3w ago
2026-08-27 10:16Z
HIGH

CVE-2026-78285 — Subscriber: SQL Injection in Like Button Rating <= 2.6.61 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78285

Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
3w ago
2026-08-27 10:16Z
CRIT

CVE-2026-78274 — Editor: Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78274

Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions. CVSSv3.1 9.1 (CRITICAL)

CWECWE 434VNDEditorTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3w ago
2026-08-27 10:16Z
CRIT

CVE-2026-78260 — SQL: Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78260

Unauthenticated SQL Injection in Epayco <= 8.4.6 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
3w ago
2026-08-27 10:16Z
HIGH

CVE-2026-78257 — Contributor: PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78257

Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDContributorTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-27 10:16Z
HIGH

CVE-2026-75020 — Apache Apisix: Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75020

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache APISIX. A caller who holds valid credentials for one entry in the LDAP directory can authenticate through APISIX as a consumer mapped to a different entry, one the plugin's configured scope was meant to keep out of reach. This issue affects Apache APISIX: from 2.11.0 through 3.17.0. Users are recommended to upgrade to version 3.18.0, which fixes the issue. CVSSv3.1 8.1 (HIGH) · EPSS 41th percentile

CWECWE 90VNDApacheTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-27 10:16Z
CRIT

CVE-2026-59354 — Spring: In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59354

In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation of certain client metadata fields supplied by the registering client. An attacker who possesses a valid Initial Access Token can register a malicious client with crafted metadata, which, depending on server configuration and how the metadata is later rendered or used, may res CVSSv3.1 9.6 (CRITICAL)

CWECWE 20VNDSpringTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
3w ago
2026-08-27 10:16Z
CRIT

CVE-2026-32566 — Privilege: Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <=

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32566

Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 266TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
3w ago
2026-08-27 10:16Z
HIGH

CVE-2026-32564 — Subscriber: SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <=

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32564

Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
3w ago
2026-08-27 10:16Z
HIGH

CVE-2026-32550 — Subscriber: SQL Injection in Kadence Shop Kit <= 3.0.6 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32550

Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
3w ago
2026-08-27 10:16Z
CRIT

CVE-2026-32479 — SQL: Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32479

Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
3w ago
2026-08-27 10:16Z
HIGH

CVE-2026-27330 — Broken: Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-27330

Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions. CVSSv3.1 8.6 (HIGH)

CWECWE 862VNDBrokenTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
3w ago
2026-08-27 06:17Z
HIGH

CVE-2026-78333 — Step: The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78333

The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticated users before storing it in its activity log and outputting it back in an admin area page, leading to a Stored Cross-Site Scripting issue which could be used against high privilege users such as admin. CVSSv3.1 8.8 (HIGH)

CWECWE 79TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-27 06:17Z
HIGH

CVE-2026-77018 — Workeera: The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77018

The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor validate the type of the file it subsequently writes into a publicly reachable directory, allowing users with a role as low as subscriber to upload arbitrary files and achieve remote code execution. CVSSv3.1 8.8 (HIGH)

CWECWE 434VNDWorkeeraTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-27 06:17Z
CRIT

CVE-2026-77016 — Workeera: The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77016

The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own candidate profile, and does not validate or contain the stored file path before deleting it, allowing users with a role as low as subscriber to delete arbitrary files on the server. CVSSv3.1 9.6 (CRITICAL)

CWECWE 73VNDWorkeeraTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
3w ago
2026-08-27 06:17Z
CRIT

CVE-2026-59270 — Spring: Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59270

Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18 Spring Security 5.8.0 - 5.8.27 Spring Security 5.7.0 - 5.7.25 CVSSv3.1 9.4 (CRITICAL)

VNDSpringTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
3w ago
2026-08-27 06:17Z
CRIT

CVE-2026-47892 — WebFlux: A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47892

A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.5.RELEASE - 5.2.25.RELEASE CVSSv3.1 9.8 (CRITICAL) · EPSS 9th percentile

CWECWE 863VNDWebfluxTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-27 06:17Z
CRIT

CVE-2026-47891 — Spring: A Spring WebFlux application that relies on the Aalto XML processor to parse XML

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47891

A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier CVSSv3.1 9.8 (CRITICAL)

CWECWE 770VNDSpringTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-27 06:17Z
CRIT

CVE-2026-47890 — Spring: MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47890

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 CVSSv3.1 9.8 (CRITICAL)

CWECWE 93VNDSpringTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-27 06:17Z
CRIT

CVE-2026-47884 — Use: of XsltView in a Spring MVC application can result in SSRF and RCE

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47884

Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier CVSSv3.1 9.8 (CRITICAL)

CWECWE 22TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-27 06:17Z
HIGH

CVE-2026-47877 — Spring: Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47877

Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 CVSSv3.1 8.2 (HIGH)

VNDSpringTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
3w ago
2026-08-26 23:17Z
CRIT

CVE-2026-75340 — The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is vulnerable to Server-side

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75340

The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is vulnerable to Server-side request forgery (SSRF). CVSSv3.1 9.1 (CRITICAL)

CWECWE 918TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3w ago
2026-08-26 23:17Z
CRIT

CVE-2026-75338 — Distributed: disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75338

disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. The config-fetching APIs /api/config/item, /api/config/file, /api/config/list and /api/config/simple/list are exposed without authentication. The LoginInterceptor explicitly whitelists these four paths, so any anonymous attacker can read every configuration item and configuration file managed by the config center. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284VNDDistributedTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 23:17Z
CRIT

CVE-2026-75336 — Funiture: 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select.json and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75336

Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select.json and /sys/tool/update.json. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDFunitureTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 23:17Z
CRIT

CVE-2026-75332 — Zyplayer: Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download().

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75332

Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download(). CVSSv3.1 9.1 (CRITICAL)

CWECWE 918VNDZyplayerTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3w ago
2026-08-26 23:17Z
CRIT

CVE-2026-75330 — The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerable to SQL injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75330

The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerable to SQL injection. The module parameter is directly concatenated into the SQL IN clause through StringUtils.split() and string concatenation without being parameterized and bound. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score