| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-65515 | Hig | 0.46 | 7.1 | 0.00 | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions. | ||
| CVE-2026-65513 | Hig | 0.46 | 7.1 | 0.00 | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions. | ||
| CVE-2026-65509 | Hig | 0.46 | 7.1 | 0.00 | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions. | ||
| CVE-2026-65508 | Cri | 0.60 | 9.3 | 0.00 | Aug 6, 2026 | Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions. | ||
| CVE-2026-65507 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions. | ||
| CVE-2026-65504 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2026 | Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions. | ||
| CVE-2026-65502 | Med | 0.34 | 5.3 | 0.00 | Aug 6, 2026 | Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions. | ||
| CVE-2026-61982 | Hig | 0.46 | 7.1 | 0.00 | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions. | ||
| CVE-2026-61964 | Hig | 0.46 | 7.1 | 0.00 | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions. | ||
| CVE-2026-61963 | Hig | 0.46 | 7.1 | 0.00 | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions. | ||
| CVE-2026-61961 | Hig | 0.46 | 7.1 | 0.00 | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions. | ||
| CVE-2026-61959 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2026 | Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions. | ||
| CVE-2026-54489 | Cri | 0.59 | 9.1 | 0.00 | Aug 6, 2026 | Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session… | ||
| CVE-2026-53976 | Cri | 0.59 | 9.1 | 0.02 | Aug 6, 2026 | OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query parameter alongside an… | ||
| CVE-2026-53975 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2026 | OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any… | ||
| CVE-2026-34502 | Hig | 0.49 | 7.5 | 0.01 | Aug 6, 2026 | Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3. | ||
| CVE-2026-34501 | Hig | 0.49 | 7.5 | 0.01 | Aug 6, 2026 | Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue. | ||
| CVE-2026-34191 | Cri | 0.59 | 9.1 | 0.00 | Aug 6, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3 | ||
| CVE-2026-32548 | Med | 0.34 | 5.3 | 0.00 | Aug 6, 2026 | Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions. | ||
| CVE-2026-32469 | Med | 0.34 | 5.3 | 0.00 | Aug 6, 2026 | Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions. | ||
| CVE-2026-32327 | Cri | 0.59 | 9.1 | 0.00 | Aug 6, 2026 | A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue. | ||
| CVE-2026-28183 | 0.00 | — | — | Aug 6, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |||
| CVE-2026-28180 | Med | 0.34 | 5.3 | 0.00 | Aug 6, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions. | ||
| CVE-2026-28179 | Med | 0.38 | 5.9 | 0.00 | Aug 6, 2026 | Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions. | ||
| CVE-2026-28178 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2026 | Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions. | ||
| CVE-2026-28177 | Hig | 0.46 | 7.1 | 0.00 | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions. | ||
| CVE-2026-28172 | Hig | 0.46 | 7.1 | 0.00 | Aug 6, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions. | ||
| CVE-2026-28169 | Med | 0.34 | 5.3 | 0.00 | Aug 6, 2026 | Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions. | ||
| CVE-2026-28146 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2026 | Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions. | ||
| CVE-2026-28143 | Hig | 0.46 | 7.1 | 0.00 | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions. | ||
| CVE-2026-28141 | Hig | 0.46 | 7.1 | 0.00 | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions. | ||
| CVE-2026-28140 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2026 | Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions. | ||
| CVE-2026-28139 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions. | ||
| CVE-2026-28111 | Hig | 0.57 | 8.8 | 0.00 | Aug 6, 2026 | Contributor Privilege Escalation in Forminator <= 1.56.0 versions. | ||
| CVE-2026-28082 | Hig | 0.46 | 7.1 | 0.00 | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions. | ||
| CVE-2026-28005 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions. | ||
| CVE-2026-25403 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2026 | Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. | ||
| CVE-2026-19045 | Med | 0.34 | 5.3 | 0.01 | Aug 6, 2026 | A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the function SecretDialog.showSecretDialog of the file src/utils/secretDialog.ts of the component get_credential_from_user. This manipulation of the argument Description causes command… | ||
| CVE-2026-19044 | Med | 0.35 | 5.3 | 0.01 | Aug 6, 2026 | A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of the file src/index.ts of the component create_scene/add_node. This manipulation of the argument projectPath causes command injection. The attack needs to be… | ||
| CVE-2026-15246 | Med | 0.28 | 4.3 | 0.00 | Aug 6, 2026 | The RealHomes Memberships WordPress plugin before 3.1.0 does not verify that a membership payment actually completed, nor check a nonce or the user's capability, before granting a paid membership package, allowing any authenticated user such as a Subscriber to obtain paid… | ||
| CVE-2025-49506 | Hig | 0.42 | 7.5 | 0.00 | Aug 6, 2026 | APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS,… | ||
| CVE-2026-64993 | Med | 0.44 | 6.8 | 0.00 | Aug 6, 2026 | Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated attacker could potentially exploit this vulnerability leading to loss of confidentiality and integrity. | ||
| CVE-2026-5134 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. CMS allows SQL Injection. This issue affects CMS: through 06082026. NOTE: The vendor was contacted early about this disclosure… | ||
| CVE-2026-19041 | Med | 0.34 | 6.3 | 0.01 | Aug 6, 2026 | A vulnerability has been found in MissionSquad mcp-api up to 1.11.8. The impacted element is the function this.packageService.installPackage of the file src/controllers/packages.ts of the component NPM Package Version Handler. The manipulation leads to command injection. It is… | ||
| CVE-2026-19040 | Med | 0.34 | 6.3 | 0.00 | Aug 6, 2026 | A flaw has been found in MissionSquad mcp-api up to 1.11.9. The affected element is an unknown function of the file src/services/dcrClients.ts. Executing a manipulation can lead to server-side request forgery. The attack may be performed from remote. Upgrading to version 1.11.10… | ||
| CVE-2026-18501 | Med | 0.42 | 6.4 | 0.00 | Aug 6, 2026 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Badge Widget Variable Substitution in all versions up to, and including, 1.2.69 due to insufficient input… | ||
| CVE-2026-16731 | Hig | 0.54 | — | 0.00 | Aug 6, 2026 | OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attacker to forge valid authentication credentials, bypass authentication and authorization, and… | ||
| CVE-2026-16316 | Med | 0.28 | 4.3 | 0.00 | Aug 6, 2026 | OMICRON StationGuard 4.00 contains an improper input validation vulnerability in its IEC 61850 Sampled Values (SV) frame processing. A specially crafted SV frame can cause the affected process to terminate, disrupting alert processing for Sampled Values traffic. The… | ||
| CVE-2026-16315 | Hig | 0.57 | 8.7 | 0.00 | Aug 6, 2026 | OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attacker to forge valid authentication credentials, bypass authentication and authorization, and… | ||
| CVE-2026-12605 | Cri | 0.62 | 9.6 | 0.00 | Aug 6, 2026 | In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until the… |
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.
- risk 0.42cvss 6.5epss 0.00
Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions.
- risk 0.59cvss 9.1epss 0.00
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session…
- risk 0.59cvss 9.1epss 0.02
OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query parameter alongside an…
- risk 0.64cvss 9.8epss 0.01
OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any…
- risk 0.49cvss 7.5epss 0.01
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3.
- risk 0.49cvss 7.5epss 0.01
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue.
- risk 0.59cvss 9.1epss 0.00
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.
- risk 0.59cvss 9.1epss 0.00
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
- CVE-2026-28183Aug 6, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.
- risk 0.38cvss 5.9epss 0.00
Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions.
- risk 0.42cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions.
- risk 0.42cvss 6.5epss 0.00
Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
- risk 0.57cvss 8.8epss 0.00
Contributor Privilege Escalation in Forminator <= 1.56.0 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
- risk 0.42cvss 6.5epss 0.00
Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
- risk 0.34cvss 5.3epss 0.01
A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the function SecretDialog.showSecretDialog of the file src/utils/secretDialog.ts of the component get_credential_from_user. This manipulation of the argument Description causes command…
- risk 0.35cvss 5.3epss 0.01
A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of the file src/index.ts of the component create_scene/add_node. This manipulation of the argument projectPath causes command injection. The attack needs to be…
- risk 0.28cvss 4.3epss 0.00
The RealHomes Memberships WordPress plugin before 3.1.0 does not verify that a membership payment actually completed, nor check a nonce or the user's capability, before granting a paid membership package, allowing any authenticated user such as a Subscriber to obtain paid…
- risk 0.42cvss 7.5epss 0.00
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS,…
- risk 0.44cvss 6.8epss 0.00
Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated attacker could potentially exploit this vulnerability leading to loss of confidentiality and integrity.
- risk 0.64cvss 9.8epss 0.00
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. CMS allows SQL Injection. This issue affects CMS: through 06082026. NOTE: The vendor was contacted early about this disclosure…
- risk 0.34cvss 6.3epss 0.01
A vulnerability has been found in MissionSquad mcp-api up to 1.11.8. The impacted element is the function this.packageService.installPackage of the file src/controllers/packages.ts of the component NPM Package Version Handler. The manipulation leads to command injection. It is…
- risk 0.34cvss 6.3epss 0.00
A flaw has been found in MissionSquad mcp-api up to 1.11.9. The affected element is an unknown function of the file src/services/dcrClients.ts. Executing a manipulation can lead to server-side request forgery. The attack may be performed from remote. Upgrading to version 1.11.10…
- risk 0.42cvss 6.4epss 0.00
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Badge Widget Variable Substitution in all versions up to, and including, 1.2.69 due to insufficient input…
- risk 0.54cvss —epss 0.00
OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attacker to forge valid authentication credentials, bypass authentication and authorization, and…
- risk 0.28cvss 4.3epss 0.00
OMICRON StationGuard 4.00 contains an improper input validation vulnerability in its IEC 61850 Sampled Values (SV) frame processing. A specially crafted SV frame can cause the affected process to terminate, disrupting alert processing for Sampled Values traffic. The…
- risk 0.57cvss 8.7epss 0.00
OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attacker to forge valid authentication credentials, bypass authentication and authorization, and…
- risk 0.62cvss 9.6epss 0.00
In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until the…