|
2421
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to unauthorized database table creation due to missing authorization checks on the `createFluentCartTable` function in al…
|
CWE-862
Missing Authorization
|
CVE-2026-2306
|
2026-05-6 22:06 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2422
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.83. This is due to the 'Ai1wmve_Schedules_Controller::s…
|
CWE-862
Missing Authorization
|
CVE-2026-5753
|
2026-05-6 22:06 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2423
|
4.9 |
MEDIUM
Network
|
-
|
-
|
The Fluent Forms plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 6.2.1. This is due to insufficient path validation in the getAttachments() method of EmailNo…
|
CWE-22
Path Traversal
|
CVE-2026-6344
|
2026-05-6 22:06 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2424
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Affiliate Program Suite — SliceWP Affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in all versions up to, and including, 1.2.7. This is due to…
|
CWE-79
Cross-site Scripting
|
CVE-2026-6672
|
2026-05-6 22:06 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2425
|
7.2 |
HIGH
Network
|
-
|
-
|
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking_form_page_url' parameter in all versions up to, …
|
CWE-79
Cross-site Scripting
|
CVE-2026-7332
|
2026-05-6 22:06 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2426
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to and including 5.5.0. This is due to insufficient input sanitization on the customer cabinet profi…
|
CWE-79
Cross-site Scripting
|
CVE-2026-7457
|
2026-05-6 22:06 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2427
|
7.5 |
HIGH
Network
|
-
|
-
|
The Gravity Bookings Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.5.9 due to insufficient escaping on the user supplied parameter and lack of su…
|
CWE-89
SQL Injection
|
CVE-2026-1719
|
2026-05-6 22:06 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2428
|
10.0 |
CRITICAL
Network
|
vm2_project
|
vm2
|
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sandbox and run arbitrary code. This issue has been patched in version 3.11.0.
|
CWE-94 CWE-693
Code Injection Protection Mechanism Failure
|
CVE-2026-26332
|
2026-05-6 21:24 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2429
|
8.8 |
HIGH
Adjacent
|
dlink
|
dir-605l_firmware
|
D-Link DIR-605L Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the s…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2026-42372
|
2026-05-6 21:20 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2430
|
8.8 |
HIGH
Adjacent
|
dlink
|
dir-605l_firmware
|
D-Link DIR-605L Hardware Revision B2 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the s…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2026-42373
|
2026-05-6 21:19 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|