CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2026-77995

    Last Modified: 8 Sept 2026

    Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0, OAuth Single Sign-On – OIDC SSO < 1.2.2, Login with Keycloak OAuth Single Sign-On (SSO) < 1.2.2, Single Sign-On for Educational Institutes < 1.2.2 - The manipulation of a cookie value allows actors to login as arbitrary accounts, including admins.

    Published: 24 Aug 2026
    9.2
    Critical

    CVE-2026-78370

    Last Modified: 24 Aug 2026

    RansomLook contains an authorization flaw in its legacy database export functionality that can allow unauthenticated remote users to retrieve information intended to remain private. The /export/<database> endpoint permits selected internal databases to be exported without requiring authentication. While limited filtering is performed for some entity databases, other exportable databases are returned directly without consistently applying the application's private-entity access restrictions. As a result, information associated with groups, markets, posts, or other records marked as private may be included in an export accessible to an unauthenticated requester. An attacker able to reach the RansomLook web application can request the affected export endpoint and retrieve data that should only be available to authorized users. Depending on the contents of the instance, this may disclose private ransomware intelligence, victim information, internal tracking data, or other information deliberately excluded from public views. The patch removes the legacy unauthenticated export route and introduces centralized authorization handling that distinguishes ordinary authenticated API access from authorization to view private entries. API keys must now be explicitly granted private-data access, while existing keys do not automatically receive this privilege. The same private-data filtering is also applied consistently across API responses and database exports.

    Published: 24 Aug 2026
    5.5
    Medium

    CVE-2026-78248

    Last Modified: 24 Aug 2026

    A vulnerability was determined in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/ajax.php?action=save_settings. This manipulation of the argument Name causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

    Published: 24 Aug 2026
    8.8
    High

    CVE-2026-78369

    Last Modified: 24 Aug 2026

    RansomLook contains a missing authentication vulnerability in the /admin/crypto/group/new endpoint. While the endpoint provides an administrative function for creating new crypto group entries, it was not protected by the application's authentication mechanism. An unauthenticated remote attacker able to access the RansomLook web interface could therefore submit requests to this endpoint and create crypto group entries without possessing a valid authenticated session or administrative credentials. Successful exploitation allows an attacker to make unauthorized modifications to data that should only be manageable by authenticated administrators. Depending on how crypto group information is subsequently consumed by RansomLook, malicious or fraudulent entries could also affect the integrity of information presented or processed by the application. The vulnerability is addressed by applying the flask_login.login_required decorator to the /admin/crypto/group/new route, ensuring that only authenticated users can access the functionality.

    Published: 24 Aug 2026
    7.2
    High

    CVE-2026-21756

    Last Modified: 24 Aug 2026

    HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unauthorized user to introduce unverified, malicious, or broken code directly into production environments.

    Published: 24 Aug 2026
    9.3
    Critical

    CVE-2026-78365

    Last Modified: 24 Aug 2026

    Authorization Bypass Through User-Controlled Key in the supplier API in Roskus Prospero Flow CRM 4.0.0 through 5.3.1 allows any authenticated user to read and modify another company's supplier record, and to reassign it to their own company, via a PUT request to /api/supplier/{id} setting company_id in the body.

    Published: 24 Aug 2026
    5.5
    Medium

    CVE-2026-78247

    Last Modified: 26 Aug 2026

    A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=confirm_order. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.

    Published: 24 Aug 2026
    4.3
    Medium

    CVE-2026-21759

    Last Modified: 24 Aug 2026

    HCL Hive is affected by an information exposure vulnerability where Swagger documentation was found exposed publicly.  Although no sensitive information (e.g., credentials, PII) was discovered, exposing API documentation to unauthenticated users can increase the overall attack surface.

    Published: 24 Aug 2026
    6.5
    Medium

    CVE-2026-78701

    Last Modified: 8 Sept 2026

    A flaw was found in 389-ds-base. A remote, authenticated attacker could exploit a vulnerability in the Simple Authentication and Security Layer (SASL) UNBIND process. By sending a specially crafted request, the attacker can cause a connection to stall, leading to resource exhaustion and a Denial of Service (DoS) for the server.

    Published: 24 Aug 2026
    8.1
    High

    CVE-2026-66670

    Last Modified: 24 Aug 2026

    Unauthenticated Local File Inclusion in Måne <= 1.7 versions.

    Published: 24 Aug 2026
    9.8
    Critical

    CVE-2026-66650

    Last Modified: 24 Aug 2026

    Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.

    Published: 24 Aug 2026
    9.8
    Critical

    CVE-2026-66648

    Last Modified: 24 Aug 2026

    Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.

    Published: 24 Aug 2026
    7.1
    High

    CVE-2026-66610

    Last Modified: 24 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions.

    Published: 24 Aug 2026
    9.8
    Critical

    CVE-2026-66587

    Last Modified: 24 Aug 2026

    Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.

    Published: 24 Aug 2026
    7.5
    High

    CVE-2026-66585

    Last Modified: 24 Aug 2026

    Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions.

    Published: 24 Aug 2026
    9.8
    Critical

    CVE-2026-32558

    Last Modified: 24 Aug 2026

    Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions.

    Published: 24 Aug 2026
    9.3
    Critical

    CVE-2026-32551

    Last Modified: 24 Aug 2026

    Unauthenticated SQL Injection in Woo Essential <= 4.3.0 versions.

    Published: 24 Aug 2026
    8.5
    High

    CVE-2026-32478

    Last Modified: 24 Aug 2026

    Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions.

    Published: 24 Aug 2026
    8.6
    High

    CVE-2026-32477

    Last Modified: 24 Aug 2026

    Unauthenticated Arbitrary File Deletion in ShopBuilder Pro – Elementor WooCommerce Builder Addons <= 2.2.0 versions.

    Published: 24 Aug 2026
    7.1
    High

    CVE-2026-32476

    Last Modified: 24 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in Brave Conversion Engine (PRO) <= 0.8.6 versions.

    Published: 24 Aug 2026
    8.5
    High

    CVE-2026-32471

    Last Modified: 24 Aug 2026

    Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions.

    Published: 24 Aug 2026
    7.1
    High

    CVE-2026-28190

    Last Modified: 24 Aug 2026

    Subscriber Broken Access Control in ProLancer Element <= 1.4.8 versions.

    Published: 24 Aug 2026
    8.6
    High

    CVE-2026-28171

    Last Modified: 24 Aug 2026

    Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions.

    Published: 24 Aug 2026
    7.5
    High

    CVE-2026-28167

    Last Modified: 24 Aug 2026

    Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions.

    Published: 24 Aug 2026
    7.1
    High

    CVE-2026-28166

    Last Modified: 24 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions.

    Published: 24 Aug 2026
    9.8
    Critical

    CVE-2026-28165

    Last Modified: 24 Aug 2026

    Unauthenticated Privilege Escalation in Digits <= 9.2 versions.

    Published: 24 Aug 2026
    7.1
    High

    CVE-2026-28162

    Last Modified: 24 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions.

    Published: 24 Aug 2026
    7.5
    High

    CVE-2026-28153

    Last Modified: 24 Aug 2026

    Unauthenticated Broken Access Control in Notification Master &#8211; Real-Time WordPress Notifications With Email, SMS, Webhooks &amp; More <= 1.7.1 versions.

    Published: 24 Aug 2026
    8.1
    High

    CVE-2026-28152

    Last Modified: 24 Aug 2026

    Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions.

    Published: 24 Aug 2026
    8.1
    High

    CVE-2026-28151

    Last Modified: 24 Aug 2026

    Unauthenticated Local File Inclusion in Tonda < 2.6 versions.

    Published: 24 Aug 2026
    8.1
    High

    CVE-2026-66671

    Last Modified: 24 Aug 2026

    Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions.

    Published: 24 Aug 2026
    6.5
    Medium

    CVE-2026-78290

    Last Modified: 24 Aug 2026

    Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions.

    Published: 24 Aug 2026
    4.3
    Medium

    CVE-2026-78280

    Last Modified: 24 Aug 2026

    Unauthenticated Cross Site Request Forgery (CSRF) in Hash Form <= 1.4.0 versions.

    Published: 24 Aug 2026
    5.4
    Medium

    CVE-2026-78279

    Last Modified: 24 Aug 2026

    Unauthenticated Cross Site Request Forgery (CSRF) in Fluent Support Pro <= 2.3.1 versions.

    Published: 24 Aug 2026
    5.3
    Medium

    CVE-2026-78278

    Last Modified: 24 Aug 2026

    Subscriber Insecure Direct Object References (IDOR) in Fluent Boards Pro <= 2.0.11 versions.

    Published: 24 Aug 2026
    4.9
    Medium

    CVE-2026-78277

    Last Modified: 24 Aug 2026

    Subscriber Server Side Request Forgery (SSRF) in FluentCRM Pro <= 3.1.12 versions.

    Published: 24 Aug 2026
    5.4
    Medium

    CVE-2026-78272

    Last Modified: 24 Aug 2026

    Subscriber Broken Access Control in Fluent Support Pro <= 2.3.1 versions.

    Published: 24 Aug 2026
    7.6
    High

    CVE-2026-78270

    Last Modified: 24 Aug 2026

    Author SQL Injection in FluentCRM Pro <= 3.1.12 versions.

    Published: 24 Aug 2026
    6.4
    Medium

    CVE-2026-78269

    Last Modified: 24 Aug 2026

    Contributor Server Side Request Forgery (SSRF) in Shared Files <= 1.7.69 versions.

    Published: 24 Aug 2026
    5.3
    Medium

    CVE-2026-78258

    Last Modified: 24 Aug 2026

    Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.5 versions.

    Published: 24 Aug 2026
    7.1
    High

    CVE-2026-66623

    Last Modified: 24 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions.

    Published: 24 Aug 2026
    7.1
    High

    CVE-2026-66599

    Last Modified: 24 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 2.9.5.6 versions.

    Published: 24 Aug 2026
    7.1
    High

    CVE-2026-66584

    Last Modified: 24 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions.

    Published: 24 Aug 2026
    5.3
    Medium

    CVE-2026-78291

    Last Modified: 24 Aug 2026

    Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 versions.

    Published: 24 Aug 2026
    5.5
    Medium

    CVE-2026-78246

    Last Modified: 24 Aug 2026

    A vulnerability has been found in itsourcecode Online Clinic Management System 1.0. This vulnerability affects unknown code of the file success/login.php of the component Admin Login. The manipulation of the argument Username leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

    Published: 24 Aug 2026
    8.5
    High

    CVE-2025-63080

    Last Modified: 24 Aug 2026

    Firmware in KAON PG5298A and PG5298B routers allow an authenticated user to send crafted JSON-RPC requests and perform operations not possible via GUI, e.g. system file read or command execution.    This vulnerability has been fixed in firmware version: 3.0.82 for PG5298A and 4.0.82 for PG5298B.

    Published: 24 Aug 2026
    7.1
    High

    CVE-2026-6017

    Last Modified: 24 Aug 2026

    Firmware in KAON PG5298A and PG5298B routers allow an unauthenticated user to query a specific endpoint and acquire sensitive information such as a password to the administrative portal.   This vulnerability has been fixed in firmware version: 3.0.82 for PG5298A and 4.0.82 for PG5298B.

    Published: 24 Aug 2026
    4.8
    Medium

    CVE-2026-78337

    Last Modified: 24 Aug 2026

    Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow CRM before 5.15.13 allows an authenticated user holding the create company and update company permissions to execute arbitrary JavaScript in the application origin via an SVG document containing an embedded script element.

    Published: 24 Aug 2026
    5.5
    Medium

    CVE-2026-78245

    Last Modified: 24 Aug 2026

    A flaw has been found in itsourcecode Online Pharmacy System 1.0. This affects the function move_uploaded_file of the file all_users/register.php of the component User Registration. Executing a manipulation of the argument photo can lead to unrestricted upload. The attack may be launched remotely. The exploit has been published and may be used.

    Published: 24 Aug 2026
    5.5
    Medium

    CVE-2026-78244

    Last Modified: 27 Aug 2026

    A vulnerability was detected in itsourcecode Real Estate Management System 1.0. Affected by this issue is some unknown functionality of the file search.php. Performing a manipulation of the argument search/delivery_type/search_price/property_type results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used.

    Published: 24 Aug 2026