2026-08-06
2026-08-06 15:17Z
CRIT

CVE-2026-66447 — SQL: Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66447

Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-06
2026-08-06 15:17Z
CRIT

CVE-2026-65581 — PHP: Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65581

Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 15:17Z
CRIT

CVE-2026-65579 — PHP: Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65579

Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 15:17Z
CRIT

CVE-2026-65578 — PHP: Unauthenticated PHP Object Injection in Agora <= 1.9 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65578

Unauthenticated PHP Object Injection in Agora <= 1.9 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 15:17Z
CRIT

CVE-2026-65577 — PHP: Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65577

Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 15:17Z
CRIT

CVE-2026-65576 — PHP: Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65576

Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 15:17Z
CRIT

CVE-2026-65575 — PHP: Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65575

Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-06
2026-08-06 15:17Z
CRIT

CVE-2026-65574 — PHP: Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65574

Unauthenticated PHP Object Injection in Abogado <= 1.18 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 15:17Z
CRIT

CVE-2026-65573 — PHP: Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65573

Unauthenticated PHP Object Injection in Abelle <= 1.22 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 15:17Z
CRIT

CVE-2026-65572 — PHP: Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65572

Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 15:17Z
CRIT

CVE-2026-65571 — PHP: Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65571

Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 15:17Z
HIGH

CVE-2026-65570 — Bypass: Unauthenticated Bypass Vulnerability in Login with phone number <= 1.8.70 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65570

Unauthenticated Bypass Vulnerability in Login with phone number <= 1.8.70 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 290VNDBypassTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-06
2026-08-06 15:17Z
HIGH

CVE-2026-65569 — Subscriber: SQL Injection in WP Job Portal <= 2.5.6 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65569

Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-06
2026-08-06 15:17Z
CRIT

CVE-2026-65556 — PHP: Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65556

Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 15:17Z
CRIT

CVE-2026-65553 — Code: Unauthenticated Remote Code Execution (RCE) in Spider Analyser &#8211; WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65553

Unauthenticated Remote Code Execution (RCE) in Spider Analyser &#8211; WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions. CVSSv3.1 10.0 (CRITICAL)

CWECWE 94VNDCodeTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-06
2026-08-06 15:17Z
CRIT

CVE-2026-65552 — Subscriber: PHP Object Injection in Export User Data <= 2.2.6 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65552

Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502VNDSubscriberTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 15:17Z
CRIT

CVE-2026-65548 — Contributor: Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65548

Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions. CVSSv3.1 9.9 (CRITICAL)

CWECWE 94VNDContributorTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-06
2026-08-06 15:17Z
HIGH

CVE-2026-65547 — Subscriber: SQL Injection in Creative Mail <= 1.6.9 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65547

Subscriber SQL Injection in Creative Mail <= 1.6.9 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-06
2026-08-06 15:17Z
CRIT

CVE-2026-65546 — SQL: Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65546

Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-06
2026-08-06 15:17Z
HIGH

CVE-2026-65542 — Broken: Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65542

Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 288VNDBrokenTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-06
2026-08-06 15:17Z
CRIT

CVE-2026-65520 — SQL: Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65520

Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-06
2026-08-06 15:17Z
CRIT

CVE-2026-65508 — SQL: Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65508

Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-06
2026-08-06 15:17Z
CRIT

CVE-2026-65507 — Privilege: Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65507

Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 266TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 15:16Z
CRIT

CVE-2026-54489 — Dell: Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54489

Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered critical as it allows an unauthenticated attacker to obtain active session credentials and fully impersonate authenticated users, including administrators. Dell CVSSv3.1 9.1 (CRITICAL)

CWECWE 200VNDDellTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-06
2026-08-06 15:16Z
CRIT

CVE-2026-53976 — OpenChamber: 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53976

OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query parameter alongside an absolute path, bypassing the workspace boundary check in resolveReadPathFromContext. Attackers can exploit the vacuous isPathWithinRoot guard to read sensitive files such as the JWT signing secret, SSH pri CVSSv3.1 9.1 (CRITICAL)

CWECWE 22VNDOpenchamberTYPVulnerability
9.1
CVSS v3.1
96
Edit Score