Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 565

Количество 376 565

nvd логотип

CVE-2026-61961

9 дней назад

Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-6195

4 месяца назад

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument admpass leads to os command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 9.8
EPSS: Средний
nvd логотип

CVE-2026-61959

9 дней назад

Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-61958

около 1 месяца назад

Missing Authorization vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects License Manager for WooCommerce: from n/a through <= 3.0.17.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-61957

18 дней назад

Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-61956

около 1 месяца назад

Cross-Site Request Forgery (CSRF) vulnerability in hamsalam ووسلام &#8211; همگام سازی ووکامرس و باسلام sync-basalam allows Cross Site Request Forgery.This issue affects ووسلام &#8211; همگام سازی ووکامرس و باسلام: from n/a through <= 1.9.1.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-61955

около 1 месяца назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hannan گرویتی فرم فارسی persian-gravity-forms allows Blind SQL Injection.This issue affects گرویتی فرم فارسی: from n/a through <= 3.0.2.

CVSS3: 7.6
EPSS: Низкий
nvd логотип

CVE-2026-61954

23 дня назад

Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-61953

18 дней назад

Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.

CVSS3: 7.2
EPSS: Низкий
nvd логотип

CVE-2026-61952

около 1 месяца назад

Missing Authorization vulnerability in Jose Vega WooCommerce Bulk Edit Products – WP Sheet Editor woo-bulk-edit-products allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Bulk Edit Products – WP Sheet Editor: from n/a through <= 1.8.21.

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2026-61951

23 дня назад

Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-61950

23 дня назад

Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2026-6194

4 месяца назад

A weakness has been identified in Totolink A3002MU B20211125.1046. Affected by this vulnerability is the function sub_410188 of the file /boafrm/formWlanSetup of the component HTTP Request Handler. This manipulation of the argument wan-url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-61949

23 дня назад

Unauthenticated SQL Injection in Bookly <= 27.7 versions.

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2026-61948

23 дня назад

Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2026-61947

23 дня назад

Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-61946

23 дня назад

Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-61945

23 дня назад

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-61944

23 дня назад

Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-61943

23 дня назад

Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-61961

Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.

CVSS3: 7.1
0%
Низкий
9 дней назад
nvd логотип
CVE-2026-6195

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument admpass leads to os command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 9.8
14%
Средний
4 месяца назад
nvd логотип
CVE-2026-61959

Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions.

CVSS3: 6.5
0%
Низкий
9 дней назад
nvd логотип
CVE-2026-61958

Missing Authorization vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects License Manager for WooCommerce: from n/a through <= 3.0.17.

CVSS3: 5.4
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-61957

Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.

CVSS3: 7.1
0%
Низкий
18 дней назад
nvd логотип
CVE-2026-61956

Cross-Site Request Forgery (CSRF) vulnerability in hamsalam ووسلام &#8211; همگام سازی ووکامرس و باسلام sync-basalam allows Cross Site Request Forgery.This issue affects ووسلام &#8211; همگام سازی ووکامرس و باسلام: from n/a through <= 1.9.1.

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-61955

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hannan گرویتی فرم فارسی persian-gravity-forms allows Blind SQL Injection.This issue affects گرویتی فرم فارسی: from n/a through <= 3.0.2.

CVSS3: 7.6
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-61954

Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.

CVSS3: 7.5
0%
Низкий
23 дня назад
nvd логотип
CVE-2026-61953

Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.

CVSS3: 7.2
0%
Низкий
18 дней назад
nvd логотип
CVE-2026-61952

Missing Authorization vulnerability in Jose Vega WooCommerce Bulk Edit Products – WP Sheet Editor woo-bulk-edit-products allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Bulk Edit Products – WP Sheet Editor: from n/a through <= 1.8.21.

CVSS3: 4.9
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-61951

Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.

CVSS3: 9.8
0%
Низкий
23 дня назад
nvd логотип
CVE-2026-61950

Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.

CVSS3: 9.3
0%
Низкий
23 дня назад
nvd логотип
CVE-2026-6194

A weakness has been identified in Totolink A3002MU B20211125.1046. Affected by this vulnerability is the function sub_410188 of the file /boafrm/formWlanSetup of the component HTTP Request Handler. This manipulation of the argument wan-url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.

CVSS3: 8.8
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-61949

Unauthenticated SQL Injection in Bookly <= 27.7 versions.

CVSS3: 9.3
0%
Низкий
23 дня назад
nvd логотип
CVE-2026-61948

Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.

CVSS3: 9.3
0%
Низкий
23 дня назад
nvd логотип
CVE-2026-61947

Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions.

CVSS3: 7.1
0%
Низкий
23 дня назад
nvd логотип
CVE-2026-61946

Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.

CVSS3: 6.5
0%
Низкий
23 дня назад
nvd логотип
CVE-2026-61945

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6.

CVSS3: 6.5
0%
Низкий
23 дня назад
nvd логотип
CVE-2026-61944

Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.

CVSS3: 7.1
0%
Низкий
23 дня назад
nvd логотип
CVE-2026-61943

Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.

CVSS3: 7.5
0%
Низкий
23 дня назад

Уязвимостей на страницу