Количество 376 565
Количество 376 565
CVE-2026-61961
Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.
CVE-2026-6195
A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument admpass leads to os command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
CVE-2026-61959
Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions.
CVE-2026-61958
Missing Authorization vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects License Manager for WooCommerce: from n/a through <= 3.0.17.
CVE-2026-61957
Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.
CVE-2026-61956
Cross-Site Request Forgery (CSRF) vulnerability in hamsalam ووسلام – همگام سازی ووکامرس و باسلام sync-basalam allows Cross Site Request Forgery.This issue affects ووسلام – همگام سازی ووکامرس و باسلام: from n/a through <= 1.9.1.
CVE-2026-61955
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hannan گرویتی فرم فارسی persian-gravity-forms allows Blind SQL Injection.This issue affects گرویتی فرم فارسی: from n/a through <= 3.0.2.
CVE-2026-61954
Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.
CVE-2026-61953
Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.
CVE-2026-61952
Missing Authorization vulnerability in Jose Vega WooCommerce Bulk Edit Products – WP Sheet Editor woo-bulk-edit-products allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Bulk Edit Products – WP Sheet Editor: from n/a through <= 1.8.21.
CVE-2026-61951
Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.
CVE-2026-61950
Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.
CVE-2026-6194
A weakness has been identified in Totolink A3002MU B20211125.1046. Affected by this vulnerability is the function sub_410188 of the file /boafrm/formWlanSetup of the component HTTP Request Handler. This manipulation of the argument wan-url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
CVE-2026-61949
Unauthenticated SQL Injection in Bookly <= 27.7 versions.
CVE-2026-61948
Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.
CVE-2026-61947
Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions.
CVE-2026-61946
Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.
CVE-2026-61945
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6.
CVE-2026-61944
Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.
CVE-2026-61943
Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-61961 Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions. | CVSS3: 7.1 | 0% Низкий | 9 дней назад | |
CVE-2026-6195 A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument admpass leads to os command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. | CVSS3: 9.8 | 14% Средний | 4 месяца назад | |
CVE-2026-61959 Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions. | CVSS3: 6.5 | 0% Низкий | 9 дней назад | |
CVE-2026-61958 Missing Authorization vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects License Manager for WooCommerce: from n/a through <= 3.0.17. | CVSS3: 5.4 | 0% Низкий | около 1 месяца назад | |
CVE-2026-61957 Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions. | CVSS3: 7.1 | 0% Низкий | 18 дней назад | |
CVE-2026-61956 Cross-Site Request Forgery (CSRF) vulnerability in hamsalam ووسلام – همگام سازی ووکامرس و باسلام sync-basalam allows Cross Site Request Forgery.This issue affects ووسلام – همگام سازی ووکامرس و باسلام: from n/a through <= 1.9.1. | CVSS3: 7.1 | 0% Низкий | около 1 месяца назад | |
CVE-2026-61955 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hannan گرویتی فرم فارسی persian-gravity-forms allows Blind SQL Injection.This issue affects گرویتی فرم فارسی: from n/a through <= 3.0.2. | CVSS3: 7.6 | 0% Низкий | около 1 месяца назад | |
CVE-2026-61954 Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions. | CVSS3: 7.5 | 0% Низкий | 23 дня назад | |
CVE-2026-61953 Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions. | CVSS3: 7.2 | 0% Низкий | 18 дней назад | |
CVE-2026-61952 Missing Authorization vulnerability in Jose Vega WooCommerce Bulk Edit Products – WP Sheet Editor woo-bulk-edit-products allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Bulk Edit Products – WP Sheet Editor: from n/a through <= 1.8.21. | CVSS3: 4.9 | 0% Низкий | около 1 месяца назад | |
CVE-2026-61951 Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions. | CVSS3: 9.8 | 0% Низкий | 23 дня назад | |
CVE-2026-61950 Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions. | CVSS3: 9.3 | 0% Низкий | 23 дня назад | |
CVE-2026-6194 A weakness has been identified in Totolink A3002MU B20211125.1046. Affected by this vulnerability is the function sub_410188 of the file /boafrm/formWlanSetup of the component HTTP Request Handler. This manipulation of the argument wan-url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. | CVSS3: 8.8 | 0% Низкий | 4 месяца назад | |
CVE-2026-61949 Unauthenticated SQL Injection in Bookly <= 27.7 versions. | CVSS3: 9.3 | 0% Низкий | 23 дня назад | |
CVE-2026-61948 Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions. | CVSS3: 9.3 | 0% Низкий | 23 дня назад | |
CVE-2026-61947 Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions. | CVSS3: 7.1 | 0% Низкий | 23 дня назад | |
CVE-2026-61946 Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions. | CVSS3: 6.5 | 0% Низкий | 23 дня назад | |
CVE-2026-61945 Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6. | CVSS3: 6.5 | 0% Низкий | 23 дня назад | |
CVE-2026-61944 Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions. | CVSS3: 7.1 | 0% Низкий | 23 дня назад | |
CVE-2026-61943 Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions. | CVSS3: 7.5 | 0% Низкий | 23 дня назад |
Уязвимостей на страницу