| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-59564 | Cri | 0.59 | 9.1 | 0.01 | Aug 24, 2026 | An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal. | ||
| CVE-2026-30512 | — | Hig | 0.51 | 7.8 | 0.00 | Aug 24, 2026 | A local privilege escalation vulnerability exists in the Restricted Access (Kiosk) Mode implementation of Scheidt & Bachmann entervo HMI prior to V2 R5 P0 M5. The vulnerability affects the external PDF viewer functionality used to display the application manual and its… | |
| CVE-2026-21751 | Hig | 0.48 | 7.4 | 0.00 | Aug 24, 2026 | HCL Hive is affected by a cryptographic primitive with a risky implementation which could allow an attacker unauthorized lateral compromise or widespread credential leakage if a single internal component is breached. | ||
| CVE-2026-17033 | Med | 0.44 | 6.8 | 0.00 | Aug 24, 2026 | An authenticated attacker with Editor access or alert.instances.external:write can submit an external Alertmanager alert containing a controlled generatorURL. The attacker is authorized to create the alert, but not to execute script in another user's Grafana session. Grafana… | ||
| CVE-2025-68833 | Med | 0.34 | 5.3 | 0.00 | Aug 24, 2026 | HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker unauthorized access to resources. | ||
| CVE-2026-78365 | Cri | 0.53 | — | 0.01 | Aug 24, 2026 | Authorization Bypass Through User-Controlled Key in the supplier API in Roskus Prospero Flow CRM 4.0.0 through 5.3.1 allows any authenticated user to read and modify another company's supplier record, and to reassign it to their own company, via a PUT request to… | ||
| CVE-2026-78247 | Hig | 0.47 | 7.3 | 0.00 | Aug 24, 2026 | A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=confirm_order. The manipulation of the argument ID results in sql injection. The attack can be executed remotely.… | ||
| CVE-2026-21759 | Med | 0.28 | 4.3 | 0.00 | Aug 24, 2026 | HCL Hive is affected by an information exposure vulnerability where Swagger documentation was found exposed publicly. Although no sensitive information (e.g., credentials, PII) was discovered, exposing API documentation to unauthenticated users can increase the overall attack… | ||
| CVE-2026-21756 | Hig | 0.47 | 7.2 | 0.00 | Aug 24, 2026 | HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unauthorized user to introduce unverified, malicious, or broken code directly into production environments. | ||
| CVE-2026-78323 | Med | 0.42 | 6.5 | 0.00 | Aug 24, 2026 | A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted as trust anchors for TLS connections. In… | ||
| CVE-2026-78291 | Med | 0.34 | 5.3 | 0.00 | Aug 24, 2026 | Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 versions. | ||
| CVE-2026-78290 | Med | 0.42 | 6.5 | 0.00 | Aug 24, 2026 | Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions. | ||
| CVE-2026-78280 | Med | 0.28 | 4.3 | 0.00 | Aug 24, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Hash Form <= 1.4.0 versions. | ||
| CVE-2026-78279 | Med | 0.35 | 5.4 | 0.00 | Aug 24, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Fluent Support Pro <= 2.3.1 versions. | ||
| CVE-2026-78278 | Med | 0.34 | 5.3 | 0.00 | Aug 24, 2026 | Subscriber Insecure Direct Object References (IDOR) in Fluent Boards Pro <= 2.0.11 versions. | ||
| CVE-2026-78277 | Med | 0.32 | 4.9 | 0.00 | Aug 24, 2026 | Subscriber Server Side Request Forgery (SSRF) in FluentCRM Pro <= 3.1.12 versions. | ||
| CVE-2026-78272 | Med | 0.35 | 5.4 | 0.00 | Aug 24, 2026 | Subscriber Broken Access Control in Fluent Support Pro <= 2.3.1 versions. | ||
| CVE-2026-78270 | Hig | 0.49 | 7.6 | 0.00 | Aug 24, 2026 | Author SQL Injection in FluentCRM Pro <= 3.1.12 versions. | ||
| CVE-2026-78269 | Med | 0.35 | 6.4 | 0.00 | Aug 24, 2026 | Contributor Server Side Request Forgery (SSRF) in Shared Files <= 1.7.69 versions. | ||
| CVE-2026-78258 | Med | 0.34 | 5.3 | 0.00 | Aug 24, 2026 | Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.5 versions. | ||
| CVE-2026-78246 | Hig | 0.47 | 7.3 | 0.00 | Aug 24, 2026 | A vulnerability has been found in itsourcecode Online Clinic Management System 1.0. This vulnerability affects unknown code of the file success/login.php of the component Admin Login. The manipulation of the argument Username leads to sql injection. Remote exploitation of the… | ||
| CVE-2026-6017 | Hig | 0.46 | — | 0.00 | Aug 24, 2026 | Firmware in KAON PG5298A and PG5298B routers allow an unauthenticated user to query a specific endpoint and acquire sensitive information such as a password to the administrative portal. This vulnerability has been fixed in firmware version: 3.0.82 for PG5298A and 4.0.82… | ||
| CVE-2026-66671 | Hig | 0.53 | 8.1 | 0.00 | Aug 24, 2026 | Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions. | ||
| CVE-2026-66670 | Hig | 0.53 | 8.1 | 0.00 | Aug 24, 2026 | Unauthenticated Local File Inclusion in Måne <= 1.7 versions. | ||
| CVE-2026-66650 | Cri | 0.64 | 9.8 | 0.01 | Aug 24, 2026 | Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions. | ||
| CVE-2026-66648 | Cri | 0.64 | 9.8 | 0.00 | Aug 24, 2026 | Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions. | ||
| CVE-2026-66623 | Hig | 0.46 | 7.1 | 0.00 | Aug 24, 2026 | Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions. | ||
| CVE-2026-66610 | Hig | 0.46 | 7.1 | 0.00 | Aug 24, 2026 | Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions. | ||
| CVE-2026-66599 | Hig | 0.46 | 7.1 | 0.00 | Aug 24, 2026 | Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 2.9.5.6 versions. | ||
| CVE-2026-66587 | Cri | 0.64 | 9.8 | 0.01 | Aug 24, 2026 | Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions. | ||
| CVE-2026-66585 | Hig | 0.49 | 7.5 | 0.00 | Aug 24, 2026 | Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions. | ||
| CVE-2026-66584 | Hig | 0.46 | 7.1 | 0.00 | Aug 24, 2026 | Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions. | ||
| CVE-2026-32558 | Cri | 0.64 | 9.8 | 0.00 | Aug 24, 2026 | Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions. | ||
| CVE-2026-32551 | Cri | 0.60 | 9.3 | 0.00 | Aug 24, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DiviNext Woo Essential allows SQL Injection. This issue affects Woo Essential: from n/a through 4.3.0. | ||
| CVE-2026-32478 | Hig | 0.55 | 8.5 | 0.00 | Aug 24, 2026 | Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions. | ||
| CVE-2026-32477 | Hig | 0.56 | 8.6 | 0.01 | Aug 24, 2026 | Unauthenticated Arbitrary File Deletion in ShopBuilder Pro – Elementor WooCommerce Builder Addons <= 2.2.0 versions. | ||
| CVE-2026-32476 | Hig | 0.46 | 7.1 | 0.00 | Aug 24, 2026 | Unauthenticated Cross Site Scripting (XSS) in Brave Conversion Engine (PRO) <= 0.8.6 versions. | ||
| CVE-2026-32471 | Hig | 0.55 | 8.5 | 0.00 | Aug 24, 2026 | Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions. | ||
| CVE-2026-28190 | Hig | 0.46 | 7.1 | 0.00 | Aug 24, 2026 | Subscriber Broken Access Control in ProLancer Element <= 1.4.8 versions. | ||
| CVE-2026-28171 | Hig | 0.56 | 8.6 | 0.01 | Aug 24, 2026 | Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions. | ||
| CVE-2026-28167 | Hig | 0.49 | 7.5 | 0.01 | Aug 24, 2026 | Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions. | ||
| CVE-2026-28166 | Hig | 0.46 | 7.1 | 0.00 | Aug 24, 2026 | Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions. | ||
| CVE-2026-28165 | Cri | 0.64 | 9.8 | 0.00 | Aug 24, 2026 | Unauthenticated Privilege Escalation in Digits <= 9.2 versions. | ||
| CVE-2026-28162 | Hig | 0.46 | 7.1 | 0.00 | Aug 24, 2026 | Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions. | ||
| CVE-2026-28153 | Hig | 0.49 | 7.5 | 0.00 | Aug 24, 2026 | Unauthenticated Broken Access Control in Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More <= 1.7.1 versions. | ||
| CVE-2026-28152 | Hig | 0.53 | 8.1 | 0.00 | Aug 24, 2026 | Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions. | ||
| CVE-2026-28151 | Hig | 0.53 | 8.1 | 0.00 | Aug 24, 2026 | Unauthenticated Local File Inclusion in Tonda < 2.6 versions. | ||
| CVE-2025-63080 | Hig | 0.55 | — | 0.00 | Aug 24, 2026 | Firmware in KAON PG5298A and PG5298B routers allow an authenticated user to send crafted JSON-RPC requests and perform operations not possible via GUI, e.g. system file read or command execution. This vulnerability has been fixed in firmware version: 3.0.82 for PG5298A and… | ||
| CVE-2026-78337 | Med | 0.24 | — | 0.00 | Aug 24, 2026 | Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow CRM before 5.15.13 allows an authenticated user holding the create company and update company permissions to execute arbitrary JavaScript in the application origin via an SVG… | ||
| CVE-2026-78245 | Hig | 0.47 | 7.3 | 0.01 | Aug 24, 2026 | A flaw has been found in itsourcecode Online Pharmacy System 1.0. This affects the function move_uploaded_file of the file all_users/register.php of the component User Registration. Executing a manipulation of the argument photo can lead to unrestricted upload. The attack may be… |
- risk 0.59cvss 9.1epss 0.01
An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal.
- risk 0.51cvss 7.8epss 0.00
A local privilege escalation vulnerability exists in the Restricted Access (Kiosk) Mode implementation of Scheidt & Bachmann entervo HMI prior to V2 R5 P0 M5. The vulnerability affects the external PDF viewer functionality used to display the application manual and its…
- risk 0.48cvss 7.4epss 0.00
HCL Hive is affected by a cryptographic primitive with a risky implementation which could allow an attacker unauthorized lateral compromise or widespread credential leakage if a single internal component is breached.
- risk 0.44cvss 6.8epss 0.00
An authenticated attacker with Editor access or alert.instances.external:write can submit an external Alertmanager alert containing a controlled generatorURL. The attacker is authorized to create the alert, but not to execute script in another user's Grafana session. Grafana…
- risk 0.34cvss 5.3epss 0.00
HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker unauthorized access to resources.
- risk 0.53cvss —epss 0.01
Authorization Bypass Through User-Controlled Key in the supplier API in Roskus Prospero Flow CRM 4.0.0 through 5.3.1 allows any authenticated user to read and modify another company's supplier record, and to reassign it to their own company, via a PUT request to…
- risk 0.47cvss 7.3epss 0.00
A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=confirm_order. The manipulation of the argument ID results in sql injection. The attack can be executed remotely.…
- risk 0.28cvss 4.3epss 0.00
HCL Hive is affected by an information exposure vulnerability where Swagger documentation was found exposed publicly. Although no sensitive information (e.g., credentials, PII) was discovered, exposing API documentation to unauthenticated users can increase the overall attack…
- risk 0.47cvss 7.2epss 0.00
HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unauthorized user to introduce unverified, malicious, or broken code directly into production environments.
- risk 0.42cvss 6.5epss 0.00
A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted as trust anchors for TLS connections. In…
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 versions.
- risk 0.42cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions.
- risk 0.28cvss 4.3epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in Hash Form <= 1.4.0 versions.
- risk 0.35cvss 5.4epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in Fluent Support Pro <= 2.3.1 versions.
- risk 0.34cvss 5.3epss 0.00
Subscriber Insecure Direct Object References (IDOR) in Fluent Boards Pro <= 2.0.11 versions.
- risk 0.32cvss 4.9epss 0.00
Subscriber Server Side Request Forgery (SSRF) in FluentCRM Pro <= 3.1.12 versions.
- risk 0.35cvss 5.4epss 0.00
Subscriber Broken Access Control in Fluent Support Pro <= 2.3.1 versions.
- risk 0.49cvss 7.6epss 0.00
Author SQL Injection in FluentCRM Pro <= 3.1.12 versions.
- risk 0.35cvss 6.4epss 0.00
Contributor Server Side Request Forgery (SSRF) in Shared Files <= 1.7.69 versions.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.5 versions.
- risk 0.47cvss 7.3epss 0.00
A vulnerability has been found in itsourcecode Online Clinic Management System 1.0. This vulnerability affects unknown code of the file success/login.php of the component Admin Login. The manipulation of the argument Username leads to sql injection. Remote exploitation of the…
- risk 0.46cvss —epss 0.00
Firmware in KAON PG5298A and PG5298B routers allow an unauthenticated user to query a specific endpoint and acquire sensitive information such as a password to the administrative portal. This vulnerability has been fixed in firmware version: 3.0.82 for PG5298A and 4.0.82…
- risk 0.53cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Måne <= 1.7 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 2.9.5.6 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions.
- risk 0.60cvss 9.3epss 0.00
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DiviNext Woo Essential allows SQL Injection. This issue affects Woo Essential: from n/a through 4.3.0.
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions.
- risk 0.56cvss 8.6epss 0.01
Unauthenticated Arbitrary File Deletion in ShopBuilder Pro – Elementor WooCommerce Builder Addons <= 2.2.0 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Brave Conversion Engine (PRO) <= 0.8.6 versions.
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions.
- risk 0.46cvss 7.1epss 0.00
Subscriber Broken Access Control in ProLancer Element <= 1.4.8 versions.
- risk 0.56cvss 8.6epss 0.01
Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions.
- risk 0.49cvss 7.5epss 0.01
Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in Digits <= 9.2 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More <= 1.7.1 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Tonda < 2.6 versions.
- risk 0.55cvss —epss 0.00
Firmware in KAON PG5298A and PG5298B routers allow an authenticated user to send crafted JSON-RPC requests and perform operations not possible via GUI, e.g. system file read or command execution. This vulnerability has been fixed in firmware version: 3.0.82 for PG5298A and…
- risk 0.24cvss —epss 0.00
Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow CRM before 5.15.13 allows an authenticated user holding the create company and update company permissions to execute arbitrary JavaScript in the application origin via an SVG…
- risk 0.47cvss 7.3epss 0.01
A flaw has been found in itsourcecode Online Pharmacy System 1.0. This affects the function move_uploaded_file of the file all_users/register.php of the component User Registration. Executing a manipulation of the argument photo can lead to unrestricted upload. The attack may be…