Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 083

Количество 374 083

nvd логотип

CVE-2026-65514

16 дней назад

Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-65513

2 дня назад

Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-65512

16 дней назад

Cross-Site request forgery (CSRF) vulnerability in Melapress WP Activity Log and Melapress WP Activity Log Premium allows Cross Site Request Forgery. This issue affects WP Activity Log: through 5.6.4; WP Activity Log Premium: through 5.6.4.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-65511

16 дней назад

Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-65510

16 дней назад

Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-6550

4 месяца назад

Cryptographic algorithm downgrade in the caching layer of Amazon AWS Encryption SDK for Python before version 3.3.1 and before version 4.0.5 might allow an authenticated local threat actor to bypass key commitment policy enforcement via a shared key cache, resulting in ciphertext that can be decrypted to multiple different plaintexts. To remediate this issue, users should upgrade to version 3.3.1, 4.0.5 or above.

CVSS3: 4.7
EPSS: Низкий
nvd логотип

CVE-2026-65509

2 дня назад

Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-65508

2 дня назад

Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2026-65507

2 дня назад

Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-65506

16 дней назад

Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-65505

16 дней назад

Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-65504

2 дня назад

Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-65503

16 дней назад

Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-65502

2 дня назад

Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-65501

16 дней назад

Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0 versions.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-65500

16 дней назад

Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-6549

3 месяца назад

The Logo Manager For Enamad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute of the `vc_enamad_namad`, `vc_enamad_shamed`, and `vc_enamad_custom` shortcodes in all versions up to, and including, 0.7.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2026-65499

16 дней назад

Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-65498

16 дней назад

Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-65497

16 дней назад

Administrator PHP Object Injection in Complianz <= 7.5.0 versions.

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-65514

Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions.

CVSS3: 6.5
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65513

Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions.

CVSS3: 7.1
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-65512

Cross-Site request forgery (CSRF) vulnerability in Melapress WP Activity Log and Melapress WP Activity Log Premium allows Cross Site Request Forgery. This issue affects WP Activity Log: through 5.6.4; WP Activity Log Premium: through 5.6.4.

CVSS3: 5.4
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65511

Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.

CVSS3: 7.1
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65510

Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions.

CVSS3: 7.1
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-6550

Cryptographic algorithm downgrade in the caching layer of Amazon AWS Encryption SDK for Python before version 3.3.1 and before version 4.0.5 might allow an authenticated local threat actor to bypass key commitment policy enforcement via a shared key cache, resulting in ciphertext that can be decrypted to multiple different plaintexts. To remediate this issue, users should upgrade to version 3.3.1, 4.0.5 or above.

CVSS3: 4.7
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-65509

Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions.

CVSS3: 7.1
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-65508

Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.

CVSS3: 9.3
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-65507

Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.

CVSS3: 9.8
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-65506

Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions.

CVSS3: 5.3
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65505

Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.

CVSS3: 5.3
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65504

Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.

CVSS3: 7.5
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-65503

Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.

CVSS3: 6.5
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65502

Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions.

CVSS3: 5.3
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-65501

Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0 versions.

CVSS3: 5.3
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65500

Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.

CVSS3: 7.5
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-6549

The Logo Manager For Enamad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute of the `vc_enamad_namad`, `vc_enamad_shamed`, and `vc_enamad_custom` shortcodes in all versions up to, and including, 0.7.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-65499

Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.

CVSS3: 6.5
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65498

Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions.

CVSS3: 5.3
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65497

Administrator PHP Object Injection in Complianz <= 7.5.0 versions.

CVSS3: 7.2
0%
Низкий
16 дней назад

Уязвимостей на страницу