2026-07-13
2026-07-13 10:16Z
CRIT

CVE-2026-57739 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57739

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Blind SQL Injection.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.0. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-13
2026-07-13 10:16Z
CRIT

CVE-2026-57738 — Deserialization: of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57738

Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1.13.0. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-13
2026-07-13 10:16Z
CRIT

CVE-2026-57726 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57726

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Kirki kirki allows Blind SQL Injection.This issue affects Kirki: from n/a through <= 6.0.12. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-13
2026-07-13 10:16Z
CRIT

CVE-2026-57724 — Deserialization: of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57724

Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-13
2026-07-13 10:16Z
CRIT

CVE-2026-57719 — Upload: Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57719

Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Malicious Files.This issue affects Aimogen Pro: from n/a through <= 2.8.3. CVSSv3.1 10.0 (CRITICAL)

CWECWE 434TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-13
2026-07-13 10:16Z
CRIT

CVE-2026-57714 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57714

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LatePoint LatePoint latepoint allows Blind SQL Injection.This issue affects LatePoint: from n/a through <= 5.6.3. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-13
2026-07-13 10:16Z
HIGH

CVE-2026-57713 — Deserialization: of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Object

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57713

Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Object Injection.This issue affects Events Manager: from n/a through <= 7.3.6. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-13
2026-07-13 10:16Z
CRIT

CVE-2026-57710 — Upload: Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57710

Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Using Malicious Files.This issue affects WoowBot Pro Max: from n/a through <= 14.1.7. CVSSv3.1 9.9 (CRITICAL)

CWECWE 434TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-13
2026-07-13 10:16Z
HIGH

CVE-2026-57709 — Limitation: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57709

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Path Traversal.This issue affects Membership For WooCommerce: from n/a through <= 3.1.0. CVSSv3.1 8.6 (HIGH)

CWECWE 22TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-13
2026-07-13 10:16Z
CRIT

CVE-2026-57707 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57707

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows SQL Injection.This issue affects Simple Business Directory Pro: from n/a through <= 15.9.4. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-13
2026-07-13 10:16Z
CRIT

CVE-2026-57702 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57702

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Melograno Venture Studio Amelia ameliabooking allows Blind SQL Injection.This issue affects Amelia: from n/a through <= 2.4.2. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-13
2026-07-13 10:16Z
HIGH

CVE-2026-57410 — Incorrect: Privilege Assignment vulnerability in MailerPress Team MailerPress mailerpress allows Privilege Escalation.This issue affects

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57410

Incorrect Privilege Assignment vulnerability in MailerPress Team MailerPress mailerpress allows Privilege Escalation.This issue affects MailerPress: from n/a through <= 2.0.2. CVSSv3.1 8.8 (HIGH)

CWECWE 266TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-13
2026-07-13 10:16Z
CRIT

CVE-2026-57401 — Limitation: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57401

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force SureDash suredash allows Path Traversal.This issue affects SureDash: from n/a through <= 1.8.0. CVSSv3.1 9.9 (CRITICAL)

CWECWE 22TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-13
2026-07-13 10:16Z
HIGH

CVE-2026-57389 — Limitation: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Adrian

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57389

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Adrian Tobey Groundhogg groundhogg allows Path Traversal.This issue affects Groundhogg: from n/a through <= 4.4.1. CVSSv3.1 8.6 (HIGH)

CWECWE 22TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-13
2026-07-13 10:16Z
HIGH

CVE-2026-57386 — Incorrect: Privilege Assignment vulnerability in Kodezen LLC aBlocks ablocks allows Privilege Escalation.This issue affects

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57386

Incorrect Privilege Assignment vulnerability in Kodezen LLC aBlocks ablocks allows Privilege Escalation.This issue affects aBlocks: from n/a through < 2.9.1. CVSSv3.1 8.8 (HIGH)

CWECWE 266TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-13
2026-07-13 10:16Z
HIGH

CVE-2026-57385 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57385

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in appsbd Vitepos vitepos-lite allows Blind SQL Injection.This issue affects Vitepos: from n/a through <= 3.4.2. CVSSv3.1 8.5 (HIGH)

CWECWE 89TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-13
2026-07-13 10:16Z
HIGH

CVE-2026-57371 — Deserialization: of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object Injection.This issue

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57371

Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object Injection.This issue affects WPJAM Basic: from n/a through <= 7.0. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-13
2026-07-13 10:16Z
CRIT

CVE-2026-41041 — URL: path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41041

URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affects Apache Gravitino: from 1.0.0 before 1.2.1. Users are recommended to upgrade to version 1.2.1, which fixes the issue. CVSSv3.1 9.1 (CRITICAL)

CWECWE 177TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-13
2026-07-13 10:16Z
HIGH

CVE-2026-15548 — The manipulation leads to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15548

A security vulnerability has been detected in Shibby Tomato up to 1.28.0000. This vulnerability affects the function sub_407220 of the file /usr/sbin/httpd of the component DNS List Rendering. The manipulation leads to stack-based buffer overflow. The attack is possible to be carried out remotely. This project is superseded by FreshTomato. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-13
2026-07-13 09:16Z
HIGH

CVE-2026-15545 — Shibby: Such manipulation leads to out-of-bounds write.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15545

A vulnerability was identified in Shibby Tomato up to 1.28.0000. Affected by this vulnerability is the function main of the file www/apcupsd/tomatodata.cgi of the component apcupsd. Such manipulation leads to out-of-bounds write. The attack may be launched remotely. The exploit is publicly available and might be used. This project is superseded by FreshTomato. CVSSv3.1 8.8 (HIGH)

CWECWE 787CWECWE 119VNDShibbyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-13
2026-07-13 09:16Z
CRIT

CVE-2026-14453 — Server: This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14453

This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module that leads to Remote Code Execution. The message_confirm field is stored without sanitization and rendered via Smarty with no security policy enabled, allowing any authenticated user, to inject and execute arbitrary code on the server. This results in disclosure of environment secrets and could impact platform availability of Centreon Infra Monitoring product. CVSSv3.1 9.6 (CRITICAL)

CWECWE 94TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-13
2026-07-13 08:16Z
CRIT

CVE-2026-57830 — Ollyo Helix_ultimate: The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57830

The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion. CVSSv3.1 9.1 (CRITICAL) · EPSS 15th percentile

CWECWE 862VNDJoomlaVNDOllyoTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-13
2026-07-13 08:16Z
CRIT

CVE-2026-4769 — Certain: devices in the WAGO System I/O Field series activate an internal diagnostic capability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-4769

Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented and becomes accessible without authentication for a brief period in the early boot phase. During this window, an unauthenticated remote attacker can gain access to the internal system processes, resulting in full system compromise. CVSSv3.1 9.8 (CRITICAL)

CWECWE 912VNDCertainTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-13
2026-07-13 08:16Z
HIGH

CVE-2026-15544 — Shibby: This manipulation of the argument Field causes stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15544

A vulnerability was determined in Shibby Tomato up to 1.28.0000. Affected is the function getupsvar of the file www/apcupsd/tomatodata.cgi of the component apcupsd. This manipulation of the argument Field causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. This project is superseded by FreshTomato. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119VNDShibbyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-13
2026-07-13 08:16Z
HIGH

CVE-2026-15543 — Tenda: The manipulation of the argument Name results in buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15543

A vulnerability was found in Tenda CH22 1.0.0.1. This impacts the function formCertListInfo of the file /goform/CertListInfo. The manipulation of the argument Name results in buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used. CVSSv3.1 8.8 (HIGH)

CWECWE 120CWECWE 119VNDTendaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score