Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 378 322

Количество 378 322

nvd логотип

CVE-2026-61950

25 дней назад

Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2026-6194

4 месяца назад

A weakness has been identified in Totolink A3002MU B20211125.1046. Affected by this vulnerability is the function sub_410188 of the file /boafrm/formWlanSetup of the component HTTP Request Handler. This manipulation of the argument wan-url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-61949

25 дней назад

Unauthenticated SQL Injection in Bookly <= 27.7 versions.

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2026-61948

25 дней назад

Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2026-61947

25 дней назад

Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-61946

25 дней назад

Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-61945

25 дней назад

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-61944

25 дней назад

Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-61943

25 дней назад

Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-6193

4 месяца назад

A security flaw has been discovered in PHPGurukul Daily Expense Tracking System 1.1. Affected is an unknown function of the file /register.php. The manipulation of the argument email results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2026-61939

6 дней назад

Use after free in Winlogon allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2026-61938

6 дней назад

Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2026-61937

6 дней назад

Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-61936

6 дней назад

Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-61934

6 дней назад

Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-61933

6 дней назад

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-61932

6 дней назад

Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-61930

6 дней назад

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-6192

4 месяца назад

A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This impacts the function opj_pi_initialise_encode in the library src/lib/openjp2/pi.c. The manipulation leads to integer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. The identifier of the patch is 839936aa33eb8899bbbd80fda02796bb65068951. It is suggested to install a patch to address this issue.

CVSS3: 3.3
EPSS: Низкий
nvd логотип

CVE-2026-61929

6 дней назад

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-61950

Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.

CVSS3: 9.3
0%
Низкий
25 дней назад
nvd логотип
CVE-2026-6194

A weakness has been identified in Totolink A3002MU B20211125.1046. Affected by this vulnerability is the function sub_410188 of the file /boafrm/formWlanSetup of the component HTTP Request Handler. This manipulation of the argument wan-url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.

CVSS3: 8.8
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-61949

Unauthenticated SQL Injection in Bookly <= 27.7 versions.

CVSS3: 9.3
0%
Низкий
25 дней назад
nvd логотип
CVE-2026-61948

Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.

CVSS3: 9.3
0%
Низкий
25 дней назад
nvd логотип
CVE-2026-61947

Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions.

CVSS3: 7.1
0%
Низкий
25 дней назад
nvd логотип
CVE-2026-61946

Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.

CVSS3: 6.5
0%
Низкий
25 дней назад
nvd логотип
CVE-2026-61945

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6.

CVSS3: 6.5
0%
Низкий
25 дней назад
nvd логотип
CVE-2026-61944

Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.

CVSS3: 7.1
0%
Низкий
25 дней назад
nvd логотип
CVE-2026-61943

Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.

CVSS3: 7.5
0%
Низкий
25 дней назад
nvd логотип
CVE-2026-6193

A security flaw has been discovered in PHPGurukul Daily Expense Tracking System 1.1. Affected is an unknown function of the file /register.php. The manipulation of the argument email results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.

CVSS3: 7.3
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-61939

Use after free in Winlogon allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
6 дней назад
nvd логотип
CVE-2026-61938

Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
6 дней назад
nvd логотип
CVE-2026-61937

Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
6 дней назад
nvd логотип
CVE-2026-61936

Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.

CVSS3: 5.5
0%
Низкий
6 дней назад
nvd логотип
CVE-2026-61934

Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
6 дней назад
nvd логотип
CVE-2026-61933

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

CVSS3: 5.5
0%
Низкий
6 дней назад
nvd логотип
CVE-2026-61932

Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
6 дней назад
nvd логотип
CVE-2026-61930

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
2%
Низкий
6 дней назад
nvd логотип
CVE-2026-6192

A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This impacts the function opj_pi_initialise_encode in the library src/lib/openjp2/pi.c. The manipulation leads to integer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. The identifier of the patch is 839936aa33eb8899bbbd80fda02796bb65068951. It is suggested to install a patch to address this issue.

CVSS3: 3.3
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-61929

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVSS3: 7
2%
Низкий
6 дней назад

Уязвимостей на страницу