.

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-56013

Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу