| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-28189 | Hig | 0.48 | 7.4 | 0.00 | Aug 13, 2026 | Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.4 versions. | ||
| CVE-2026-28188 | Hig | 0.47 | 7.3 | 0.00 | Aug 13, 2026 | Unauthenticated Broken Access Control in Hydra Booking <= 1.2.2 versions. | ||
| CVE-2026-28187 | Hig | 0.46 | 7.1 | 0.00 | Aug 13, 2026 | Unauthenticated Cross Site Scripting (XSS) in Knowledge Base for Documentation, FAQs with AI Assistance <= 17.211.0 versions. | ||
| CVE-2026-28186 | Hig | 0.53 | 8.1 | 0.00 | Aug 13, 2026 | Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1 versions. | ||
| CVE-2026-28185 | Cri | 0.64 | 9.8 | 0.00 | Aug 13, 2026 | Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions. | ||
| CVE-2026-28184 | — | 0.00 | — | — | Aug 13, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | ||
| CVE-2026-28182 | Med | 0.42 | 6.5 | 0.00 | Aug 13, 2026 | Subscriber Cross Site Scripting (XSS) in AcyMailing SMTP Newsletter <= 10.11.1 versions. | ||
| CVE-2026-28181 | Med | 0.42 | 6.5 | 0.00 | Aug 13, 2026 | Subscriber Broken Access Control in AcyMailing SMTP Newsletter <= 10.11.1 versions. | ||
| CVE-2026-28176 | Hig | 0.57 | 8.8 | 0.00 | Aug 13, 2026 | Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions. | ||
| CVE-2026-28175 | Hig | 0.46 | 7.1 | 0.00 | Aug 13, 2026 | Unauthenticated Cross Site Scripting (XSS) in Visitors Traffic Real Time Statistics <= 8.11 versions. | ||
| CVE-2026-28174 | Med | 0.42 | 6.5 | 0.00 | Aug 13, 2026 | Customer Sensitive Data Exposure in WP Event SOlution <= 4.1.18 versions. | ||
| CVE-2026-28173 | Hig | 0.46 | 7.1 | 0.00 | Aug 13, 2026 | Customer Arbitrary Content Deletion in WP Event SOlution <= 4.1.19 versions. | ||
| CVE-2026-28170 | Hig | 0.46 | 7.1 | 0.00 | Aug 13, 2026 | Unauthenticated Cross Site Scripting (XSS) in Blog Floating Button <= 1.4.20 versions. | ||
| CVE-2026-28168 | Hig | 0.55 | 8.5 | 0.00 | Aug 13, 2026 | Subscriber SQL Injection in CubeWP <= 1.1.30 versions. | ||
| CVE-2026-28161 | Hig | 0.57 | 8.8 | 0.00 | Aug 13, 2026 | Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions. | ||
| CVE-2026-28159 | Med | 0.42 | 6.5 | 0.00 | Aug 13, 2026 | Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions. | ||
| CVE-2026-28158 | Hig | 0.46 | 7.1 | 0.00 | Aug 13, 2026 | Unauthenticated Cross Site Scripting (XSS) in Do Lasso <= 358 versions. | ||
| CVE-2026-28157 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2026 | Subscriber Path Traversal in Do Lasso <= 358 versions. | ||
| CVE-2026-28156 | Hig | 0.55 | 8.5 | 0.00 | Aug 13, 2026 | Subscriber SQL Injection in Do Lasso <= 358 versions. | ||
| CVE-2026-28155 | Med | 0.42 | 6.5 | 0.00 | Aug 13, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso <= 358 versions. | ||
| CVE-2026-28149 | Cri | 0.64 | 9.8 | 0.01 | Aug 13, 2026 | Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions. | ||
| CVE-2026-28148 | Cri | 0.64 | 9.8 | 0.00 | Aug 13, 2026 | Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions. | ||
| CVE-2026-28142 | Cri | 0.60 | 9.3 | 0.00 | Aug 13, 2026 | Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions. | ||
| CVE-2026-28008 | Cri | 0.64 | 9.8 | 0.01 | Aug 13, 2026 | Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions. | ||
| CVE-2026-28004 | Hig | 0.46 | 7.1 | 0.00 | Aug 13, 2026 | Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.25 versions. | ||
| CVE-2026-28003 | Hig | 0.46 | 7.1 | 0.00 | Aug 13, 2026 | Unauthenticated Cross Site Scripting (XSS) in Maspik – Spam blacklist <= 2.9.1 versions. | ||
| CVE-2026-28002 | Hig | 0.55 | 8.5 | 0.00 | Aug 13, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arraytics Booktics allows Blind SQL Injection. This issue affects Booktics: from n/a through 1.0.22. | ||
| CVE-2026-28001 | Cri | 0.60 | 9.3 | 0.00 | Aug 13, 2026 | Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions. | ||
| CVE-2026-27999 | Med | 0.42 | 6.5 | 0.00 | Aug 13, 2026 | Subscriber Broken Access Control in Tourfic <= 2.23.1 versions. | ||
| CVE-2026-27544 | Cri | 0.65 | 10.0 | 0.01 | Aug 13, 2026 | Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions. | ||
| CVE-2026-27543 | Hig | 0.53 | 8.1 | 0.00 | Aug 13, 2026 | Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions. | ||
| CVE-2026-27539 | Hig | 0.46 | 7.1 | 0.00 | Aug 13, 2026 | Unauthenticated Cross Site Scripting (XSS) in Welcart e-Commerce <= 2.11.31 versions. | ||
| CVE-2026-27538 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2026 | Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions. | ||
| CVE-2026-27537 | Med | 0.42 | 6.5 | 0.00 | Aug 13, 2026 | Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.11.2 versions. | ||
| CVE-2026-27536 | Hig | 0.46 | 7.1 | 0.00 | Aug 13, 2026 | Unauthenticated Cross Site Scripting (XSS) in MailChimp Subscribe Forms <= 4.3.3 versions. | ||
| CVE-2026-27535 | Hig | 0.46 | 7.1 | 0.00 | Aug 13, 2026 | Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions. | ||
| CVE-2026-27380 | Hig | 0.47 | 7.2 | 0.01 | Aug 13, 2026 | Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions. | ||
| CVE-2026-27345 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2026 | Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions. | ||
| CVE-2026-21832 | Med | 0.28 | 4.3 | 0.00 | Aug 13, 2026 | HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security impact under certain conditions. | ||
| CVE-2026-19716 | Med | 0.26 | — | 0.00 | Aug 13, 2026 | Stored Cross-site Scripting (CWE-79) in the user management component in maalfer Pentestify before 1.1.1 allows an authenticated attacker to execute arbitrary JavaScript in the browser of another authenticated user via a crafted username, because the frontend escapes the… | ||
| CVE-2025-62318 | Low | 0.24 | 3.7 | 0.00 | Aug 13, 2026 | HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages, potentially allowing sensitive information to be captured by an attacker-controlled page (JavaScript hijacking) under certain conditions. | ||
| CVE-2025-62315 | Low | 0.22 | 3.4 | 0.00 | Aug 13, 2026 | HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validation. Unexpected or crafted input may be accepted by the application, potentially resulting in unintended behavior or security impact under certain conditions. | ||
| CVE-2025-62314 | Med | 0.36 | 5.6 | 0.00 | Aug 13, 2026 | HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or scripted requests may be submitted without adequate rate limiting or challenge mechanisms, potentially resulting in unintended behavior or security impact under… | ||
| CVE-2026-73585 | Med | 0.41 | 6.3 | 0.00 | Aug 13, 2026 | A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a local unprivileged user to perform a symlink attack. By creating a symlink in a world-writable directory, an attacker can redirect privileged writes to an… | ||
| CVE-2026-73584 | Med | 0.41 | 6.3 | 0.00 | Aug 13, 2026 | A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the `/tmp` directory. By repeatedly recreating a symbolic link, the attacker can redirect privileged output to… | ||
| CVE-2026-73583 | Med | 0.43 | 6.6 | 0.00 | Aug 13, 2026 | A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserialization vulnerability in the provider-manager's inter-process communication (IPC) message parsing. By sending a specially crafted message, the attacker can cause… | ||
| CVE-2026-6471 | Hig | 0.40 | 7.2 | 0.01 | Aug 13, 2026 | Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. … | ||
| CVE-2026-6470 | Med | 0.21 | 4.3 | 0.00 | Aug 13, 2026 | Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type… | ||
| CVE-2026-6469 | Low | 0.18 | 3.8 | 0.00 | Aug 13, 2026 | Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies… | ||
| CVE-2026-6464 | Hig | 0.46 | 8.1 | 0.00 | Aug 13, 2026 | Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql… |
- risk 0.48cvss 7.4epss 0.00
Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.4 versions.
- risk 0.47cvss 7.3epss 0.00
Unauthenticated Broken Access Control in Hydra Booking <= 1.2.2 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Knowledge Base for Documentation, FAQs with AI Assistance <= 17.211.0 versions.
- risk 0.53cvss 8.1epss 0.00
Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions.
- CVE-2026-28184Aug 13, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- risk 0.42cvss 6.5epss 0.00
Subscriber Cross Site Scripting (XSS) in AcyMailing SMTP Newsletter <= 10.11.1 versions.
- risk 0.42cvss 6.5epss 0.00
Subscriber Broken Access Control in AcyMailing SMTP Newsletter <= 10.11.1 versions.
- risk 0.57cvss 8.8epss 0.00
Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Visitors Traffic Real Time Statistics <= 8.11 versions.
- risk 0.42cvss 6.5epss 0.00
Customer Sensitive Data Exposure in WP Event SOlution <= 4.1.18 versions.
- risk 0.46cvss 7.1epss 0.00
Customer Arbitrary Content Deletion in WP Event SOlution <= 4.1.19 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Blog Floating Button <= 1.4.20 versions.
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in CubeWP <= 1.1.30 versions.
- risk 0.57cvss 8.8epss 0.00
Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions.
- risk 0.42cvss 6.5epss 0.00
Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Do Lasso <= 358 versions.
- risk 0.49cvss 7.5epss 0.00
Subscriber Path Traversal in Do Lasso <= 358 versions.
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in Do Lasso <= 358 versions.
- risk 0.42cvss 6.5epss 0.00
Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso <= 358 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.25 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Maspik – Spam blacklist <= 2.9.1 versions.
- risk 0.55cvss 8.5epss 0.00
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arraytics Booktics allows Blind SQL Injection. This issue affects Booktics: from n/a through 1.0.22.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
- risk 0.42cvss 6.5epss 0.00
Subscriber Broken Access Control in Tourfic <= 2.23.1 versions.
- risk 0.65cvss 10.0epss 0.01
Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Welcart e-Commerce <= 2.11.31 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
- risk 0.42cvss 6.5epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.11.2 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in MailChimp Subscribe Forms <= 4.3.3 versions.
- risk 0.46cvss 7.1epss 0.00
Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions.
- risk 0.47cvss 7.2epss 0.01
Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions.
- risk 0.28cvss 4.3epss 0.00
HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security impact under certain conditions.
- risk 0.26cvss —epss 0.00
Stored Cross-site Scripting (CWE-79) in the user management component in maalfer Pentestify before 1.1.1 allows an authenticated attacker to execute arbitrary JavaScript in the browser of another authenticated user via a crafted username, because the frontend escapes the…
- risk 0.24cvss 3.7epss 0.00
HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages, potentially allowing sensitive information to be captured by an attacker-controlled page (JavaScript hijacking) under certain conditions.
- risk 0.22cvss 3.4epss 0.00
HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validation. Unexpected or crafted input may be accepted by the application, potentially resulting in unintended behavior or security impact under certain conditions.
- risk 0.36cvss 5.6epss 0.00
HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or scripted requests may be submitted without adequate rate limiting or challenge mechanisms, potentially resulting in unintended behavior or security impact under…
- risk 0.41cvss 6.3epss 0.00
A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a local unprivileged user to perform a symlink attack. By creating a symlink in a world-writable directory, an attacker can redirect privileged writes to an…
- risk 0.41cvss 6.3epss 0.00
A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the `/tmp` directory. By repeatedly recreating a symbolic link, the attacker can redirect privileged output to…
- risk 0.43cvss 6.6epss 0.00
A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserialization vulnerability in the provider-manager's inter-process communication (IPC) message parsing. By sending a specially crafted message, the attacker can cause…
- risk 0.40cvss 7.2epss 0.01
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. …
- risk 0.21cvss 4.3epss 0.00
Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type…
- risk 0.18cvss 3.8epss 0.00
Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies…
- risk 0.46cvss 8.1epss 0.00
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql…