Количество 374 083
Количество 374 083
CVE-2026-65551
Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Breakdance: from n/a before 2.7.
CVE-2026-65550
Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.
CVE-2026-65549
Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions.
CVE-2026-65548
Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.
CVE-2026-65547
Subscriber SQL Injection in Creative Mail <= 1.6.9 versions.
CVE-2026-65546
Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions.
CVE-2026-65545
Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions.
CVE-2026-65544
Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions.
CVE-2026-65543
Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions.
CVE-2026-65542
Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.
CVE-2026-65541
Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions.
CVE-2026-65540
Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions.
CVE-2026-6553
Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings fields of the be_users database table. This issue affects TYPO3 CMS version 14.2.0.
CVE-2026-65539
Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.
CVE-2026-65538
Author Cross Site Scripting (XSS) in Machete <= 5.2 versions.
CVE-2026-65537
Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.
CVE-2026-65536
Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions.
CVE-2026-65535
Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.
CVE-2026-65534
Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions.
CVE-2026-65533
Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-65551 Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Breakdance: from n/a before 2.7. | CVSS3: 7.5 | 0% Низкий | 2 дня назад | |
CVE-2026-65550 Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions. | CVSS3: 5.9 | 0% Низкий | 16 дней назад | |
CVE-2026-65549 Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions. | CVSS3: 7.2 | 0% Низкий | 2 дня назад | |
CVE-2026-65548 Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions. | CVSS3: 9.9 | 0% Низкий | 2 дня назад | |
CVE-2026-65547 Subscriber SQL Injection in Creative Mail <= 1.6.9 versions. | CVSS3: 8.5 | 0% Низкий | 2 дня назад | |
CVE-2026-65546 Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions. | CVSS3: 9.3 | 0% Низкий | 2 дня назад | |
CVE-2026-65545 Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions. | CVSS3: 7.1 | 0% Низкий | 2 дня назад | |
CVE-2026-65544 Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions. | CVSS3: 7.1 | 0% Низкий | 2 дня назад | |
CVE-2026-65543 Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions. | CVSS3: 7.5 | 0% Низкий | 2 дня назад | |
CVE-2026-65542 Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions. | CVSS3: 8.8 | 0% Низкий | 2 дня назад | |
CVE-2026-65541 Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions. | CVSS3: 7.3 | 0% Низкий | 2 дня назад | |
CVE-2026-65540 Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions. | CVSS3: 7.1 | 0% Низкий | 16 дней назад | |
CVE-2026-6553 Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings fields of the be_users database table. This issue affects TYPO3 CMS version 14.2.0. | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-65539 Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions. | CVSS3: 7.1 | 0% Низкий | 16 дней назад | |
CVE-2026-65538 Author Cross Site Scripting (XSS) in Machete <= 5.2 versions. | CVSS3: 5.9 | 0% Низкий | 16 дней назад | |
CVE-2026-65537 Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions. | CVSS3: 4.3 | 0% Низкий | 16 дней назад | |
CVE-2026-65536 Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions. | CVSS3: 6.5 | 0% Низкий | 16 дней назад | |
CVE-2026-65535 Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions. | CVSS3: 4.3 | 0% Низкий | 16 дней назад | |
CVE-2026-65534 Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions. | CVSS3: 5.9 | 0% Низкий | 16 дней назад | |
CVE-2026-65533 Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions. | CVSS3: 6.5 | 0% Низкий | 16 дней назад |
Уязвимостей на страницу