Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-6206

The MW WP Form plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 5.1.2 via the _get_post_property_from_querystring() function due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from password protected, private, or draft posts that they should not have access to.

PUBLISHED
Vendor
websoudan
Product
MW WP Form
Provider severity
MEDIUM
Conflicts
0

CVE-2026-6204

LibreNMS versions before 26.3.0 are affected by an authenticated remote code execution vulnerability by abusing the Binary Locations config and the Netcommand feature. Successful exploitation requires administrative privileges. Exploitation could result in compromise of the underlying web server.

PUBLISHED
Vendor
librenms
Product
librenms
Provider severity
HIGH
Conflicts
0

CVE-2026-6203

The User Registration & Membership plugin for WordPress is vulnerable to Open Redirect in versions up to and including 5.1.4. This is due to insufficient validation of user-supplied URLs passed via the 'redirect_to_on_logout' GET parameter before redirecting users. The `redirect_to_on_logout` GET parameter is passed directly to WordPress's `wp_redirect()` function instead of the domain-restricted `wp_safe_redirect()`. While `esc_url_raw()` is applied to sanitize malformed URLs, it does not restr

PUBLISHED
Vendor
wpeverest
Product
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2026-6202

A security flaw has been discovered in code-projects Easy Blog Site 1.0. This affects an unknown function of the file post.php. Performing a manipulation of the argument tags results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.

PUBLISHED
Vendor
code-projects
Product
Easy Blog Site
Provider severity
MEDIUM
Conflicts
2

CVE-2026-6201

A vulnerability was identified in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the file /jobs/job-delete.php of the component Delete Job Posting Handler. Such manipulation of the argument ID leads to improper access controls. The attack can be launched remotely. The exploit is publicly available and might be used.

PUBLISHED
Vendor
CodeAstro
Product
Online Job Portal
Provider severity
MEDIUM
Conflicts
2

CVE-2026-6200

A vulnerability was determined in Tenda F456 1.0.0.5. The affected element is the function formwebtypelibrary of the file /goform/webtypelibrary. This manipulation of the argument menufacturer/Go causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
Tenda
Product
F456
Provider severity
HIGH
Conflicts
2

CVE-2026-6199

A vulnerability was found in Tenda F456 1.0.0.5. Impacted is the function fromqossetting of the file /goform/qossetting. The manipulation of the argument page results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used.

PUBLISHED
Vendor
Tenda
Product
F456
Provider severity
HIGH
Conflicts
2

CVE-2026-61985

Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Car Rental Manager: from n/a through <= 1.3.7.

PUBLISHED
Vendor
magepeopleteam
Product
Car Rental Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2026-61983

Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Church Admin: from n/a through <= 5.0.30.

PUBLISHED
Vendor
andy_moyle
Product
Church Admin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-61981

Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.

PUBLISHED
Vendor
QuantumCloud
Product
Simple Link Directory Pro
Provider severity
MEDIUM
Conflicts
0

CVE-2026-6198

A vulnerability has been found in Tenda F456 1.0.0.5. This issue affects the function fromNatStaticSetting of the file /goform/NatStaticSetting. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
Tenda
Product
F456
Provider severity
HIGH
Conflicts
2

CVE-2026-61977

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetSearch jet-search allows Retrieve Embedded Sensitive Data.This issue affects JetSearch: from n/a through <= 3.6.1.2.

PUBLISHED
Vendor
Crocoblock
Product
JetSearch
Provider severity
MEDIUM
Conflicts
0

CVE-2026-61976

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Retrieve Embedded Sensitive Data.This issue affects JetBlocks For Elementor: from n/a through <= 1.5.0.

PUBLISHED
Vendor
Crocoblock
Product
JetBlocks For Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2026-61975

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetReviews jet-reviews allows Retrieve Embedded Sensitive Data.This issue affects JetReviews: from n/a through <= 3.0.1.

PUBLISHED
Vendor
Crocoblock
Product
JetReviews
Provider severity
MEDIUM
Conflicts
0

CVE-2026-61973

Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.

PUBLISHED
Vendor
WooLentor
Product
ShopLentor Pro
Provider severity
MEDIUM
Conflicts
0

CVE-2026-61972

Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.

PUBLISHED
Vendor
WooLentor
Product
ShopLentor Pro
Provider severity
MEDIUM
Conflicts
0

CVE-2026-61971

Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs User Profile Picture metronet-profile-picture allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Profile Picture: from n/a through <= 2.6.3.

PUBLISHED
Vendor
Cozmoslabs
Product
User Profile Picture
Provider severity
LOW
Conflicts
0

CVE-2026-61970

Server-Side Request Forgery (SSRF) vulnerability in Themeisle Auto Featured Image (Auto Post Thumbnail) auto-post-thumbnail allows Server Side Request Forgery.This issue affects Auto Featured Image (Auto Post Thumbnail): from n/a through <= 5.0.4.

PUBLISHED
Vendor
Themeisle
Product
Auto Featured Image (Auto Post Thumbnail)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-6197

A flaw has been found in Tenda F456 1.0.0.5. This vulnerability affects the function formWrlsafeset of the file /goform/AdvSetWrlsafeset. Executing a manipulation of the argument mit_ssid can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used.

PUBLISHED
Vendor
Tenda
Product
F456
Provider severity
HIGH
Conflicts
2

CVE-2026-61968

Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects myCred: from n/a through <= 3.1.2.

PUBLISHED
Vendor
Saad Iqbal
Product
myCred
Provider severity
MEDIUM
Conflicts
0

CVE-2026-6196

A vulnerability was detected in Tenda F456 1.0.0.5. This affects the function fromexeCommand of the file /goform/exeCommand. Performing a manipulation of the argument cmdinput results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.

PUBLISHED
Vendor
Tenda
Product
F456
Provider severity
HIGH
Conflicts
2

CVE-2026-61958

Missing Authorization vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects License Manager for WooCommerce: from n/a through <= 3.0.17.

PUBLISHED
Vendor
Saad Iqbal
Product
License Manager for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-61957

Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.

PUBLISHED
Vendor
miniOrange
Product
miniorange otp verification
Provider severity
HIGH
Conflicts
0

CVE-2026-61956

Cross-Site Request Forgery (CSRF) vulnerability in hamsalam ووسلام &#8211; همگام سازی ووکامرس و باسلام sync-basalam allows Cross Site Request Forgery.This issue affects ووسلام &#8211; همگام سازی ووکامرس و باسلام: from n/a through <= 1.9.1.

PUBLISHED
Vendor
hamsalam
Product
ووسلام &#8211; همگام سازی ووکامرس و باسلام
Provider severity
HIGH
Conflicts
0

CVE-2026-61955

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hannan گرویتی فرم فارسی persian-gravity-forms allows Blind SQL Injection.This issue affects گرویتی فرم فارسی: from n/a through <= 3.0.2.

PUBLISHED
Vendor
Hannan
Product
گرویتی فرم فارسی
Provider severity
HIGH
Conflicts
0

CVE-2026-61954

Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.

PUBLISHED
Vendor
PayU India
Product
PayU India
Provider severity
HIGH
Conflicts
0

CVE-2026-61953

Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.

PUBLISHED
Vendor
QuantumCloud
Product
Simple Link Directory Pro
Provider severity
HIGH
Conflicts
0

CVE-2026-61952

Missing Authorization vulnerability in Jose Vega WooCommerce Bulk Edit Products – WP Sheet Editor woo-bulk-edit-products allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Bulk Edit Products – WP Sheet Editor: from n/a through <= 1.8.21.

PUBLISHED
Vendor
Jose Vega
Product
WooCommerce Bulk Edit Products – WP Sheet Editor
Provider severity
MEDIUM
Conflicts
0

CVE-2026-61951

Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.

PUBLISHED
Vendor
themetechmount
Product
TrueBooker
Provider severity
CRITICAL
Conflicts
0

CVE-2026-61950

Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.

PUBLISHED
Vendor
themetechmount
Product
TrueBooker
Provider severity
CRITICAL
Conflicts
0

CVE-2026-6195

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument admpass leads to os command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
Totolink
Product
A7100RU
Provider severity
CRITICAL
Conflicts
2

CVE-2026-61949

Unauthenticated SQL Injection in Bookly <= 27.7 versions.

PUBLISHED
Vendor
Bookly
Product
Bookly
Provider severity
CRITICAL
Conflicts
0

CVE-2026-61948

Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.

PUBLISHED
Vendor
Shahjada
Product
WPDM – Premium Packages
Provider severity
CRITICAL
Conflicts
0

CVE-2026-61947

Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions.

PUBLISHED
Vendor
WPVibes
Product
Form Vibes – Database Manager for Forms
Provider severity
HIGH
Conflicts
0

CVE-2026-61946

Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.

PUBLISHED
Vendor
Easy Appointments
Product
Easy Appointments
Provider severity
MEDIUM
Conflicts
0

CVE-2026-61945

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6.

PUBLISHED
Vendor
MultiVendorX
Product
WooCommerce Product Stock Alert
Provider severity
MEDIUM
Conflicts
0

CVE-2026-61944

Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.

PUBLISHED
Vendor
Bookly
Product
Bookly
Provider severity
HIGH
Conflicts
0

CVE-2026-61943

Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.

PUBLISHED
Vendor
Shahjada
Product
WPDM – Premium Packages
Provider severity
HIGH
Conflicts
0

CVE-2026-6194

A weakness has been identified in Totolink A3002MU B20211125.1046. Affected by this vulnerability is the function sub_410188 of the file /boafrm/formWlanSetup of the component HTTP Request Handler. This manipulation of the argument wan-url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.

PUBLISHED
Vendor
Totolink
Product
A3002MU
Provider severity
HIGH
Conflicts
2

CVE-2026-6193

A security flaw has been discovered in PHPGurukul Daily Expense Tracking System 1.1. Affected is an unknown function of the file /register.php. The manipulation of the argument email results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.

PUBLISHED
Vendor
PHPGurukul
Product
Daily Expense Tracking System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-6192

A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This impacts the function opj_pi_initialise_encode in the library src/lib/openjp2/pi.c. The manipulation leads to integer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. The identifier of the patch is 839936aa33eb8899bbbd80fda02796bb65068951. It is suggested to install a patch to address this issue.

PUBLISHED
Vendor
uclouvain
Product
openjpeg
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-6191

A vulnerability was determined in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /equipments.php. Executing a manipulation of the argument Name can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
itsourcecode
Product
Construction Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-61901

Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2 - The Joomla extension Hikashop is vulnerable to an open redirect.

PUBLISHED
Vendor
hikashop.com
Product
Hikashop extension for Joomla
Provider severity
MEDIUM
Conflicts
0

CVE-2026-61900

Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE.

PUBLISHED
Vendor
dj-extensions.com
Product
jDownloads extension for Joomla
Provider severity
CRITICAL
Conflicts
0

CVE-2026-6190

A vulnerability was found in itsourcecode Construction Management System 1.0. The impacted element is an unknown function of the file /employees.php. Performing a manipulation of the argument Name results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.

PUBLISHED
Vendor
itsourcecode
Product
Construction Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-61893

A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBuffer to read one byte past the end of the heap-allocated message buffer.

PUBLISHED
Vendor
MZ Automation
Product
lib60870
Provider severity
MEDIUM
Conflicts
1

CVE-2026-61892

Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.

PUBLISHED
Vendor
Weintek, Weintek
Product
cMT3092X firmware, EasyWeb
Provider severity
HIGH
Conflicts
2

CVE-2026-6189

A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. The affected element is an unknown function of the file /ajax.php?action=login. Such manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
SourceCodester
Product
Pharmacy Sales and Inventory System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-61886

Weintek cMT3092X HMI stores user account passwords in plaintext.

PUBLISHED
Vendor
Weintek, Weintek
Product
EasyWeb, cMT3092X firmware
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-61884

The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check and establish a valid administrative session. This grants full access to device controls including power relay management, device reboot, remote access service configuration, and network settings, which could allow an attacker

PUBLISHED
Vendor
Tycon Systems
Product
TPDIN-Monitor-WEB2
Provider severity
CRITICAL
Conflicts
1