|
181
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Authorization Bypass Through User-Controlled Key vulnerability in Matteo Manna Simple User Avatar allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Simple U…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-57676
|
2026-06-30 03:39 |
2026-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
182
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Epiphyt Embed Privacy allows Path Traversal.
This issue affects Embed Privacy: from n/a through 1.12.3.
New
|
CWE-22
Path Traversal
|
CVE-2026-57346
|
2026-06-30 03:39 |
2026-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
183
|
7.1 |
HIGH
Network
|
-
|
-
|
Unauthenticated Cross Site Scripting (XSS) in BEAR <= 1.1.8 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-57320
|
2026-06-30 03:39 |
2026-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
184
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-57326
|
2026-06-30 03:39 |
2026-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
185
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Subscriber Broken Access Control in MainWP <= 6.1.1 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-57327
|
2026-06-30 03:39 |
2026-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
186
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-57328
|
2026-06-30 03:39 |
2026-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
187
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Subscriber Cross Site Scripting (XSS) in WooCommerce Designer Pro <= 1.9.34 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-57329
|
2026-06-30 03:39 |
2026-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
188
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Subscriber Cross Site Scripting (XSS) in MasterStudy LMS <= 3.7.27 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-57330
|
2026-06-30 03:39 |
2026-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
189
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.
New
|
CWE-22
Path Traversal
|
CVE-2026-57331
|
2026-06-30 03:39 |
2026-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190
|
7.1 |
HIGH
Network
|
-
|
-
|
Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-57332
|
2026-06-30 03:39 |
2026-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|