Количество 377 179
Количество 377 179
CVE-2026-61967
Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.
CVE-2026-61966
Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.
CVE-2026-61965
Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versions.
CVE-2026-61964
Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions.
CVE-2026-61963
Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions.
CVE-2026-61962
Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
CVE-2026-61961
Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.
CVE-2026-61960
Unauthenticated Cross Site Scripting (XSS) in WP Full Stripe Free <= 8.5.0 versions.
CVE-2026-6195
A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument admpass leads to os command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
CVE-2026-61959
Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions.
CVE-2026-61958
Missing Authorization vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects License Manager for WooCommerce: from n/a through <= 3.0.17.
CVE-2026-61957
Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.
CVE-2026-61956
Cross-Site Request Forgery (CSRF) vulnerability in hamsalam ووسلام – همگام سازی ووکامرس و باسلام sync-basalam allows Cross Site Request Forgery.This issue affects ووسلام – همگام سازی ووکامرس و باسلام: from n/a through <= 1.9.1.
CVE-2026-61955
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hannan گرویتی فرم فارسی persian-gravity-forms allows Blind SQL Injection.This issue affects گرویتی فرم فارسی: from n/a through <= 3.0.2.
CVE-2026-61954
Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.
CVE-2026-61953
Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.
CVE-2026-61952
Missing Authorization vulnerability in Jose Vega WooCommerce Bulk Edit Products – WP Sheet Editor woo-bulk-edit-products allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Bulk Edit Products – WP Sheet Editor: from n/a through <= 1.8.21.
CVE-2026-61951
Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.
CVE-2026-61950
Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.
CVE-2026-6194
A weakness has been identified in Totolink A3002MU B20211125.1046. Affected by this vulnerability is the function sub_410188 of the file /boafrm/formWlanSetup of the component HTTP Request Handler. This manipulation of the argument wan-url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-61967 Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions. | CVSS3: 9.8 | 0% Низкий | 2 дня назад | |
CVE-2026-61966 Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions. | CVSS3: 9.3 | 0% Низкий | 2 дня назад | |
CVE-2026-61965 Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versions. | CVSS3: 7.1 | 0% Низкий | 2 дня назад | |
CVE-2026-61964 Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions. | CVSS3: 7.1 | 0% Низкий | 9 дней назад | |
CVE-2026-61963 Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions. | CVSS3: 7.1 | 0% Низкий | 9 дней назад | |
CVE-2026-61962 Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions. | CVSS3: 10 | 0% Низкий | 2 дня назад | |
CVE-2026-61961 Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions. | CVSS3: 7.1 | 0% Низкий | 9 дней назад | |
CVE-2026-61960 Unauthenticated Cross Site Scripting (XSS) in WP Full Stripe Free <= 8.5.0 versions. | CVSS3: 7.1 | 0% Низкий | 2 дня назад | |
CVE-2026-6195 A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument admpass leads to os command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. | CVSS3: 9.8 | 14% Средний | 4 месяца назад | |
CVE-2026-61959 Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions. | CVSS3: 6.5 | 0% Низкий | 9 дней назад | |
CVE-2026-61958 Missing Authorization vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects License Manager for WooCommerce: from n/a through <= 3.0.17. | CVSS3: 5.4 | 0% Низкий | около 1 месяца назад | |
CVE-2026-61957 Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions. | CVSS3: 7.1 | 0% Низкий | 19 дней назад | |
CVE-2026-61956 Cross-Site Request Forgery (CSRF) vulnerability in hamsalam ووسلام – همگام سازی ووکامرس و باسلام sync-basalam allows Cross Site Request Forgery.This issue affects ووسلام – همگام سازی ووکامرس و باسلام: from n/a through <= 1.9.1. | CVSS3: 7.1 | 0% Низкий | около 1 месяца назад | |
CVE-2026-61955 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hannan گرویتی فرم فارسی persian-gravity-forms allows Blind SQL Injection.This issue affects گرویتی فرم فارسی: from n/a through <= 3.0.2. | CVSS3: 7.6 | 0% Низкий | около 1 месяца назад | |
CVE-2026-61954 Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions. | CVSS3: 7.5 | 0% Низкий | 23 дня назад | |
CVE-2026-61953 Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions. | CVSS3: 7.2 | 0% Низкий | 19 дней назад | |
CVE-2026-61952 Missing Authorization vulnerability in Jose Vega WooCommerce Bulk Edit Products – WP Sheet Editor woo-bulk-edit-products allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Bulk Edit Products – WP Sheet Editor: from n/a through <= 1.8.21. | CVSS3: 4.9 | 0% Низкий | около 1 месяца назад | |
CVE-2026-61951 Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions. | CVSS3: 9.8 | 0% Низкий | 23 дня назад | |
CVE-2026-61950 Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions. | CVSS3: 9.3 | 0% Низкий | 23 дня назад | |
CVE-2026-6194 A weakness has been identified in Totolink A3002MU B20211125.1046. Affected by this vulnerability is the function sub_410188 of the file /boafrm/formWlanSetup of the component HTTP Request Handler. This manipulation of the argument wan-url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. | CVSS3: 8.8 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу