2026-06-26
2026-06-26 15:16Z
HIGH

CVE-2026-57527 — Zed: Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57527

Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability that allows attackers who control a proxied web server to achieve arbitrary code execution by embedding a malicious serialized Java object in the javax.faces.ViewState HTTP response parameter. The JSFViewState.decode() method base64-decodes the ViewState value and passes it directly to ObjectInputStream.readObject() without a deserialization filter, allowlist, or type r CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDZedTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-26
2026-06-26 15:16Z
HIGH

CVE-2026-57315 — Contributor: Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.45 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57315

Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.45 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 94VNDContributorTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-26
2026-06-26 15:16Z
HIGH

CVE-2026-56773 — REST: Teable's v2 REST API controller lacks @Permissions metadata on ORPC endpoints, allowing any authenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56773

Teable's v2 REST API controller lacks @Permissions metadata on ORPC endpoints, allowing any authenticated user to bypass authorization checks. Attackers can read table schemas, create tables, and modify or delete records across bases and tables via endpoints like GET /api/v2/tables/get and POST /api/v2/tables/updateRecords. CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDRestTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-26
2026-06-26 15:16Z
CRIT

CVE-2026-56070 — SQL: Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56070

Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-26
2026-06-26 15:16Z
CRIT

CVE-2026-56068 — SQL: Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56068

Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-26
2026-06-26 15:16Z
CRIT

CVE-2026-56067 — SQL: Unauthenticated SQL Injection in JetSmartFilters <= 3.8.3 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56067

Unauthenticated SQL Injection in JetSmartFilters <= 3.8.3 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-26
2026-06-26 15:16Z
HIGH

CVE-2026-56064 — Subscriber: SQL Injection in Tourfic <= 2.22.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56064

Subscriber SQL Injection in Tourfic <= 2.22.5 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-26
2026-06-26 15:16Z
HIGH

CVE-2026-56063 — Broken: Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56063

Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions. CVSSv3.1 8.3 (HIGH)

CWECWE 862VNDBrokenTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-26
2026-06-26 15:16Z
CRIT

CVE-2026-56062 — SQL: Unauthenticated SQL Injection in Quotes llama <= 3.1.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56062

Unauthenticated SQL Injection in Quotes llama <= 3.1.5 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-26
2026-06-26 15:16Z
CRIT

CVE-2026-56059 — Subscriber: Arbitrary File Upload in Travel Booking <= 2.2.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56059

Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions. CVSSv3.1 9.9 (CRITICAL)

CWECWE 434VNDSubscriberTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-26
2026-06-26 15:16Z
CRIT

CVE-2026-56058 — Subscriber: Arbitrary File Upload in Quform <= 2.23.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56058

Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions. CVSSv3.1 9.9 (CRITICAL)

CWECWE 434VNDSubscriberTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-26
2026-06-26 15:16Z
CRIT

CVE-2026-56057 — Subscriber: PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56057

Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502VNDSubscriberTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-26
2026-06-26 15:16Z
HIGH

CVE-2026-56055 — Subscriber: PHP Object Injection in RealHomes <= 4.5.3 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56055

Subscriber PHP Object Injection in RealHomes <= 4.5.3 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDSubscriberTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-26
2026-06-26 15:16Z
HIGH

CVE-2026-56038 — Contributor: Privilege Escalation in Frisbii Pay <= 1.8.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56038

Contributor Privilege Escalation in Frisbii Pay <= 1.8.2 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDContributorTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-26
2026-06-26 15:16Z
CRIT

CVE-2026-56036 — SQL: Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56036

Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-26
2026-06-26 15:16Z
HIGH

CVE-2026-56035 — Vulnerabilities: Unauthenticated Multiple Vulnerabilities in BitFire Security <= 5.0.3 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56035

Unauthenticated Multiple Vulnerabilities in BitFire Security <= 5.0.3 versions. CVSSv3.1 8.6 (HIGH)

CWECWE 1284VNDVulnerabilitiesTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-26
2026-06-26 15:16Z
CRIT

CVE-2026-56034 — SQL: Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56034

Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-26
2026-06-26 15:16Z
CRIT

CVE-2026-56033 — Privilege: Unauthenticated Privilege Escalation in Dokan Pro <= 5.0.4 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56033

Unauthenticated Privilege Escalation in Dokan Pro <= 5.0.4 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 266TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-26
2026-06-26 15:16Z
CRIT

CVE-2026-56032 — Subscriber: PHP Object Injection in Buddyboss Platform <= 3.0.4 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56032

Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502VNDSubscriberTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-26
2026-06-26 15:16Z
HIGH

CVE-2026-56031 — PHP: Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56031

Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-26
2026-06-26 15:16Z
CRIT

CVE-2026-56030 — Privilege: Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56030

Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 266TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-26
2026-06-26 15:16Z
CRIT

CVE-2026-56028 — Privilege: Unauthenticated Privilege Escalation in Easy Elements for Elementor &#8211; Addons &amp; Website Templates <=

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56028

Unauthenticated Privilege Escalation in Easy Elements for Elementor &#8211; Addons &amp; Website Templates <= 1.4.9 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 266TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-26
2026-06-26 15:16Z
CRIT

CVE-2026-56027 — Customer: Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56027

Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions. CVSSv3.1 9.9 (CRITICAL)

CWECWE 434VNDCustomerTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-26
2026-06-26 15:16Z
HIGH

CVE-2026-56010 — Subscriber: Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56010

Subscriber Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 266VNDSubscriberTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-26
2026-06-26 15:16Z
HIGH

CVE-2026-56008 — Contributor: Privilege Escalation in Fusion Builder <= 3.15.4 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56008

Contributor Privilege Escalation in Fusion Builder <= 3.15.4 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 266VNDContributorTYPVulnerability
8.8
CVSS v3.1
94
Edit Score