| CVE-2026-81298 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in LeadConnector <= 4.0.5 versions.… | 2026-08-31 |
| CVE-2026-81756 | CRITICAL | 9.3 | Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions.… | 2026-08-31 |
| CVE-2026-81758 | MEDIUM | 6.3 | Subscriber Broken Access Control in OwnerRez API <= 1.2.6 versions.… | 2026-08-31 |
| CVE-2026-81762 | MEDIUM | 6.5 | Subscriber Broken Access Control in Booking and Rental Manager <= 2.7.6 versions.… | 2026-08-31 |
| CVE-2026-81763 | CRITICAL | 9.3 | Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.… | 2026-08-31 |
| CVE-2026-81764 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0.6 versions.… | 2026-08-31 |
| CVE-2026-81765 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 versions.… | 2026-08-31 |
| CVE-2026-81768 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions.… | 2026-08-31 |
| CVE-2026-81778 | MEDIUM | 6.5 | Subscriber Cross Site Scripting (XSS) in Kalles Addons <= 1.0.6 versions.… | 2026-08-31 |
| CVE-2026-81779 | CRITICAL | 10.0 | Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious … | 2026-08-31 |
| CVE-2026-81780 | CRITICAL | 10.0 | Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.… | 2026-08-31 |
| CVE-2026-81887 | NA | N/A | Livewire is a full-stack framework for Laravel. From 3.0.0-beta.1 until 3.8.3 and 4.3.4, the dot-notated query… | 2026-08-31 |
| CVE-2026-81888 | MEDIUM | 5.4 | @hono/oauth-providers is Authentication middleware for Hono. Prior to version 0.8.6, the built-in social login… | 2026-08-31 |
| CVE-2026-81889 | HIGH | 8.6 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, elFin… | 2026-08-31 |
| CVE-2026-81890 | MEDIUM | 5.4 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, the n… | 2026-08-31 |
| CVE-2026-81891 | HIGH | 8.1 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, check… | 2026-08-31 |
| CVE-2026-81892 | HIGH | 8.1 | EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 and 5.5.1, E… | 2026-08-31 |
| CVE-2026-82221 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions.… | 2026-08-31 |
| CVE-2026-82224 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in SliceWP <= 1.2.10 versions.… | 2026-08-31 |
| CVE-2026-82225 | HIGH | 7.4 | Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions.… | 2026-08-31 |
| CVE-2026-82226 | CRITICAL | 9.8 | Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.… | 2026-08-31 |
| CVE-2026-82228 | HIGH | 8.1 | Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions.… | 2026-08-31 |
| CVE-2026-82229 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions.… | 2026-08-31 |
| CVE-2026-82346 | NA | N/A | A potential security vulnerability has been identified in the HP ImageDiags for versions prior to 5.0.0.36. Th… | 2026-08-31 |
| CVE-2026-82392 | HIGH | 7.1 | pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11.0, pnpm parses the package name from a… | 2026-08-31 |
| CVE-2026-82852 | MEDIUM | 5.4 | Unauthenticated Server Side Request Forgery (SSRF) in MapSVG <= 8.15.0 versions.… | 2026-08-31 |
| CVE-2026-82906 | LOW | 3.7 | A flaw has been found in sdcb chats up to 1.12.0. This impacts the function DownloadPublic of the file src/BE/… | 2026-08-31 |
| CVE-2026-82908 | HIGH | 8.8 | A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affected by this vulnerability is the function… | 2026-08-31 |
| CVE-2026-82909 | MEDIUM | 4.3 | A vulnerability was determined in QuantumNous new-api up to 1.0.0-rc.15. Affected by this issue is some unknow… | 2026-08-31 |
| CVE-2026-82914 | HIGH | 7.3 | A security flaw has been discovered in kishan0725 Hospital-Management-System 1.0. This vulnerability affects u… | 2026-08-31 |
| CVE-2026-82919 | HIGH | 7.3 | A vulnerability was identified in cu silicon up to 0.1.5. Affected by this vulnerability is the function creat… | 2026-08-31 |
| CVE-2026-83596 | HIGH | 8.8 | A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper me… | 2026-08-31 |
| CVE-2026-77348 | HIGH | 8.2 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the fix for CVE… | 2026-08-31 |
| CVE-2026-77351 | LOW | 3.5 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos lets any… | 2026-08-31 |
| CVE-2026-77352 | MEDIUM | 4.3 | Wallos is an open-source, self-hostable personal subscription tracker. From version 2.0.0 to before version 5.… | 2026-08-31 |
| CVE-2026-77353 | MEDIUM | 4.6 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos allows a… | 2026-08-31 |
| CVE-2026-82393 | HIGH | 7.5 | pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dep… | 2026-08-31 |
| CVE-2026-82394 | NA | N/A | Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 … | 2026-08-31 |
| CVE-2026-82395 | NA | N/A | Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 … | 2026-08-31 |
| CVE-2026-82396 | MEDIUM | 5.4 | Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 … | 2026-08-31 |
| CVE-2026-82397 | HIGH | 7.5 | Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses applicat… | 2026-08-31 |
| CVE-2026-82398 | NA | N/A | pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that cau… | 2026-08-31 |
| CVE-2026-82882 | HIGH | 8.8 | Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoin… | 2026-08-31 |
| CVE-2026-82921 | HIGH | 7.3 | A weakness has been identified in ShopEx ECShop up to 2.5.1. This affects the function check_img_type of the f… | 2026-08-31 |
| CVE-2026-82922 | HIGH | 7.3 | A security vulnerability has been detected in ShopEx ECShop up to 2.5.1. This vulnerability affects the functi… | 2026-08-31 |
| CVE-2026-82954 | CRITICAL | 9.9 | A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath… | 2026-08-31 |
| CVE-2026-82957 | HIGH | 7.3 | A vulnerability was found in hyperledger-firefly firefly up to 1.4.0. The impacted element is the function Val… | 2026-08-31 |
| CVE-2026-4560 | NA | N/A | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. No… | 2026-08-31 |
| CVE-2026-82971 | CRITICAL | 10.0 | A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the f… | 2026-08-31 |
| CVE-2026-83524 | CRITICAL | 9.9 | A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-2… | 2026-08-31 |