Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 377 179

Количество 377 179

nvd логотип

CVE-2026-61985

около 1 месяца назад

Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Car Rental Manager: from n/a through <= 1.3.7.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-61984

2 дня назад

Unauthenticated Broken Access Control in WPMobile.App <= 11.77 versions.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-61983

около 1 месяца назад

Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Church Admin: from n/a through <= 5.0.30.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-61982

9 дней назад

Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-61981

23 дня назад

Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-61980

2 дня назад

Unauthenticated Arbitrary File Download in OMGF Pro <= 5.2.7 versions.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-6197

4 месяца назад

A flaw has been found in Tenda F456 1.0.0.5. This vulnerability affects the function formWrlsafeset of the file /goform/AdvSetWrlsafeset. Executing a manipulation of the argument mit_ssid can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-61979

2 дня назад

Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-61978

2 дня назад

Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-61977

около 1 месяца назад

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetSearch jet-search allows Retrieve Embedded Sensitive Data.This issue affects JetSearch: from n/a through <= 3.6.1.2.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-61976

около 1 месяца назад

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Retrieve Embedded Sensitive Data.This issue affects JetBlocks For Elementor: from n/a through <= 1.5.0.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-61975

около 1 месяца назад

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetReviews jet-reviews allows Retrieve Embedded Sensitive Data.This issue affects JetReviews: from n/a through <= 3.0.1.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-61974

2 дня назад

Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.3.4 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-61973

23 дня назад

Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-61972

23 дня назад

Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-61971

около 1 месяца назад

Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs User Profile Picture metronet-profile-picture allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Profile Picture: from n/a through <= 2.6.3.

CVSS3: 2.7
EPSS: Низкий
nvd логотип

CVE-2026-61970

около 1 месяца назад

Server-Side Request Forgery (SSRF) vulnerability in Themeisle Auto Featured Image (Auto Post Thumbnail) auto-post-thumbnail allows Server Side Request Forgery.This issue affects Auto Featured Image (Auto Post Thumbnail): from n/a through <= 5.0.4.

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2026-6196

4 месяца назад

A vulnerability was detected in Tenda F456 1.0.0.5. This affects the function fromexeCommand of the file /goform/exeCommand. Performing a manipulation of the argument cmdinput results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-61969

2 дня назад

Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2026-61968

около 1 месяца назад

Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects myCred: from n/a through <= 3.1.2.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-61985

Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Car Rental Manager: from n/a through <= 1.3.7.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-61984

Unauthenticated Broken Access Control in WPMobile.App <= 11.77 versions.

CVSS3: 7.5
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-61983

Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Church Admin: from n/a through <= 5.0.30.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-61982

Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions.

CVSS3: 7.1
0%
Низкий
9 дней назад
nvd логотип
CVE-2026-61981

Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.

CVSS3: 5.4
0%
Низкий
23 дня назад
nvd логотип
CVE-2026-61980

Unauthenticated Arbitrary File Download in OMGF Pro <= 5.2.7 versions.

CVSS3: 7.5
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-6197

A flaw has been found in Tenda F456 1.0.0.5. This vulnerability affects the function formWrlsafeset of the file /goform/AdvSetWrlsafeset. Executing a manipulation of the argument mit_ssid can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used.

CVSS3: 8.8
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-61979

Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions.

CVSS3: 8.1
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-61978

Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions.

CVSS3: 6.5
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-61977

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetSearch jet-search allows Retrieve Embedded Sensitive Data.This issue affects JetSearch: from n/a through <= 3.6.1.2.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-61976

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Retrieve Embedded Sensitive Data.This issue affects JetBlocks For Elementor: from n/a through <= 1.5.0.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-61975

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetReviews jet-reviews allows Retrieve Embedded Sensitive Data.This issue affects JetReviews: from n/a through <= 3.0.1.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-61974

Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.3.4 versions.

CVSS3: 7.1
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-61973

Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.

CVSS3: 4.3
0%
Низкий
23 дня назад
nvd логотип
CVE-2026-61972

Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.

CVSS3: 5.3
0%
Низкий
23 дня назад
nvd логотип
CVE-2026-61971

Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs User Profile Picture metronet-profile-picture allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Profile Picture: from n/a through <= 2.6.3.

CVSS3: 2.7
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-61970

Server-Side Request Forgery (SSRF) vulnerability in Themeisle Auto Featured Image (Auto Post Thumbnail) auto-post-thumbnail allows Server Side Request Forgery.This issue affects Auto Featured Image (Auto Post Thumbnail): from n/a through <= 5.0.4.

CVSS3: 4.9
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-6196

A vulnerability was detected in Tenda F456 1.0.0.5. This affects the function fromexeCommand of the file /goform/exeCommand. Performing a manipulation of the argument cmdinput results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.

CVSS3: 8.8
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-61969

Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.

CVSS3: 9.3
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-61968

Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects myCred: from n/a through <= 3.1.2.

CVSS3: 5.4
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу