|
3401
|
8.2 |
HIGH
Network
|
-
|
-
|
All in One Video Downloader 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. At…
|
CWE-89
SQL Injection
|
CVE-2019-25726
|
2026-06-5 00:00 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3402
|
9.8 |
CRITICAL
Network
|
-
|
-
|
WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive files by manipulating the path parameter. Attackers…
|
CWE-22
Path Traversal
|
CVE-2019-25727
|
2026-06-5 00:00 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3403
|
8.2 |
HIGH
Network
|
-
|
-
|
Care2x 2.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by manipulating the ck_config cookie parameter. Attackers can inject …
|
CWE-89
SQL Injection
|
CVE-2019-25728
|
2026-06-5 00:00 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3404
|
9.8 |
CRITICAL
Network
|
-
|
-
|
PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP commands through the CSRF-TOKEN cookie paramete…
|
CWE-352
Origin Validation Error
|
CVE-2019-25729
|
2026-06-5 00:00 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3405
|
8.2 |
HIGH
Network
|
-
|
-
|
Listing Hub CMS 1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can s…
|
CWE-89
SQL Injection
|
CVE-2019-25730
|
2026-06-5 00:00 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3406
|
8.2 |
HIGH
Network
|
-
|
-
|
PHP EI-Tube Script 3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parameter. Attackers…
|
CWE-89
SQL Injection
|
CVE-2019-25732
|
2026-06-5 00:00 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3407
|
8.4 |
HIGH
Local
|
-
|
-
|
NetShareWatcher 1.5.8.0 contains a structured exception handler buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input. Attackers can craft a…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-25733
|
2026-06-5 00:00 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3408
|
4.0 |
MEDIUM
Local
|
-
|
-
|
Contact Form by WD 1.13.1 contains a cross-site request forgery vulnerability combined with local file inclusion that allows unauthenticated attackers to include arbitrary files by exploiting unsanit…
|
CWE-22
Path Traversal
|
CVE-2019-25734
|
2026-06-5 00:00 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3409
|
8.4 |
HIGH
Local
|
-
|
-
|
AllPlayer 7.4 contains a local buffer overflow vulnerability in URL handling that allows attackers to overwrite structured exception handling pointers by supplying an excessively long URL string. Att…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-25735
|
2026-06-5 00:00 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3410
|
8.4 |
HIGH
Local
|
-
|
-
|
LabF nfsAxe 3.7 Ping Client contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload in the Host IP field. Attackers can craft a…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-25736
|
2026-06-5 00:00 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3411
|
9.8 |
CRITICAL
Network
|
-
|
-
|
WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allows unauthenticated attackers to modify WordPress options by exploiting the hc_ajax_save_option actio…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-25738
|
2026-06-5 00:00 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3412
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Joomla com_jsjobs 1.2.6 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating custom userfield parameters. Attackers can send POST requ…
|
CWE-22
Path Traversal
|
CVE-2019-25740
|
2026-06-5 00:00 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3413
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Mobatek MobaXterm 12.1 contains a structured exception handling (SEH) based buffer overflow vulnerability in the username field of session files that allows remote attackers to execute arbitrary code…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-25741
|
2026-06-5 00:00 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3414
|
8.2 |
HIGH
Network
|
-
|
-
|
WordPress Plugin Google Review Slider 6.1 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through th…
|
CWE-89
SQL Injection
|
CVE-2019-25745
|
2026-06-5 00:00 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3415
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulnerability is the function Login of the file /admin/admin_class_novo.php of the component Administrat…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-10704
|
2026-06-4 23:58 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3416
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in DedeCMS 5.7.88. The impacted element is the function dede_htmlspecialchars of the file /plus/flink.php. The manipulation of the argument msg leads to sql injection. …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-10607
|
2026-06-4 23:56 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3417
|
7.3 |
HIGH
Network
|
-
|
-
|
A security flaw has been discovered in DedeCMS 5.7.88. This affects the function RemoveXSS of the file /plus/carbuyaction.php. The manipulation of the argument postname/des results in sql injection. …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-10608
|
2026-06-4 23:56 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3418
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in nextlevelbuilder GoClaw up to 3.11.3. The impacted element is the function TeamTasksTool.executeComplete of the file internal/tools/team_tasks_lifecycle.go of the co…
|
CWE-862 CWE-863
Missing Authorization Incorrect Authorization
|
CVE-2026-10616
|
2026-06-4 23:56 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3419
|
7.3 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. This affects the function resolveAuth of the file internal/http/auth.go of the component Webhook Verification Handl…
|
CWE-287 CWE-306
Improper Authentication Missing Authentication for Critical Function
|
CVE-2026-10617
|
2026-06-4 23:56 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3420
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. Impacted is the function Open of the file src/blender_mcp/server.py. The manipulation of the arg…
|
CWE-74 CWE-707
Injection Improper Enforcement of Message or Data Structure
|
CVE-2026-10661
|
2026-06-4 23:56 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3421
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. The affected element is the function requests.get of the file src/blender_mcp/server.py of the compon…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-10662
|
2026-06-4 23:56 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3422
|
5.5 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. The impacted element is the function execute_blender_code of the file /src/blender_mcp/server.py…
|
CWE-74 CWE-94
Injection Code Injection
|
CVE-2026-10688
|
2026-06-4 23:56 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3423
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in itsourcecode Fees Management System 1.0. This affects an unknown function of the file /manage_student.php. The manipulation of the argument ID leads to sql injection…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-10808
|
2026-06-4 23:41 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3424
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in itsourcecode Fees Management System 1.0. This impacts an unknown function of the file /manage_user.php. The manipulation of the argument ID results in sql injec…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-10809
|
2026-06-4 23:41 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3425
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in itsourcecode Fees Management System up to 1.0. Affected is an unknown function of the file /navbar.php. This manipulation of the argument page causes cross site scri…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-10810
|
2026-06-4 23:41 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3426
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in mjperpinosa stumasy. The affected element is an unknown function of the file application/PHP/objects/updates/add_post.php. Performing a manipulation of the argument up_fi…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-10806
|
2026-06-4 23:41 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3427
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in mjperpinosa stumasy. The impacted element is an unknown function of the file application/PHP/objects/profiles/change_profile_image.php. Executing a manipulation of t…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-10807
|
2026-06-4 23:41 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3428
|
- |
-
|
-
|
-
|
Rejected reason: After analysis, the originally reported behaviour was determined not to constitute a security vulnerability. The findings were parser-strictness defects without an exploitable framin…
|
-
|
CVE-2026-8762
|
2026-06-4 23:16 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3429
|
5.3 |
MEDIUM
Network
|
oracle
|
rest_data_services
|
Vulnerability in Oracle REST Data Services (component: General). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network…
|
CWE-200
Information Exposure
|
CVE-2026-46841
|
2026-06-4 23:07 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3430
|
10.0 |
CRITICAL
Network
|
oracle
|
rest_data_services
|
Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker…
|
CWE-284 CWE-287 CWE-306
Improper Access Control Improper Authentication Missing Authentication for Critical Function
|
CVE-2026-46840
|
2026-06-4 23:01 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3431
|
9.9 |
CRITICAL
Network
|
oracle
|
rest_data_services
|
Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network acc…
|
CWE-284
Improper Access Control
|
CVE-2026-46839
|
2026-06-4 22:58 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3432
|
6.1 |
MEDIUM
Network
|
-
|
-
|
A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote locations into an active user session on an affected device, possibly leading to b…
|
CWE-73
External Control of File Name or Path
|
CVE-2026-20175
|
2026-06-4 22:54 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3433
|
8.6 |
HIGH
Network
|
-
|
-
|
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attack…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-20230
|
2026-06-4 22:54 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3434
|
8.8 |
HIGH
Network
|
-
|
-
|
The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.02 via the 'et_pb_text' shortcode 'cvdb_content_visibility_…
|
CWE-94
Code Injection
|
CVE-2026-1829
|
2026-06-4 22:53 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3435
|
7.3 |
HIGH
Network
|
-
|
-
|
A flaw has been found in code-projects Student Admission System 1.0. Affected is an unknown function of the file /index.php. This manipulation of the argument eid/did causes sql injection. The attack…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-10620
|
2026-06-4 22:53 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3436
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in SourceCodester Human Resource Management 1.0. Affected by this vulnerability is an unknown functionality of the file /detailview.php of the component Employee View P…
|
CWE-99
Resource Injection
|
CVE-2026-10624
|
2026-06-4 22:53 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3437
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in sayan365 student-management-system up to 7f3c9ce7d410332335c2affac93a385485051800. This impacts an unknown function. The manipulation results in improper authenticatio…
|
CWE-287
Improper Authentication
|
CVE-2026-10619
|
2026-06-4 22:53 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3438
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in warmcat libwebsockets up to 4.5.8. This issue affects the function lws_ssh_parse_plaintext of the file plugins/protocol_lws_ssh_base/sshd.c of the component SSH Protocol Hand…
|
CWE-400 CWE-404
Uncontrolled Resource Consumption Improper Resource Shutdown or Release
|
CVE-2026-10650
|
2026-06-4 22:53 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3439
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the component Administrative Endpoint. T…
|
CWE-266 CWE-285
Incorrect Privilege Assignment Improper Authorization
|
CVE-2026-10693
|
2026-06-4 22:53 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3440
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this issue is the function include of the file /index.php. The manipulation of the argument page results in…
|
CWE-73
External Control of File Name or Path
|
CVE-2026-10694
|
2026-06-4 22:53 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3441
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in johnhuang316 code-index-mcp up to 2.14.0. Affected is the function is_safe_regex_pattern of the component search_code_advanced. Executing a manipulation of the argum…
|
CWE-400 CWE-1333
Uncontrolled Resource Consumption Inefficient Regular Expression Complexity
|
CVE-2026-10692
|
2026-06-4 22:53 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3442
|
4.4 |
MEDIUM
Network
|
-
|
-
|
The Passeum Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.0. This is due to the `get_shop_url()` method returning the `shop_name`…
|
CWE-79
Cross-site Scripting
|
CVE-2026-7421
|
2026-06-4 22:53 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3443
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The EmergencyWP – Dead Man's switch & legacy deliverance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing or incorr…
|
CWE-352
Origin Validation Error
|
CVE-2026-9732
|
2026-06-4 22:53 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3444
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fox-themes Prague allows Reflected XSS.
This issue affects Prague: from n/a through 2.2.8.
|
CWE-79
Cross-site Scripting
|
CVE-2025-15654
|
2026-06-4 22:53 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3445
|
7.6 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla School Management allows SQL Injection.
This issue affects School Management: from n/a …
|
CWE-89
SQL Injection
|
CVE-2025-15655
|
2026-06-4 22:53 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3446
|
8.8 |
HIGH
Network
|
-
|
-
|
Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation.
This issue affects School Management: from n/a through 93.2.0.
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2025-15656
|
2026-06-4 22:53 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3447
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The MasterStudy LMS Pro Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'columns' parameter in all versions up to, and including, 4.8.20 due to insufficient escaping on the u…
|
CWE-89
SQL Injection
|
CVE-2026-8653
|
2026-06-4 22:53 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3448
|
7.5 |
HIGH
Network
|
-
|
-
|
The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the view_file function in all versions up to, and including, 4.71. Thi…
|
CWE-862
Missing Authorization
|
CVE-2026-10737
|
2026-06-4 22:53 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3449
|
7.6 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Photo Gallery by 10Web allows Blind SQL Injection.
This issue affects Photo Gallery by 10W…
|
CWE-89
SQL Injection
|
CVE-2026-49771
|
2026-06-4 22:53 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3450
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tips and Tricks HQ WP eMember allows Retrieve Embedded Sensitive Data.
This issue affects WP eMember: from…
|
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
|
CVE-2026-49077
|
2026-06-4 22:53 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|