CVE-2026-96815
Custom role Privilege Escalation in Vitepos <= 3.5.0 versions.
Busca em todas as edições
Agregado automaticamente, sem curadoria humana, a partir de fontes públicas: CISA KEV, NVD, EQSTLab e VEXDay. Cada alerta leva à sua fonte oficial.
1496 alertas em todas as edições, exibindo 391–420.
CVE-2026-96815
Custom role Privilege Escalation in Vitepos <= 3.5.0 versions.
CVE-2026-96344
Custom role PHP Object Injection in eCommerce Product Catalog <= 3.6.0 versions.
CVE-2026-96343
Custom role PHP Object Injection in WP ERP <= 1.17.9 versions.
CVE-2026-94677
Shop manager PHP Object Injection in Kadence WooCommerce Email Designer <= 1.5.19.1 versions.
CVE-2026-94122
Editor PHP Object Injection in Responsive Slider Gallery <= 1.5.5 versions.
CVE-2026-93771
Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions.
CVE-2026-93651
Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions.
CVE-2026-93624
Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions.
CVE-2026-97347
The Post Views Stats Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User-Agent Header in all versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...
CVE-2026-102454
EasyFlow .NET developed by Digiwin has an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
CVE-2026-96649
The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label DOM Sink) in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes...
CVE-2026-102109
A SQL injection vulnerability existed in Kiteworks Secure Data Forms, where a value derived from the authenticated user's stored account data was incorporated into a database query without proper sanitization. An authenticated user could potentially influence that value to inject SQL. Exploitation requires an...
CVE-2026-97290
Unauthenticated Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.36 versions.
CVE-2026-94171
Unauthenticated Cross Site Scripting (XSS) in CURCY <= 2.2.16 versions.
CVE-2026-102391
Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions.
CVE-2026-102376
Subscriber Cross Site Scripting (XSS) in Branda <= 3.4.32 versions.
CVE-2026-100510
Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid <= 1.27.14 versions.
CVE-2026-47602
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode driver where a local user can cause the driver to dereference an untrusted pointer. A successful exploit of this vulnerability might lead to denial of service and information disclosure.
CVE-2026-47554
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where improper verification of cryptographic signatures may cause signature verification to be bypassed under memory pressure. A successful exploit of this vulnerability might lead to denial of service and data tampering.
CVE-2026-97289
Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions.
CVE-2026-97272
Unauthenticated Cross Site Scripting (XSS) in Premmerce Permalink Manager for WooCommerce <= 2.3.13 versions.
CVE-2026-97271
Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions.
CVE-2026-97253
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kreatura LayerSlider allows Reflected XSS. This issue affects LayerSlider: from n/a through 8.4.0.
CVE-2026-97250
Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.
CVE-2026-97237
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions.
CVE-2026-97235
Unauthenticated Cross Site Scripting (XSS) in ThemeREX Addons < 2.45.0 versions.
CVE-2026-97077
Unauthenticated Cross Site Scripting (XSS) in Ad Inserter <= 2.8.18 versions.
CVE-2026-97065
Unauthenticated Cross Site Scripting (XSS) in Happyforms <= 1.26.15 versions.
CVE-2026-96836
Unauthenticated Cross Site Scripting (XSS) in Parsi Date <= 6.3 versions.
CVE-2026-96830
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.9 versions.