CVE-2026-77995
Last Modified: 8 Sept 2026Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0, OAuth Single Sign-On – OIDC SSO < 1.2.2, Login with Keycloak OAuth Single Sign-On (SSO) < 1.2.2, Single Sign-On for Educational Institutes < 1.2.2 - The manipulation of a cookie value allows actors to login as arbitrary accounts, including admins.
CVE-2026-78370
Last Modified: 24 Aug 2026RansomLook contains an authorization flaw in its legacy database export functionality that can allow unauthenticated remote users to retrieve information intended to remain private. The /export/<database> endpoint permits selected internal databases to be exported without requiring authentication. While limited filtering is performed for some entity databases, other exportable databases are returned directly without consistently applying the application's private-entity access restrictions. As a result, information associated with groups, markets, posts, or other records marked as private may be included in an export accessible to an unauthenticated requester. An attacker able to reach the RansomLook web application can request the affected export endpoint and retrieve data that should only be available to authorized users. Depending on the contents of the instance, this may disclose private ransomware intelligence, victim information, internal tracking data, or other information deliberately excluded from public views. The patch removes the legacy unauthenticated export route and introduces centralized authorization handling that distinguishes ordinary authenticated API access from authorization to view private entries. API keys must now be explicitly granted private-data access, while existing keys do not automatically receive this privilege. The same private-data filtering is also applied consistently across API responses and database exports.
CVE-2026-78248
Last Modified: 24 Aug 2026A vulnerability was determined in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/ajax.php?action=save_settings. This manipulation of the argument Name causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2026-78369
Last Modified: 24 Aug 2026RansomLook contains a missing authentication vulnerability in the /admin/crypto/group/new endpoint. While the endpoint provides an administrative function for creating new crypto group entries, it was not protected by the application's authentication mechanism. An unauthenticated remote attacker able to access the RansomLook web interface could therefore submit requests to this endpoint and create crypto group entries without possessing a valid authenticated session or administrative credentials. Successful exploitation allows an attacker to make unauthorized modifications to data that should only be manageable by authenticated administrators. Depending on how crypto group information is subsequently consumed by RansomLook, malicious or fraudulent entries could also affect the integrity of information presented or processed by the application. The vulnerability is addressed by applying the flask_login.login_required decorator to the /admin/crypto/group/new route, ensuring that only authenticated users can access the functionality.
CVE-2026-21756
Last Modified: 24 Aug 2026HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unauthorized user to introduce unverified, malicious, or broken code directly into production environments.
CVE-2026-78365
Last Modified: 24 Aug 2026Authorization Bypass Through User-Controlled Key in the supplier API in Roskus Prospero Flow CRM 4.0.0 through 5.3.1 allows any authenticated user to read and modify another company's supplier record, and to reassign it to their own company, via a PUT request to /api/supplier/{id} setting company_id in the body.
CVE-2026-78247
Last Modified: 26 Aug 2026A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=confirm_order. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
CVE-2026-21759
Last Modified: 24 Aug 2026HCL Hive is affected by an information exposure vulnerability where Swagger documentation was found exposed publicly. Although no sensitive information (e.g., credentials, PII) was discovered, exposing API documentation to unauthenticated users can increase the overall attack surface.
CVE-2026-78701
Last Modified: 8 Sept 2026A flaw was found in 389-ds-base. A remote, authenticated attacker could exploit a vulnerability in the Simple Authentication and Security Layer (SASL) UNBIND process. By sending a specially crafted request, the attacker can cause a connection to stall, leading to resource exhaustion and a Denial of Service (DoS) for the server.
CVE-2026-66670
Last Modified: 24 Aug 2026Unauthenticated Local File Inclusion in Måne <= 1.7 versions.
CVE-2026-66650
Last Modified: 24 Aug 2026Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.
CVE-2026-66648
Last Modified: 24 Aug 2026Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.
CVE-2026-66610
Last Modified: 24 Aug 2026Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions.
CVE-2026-66587
Last Modified: 24 Aug 2026Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.
CVE-2026-66585
Last Modified: 24 Aug 2026Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions.
CVE-2026-32558
Last Modified: 24 Aug 2026Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions.
CVE-2026-32551
Last Modified: 24 Aug 2026Unauthenticated SQL Injection in Woo Essential <= 4.3.0 versions.
CVE-2026-32478
Last Modified: 24 Aug 2026Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions.
CVE-2026-32477
Last Modified: 24 Aug 2026Unauthenticated Arbitrary File Deletion in ShopBuilder Pro – Elementor WooCommerce Builder Addons <= 2.2.0 versions.
CVE-2026-32476
Last Modified: 24 Aug 2026Unauthenticated Cross Site Scripting (XSS) in Brave Conversion Engine (PRO) <= 0.8.6 versions.
CVE-2026-32471
Last Modified: 24 Aug 2026Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions.
CVE-2026-28190
Last Modified: 24 Aug 2026Subscriber Broken Access Control in ProLancer Element <= 1.4.8 versions.
CVE-2026-28171
Last Modified: 24 Aug 2026Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions.
CVE-2026-28167
Last Modified: 24 Aug 2026Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions.
CVE-2026-28166
Last Modified: 24 Aug 2026Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions.
CVE-2026-28165
Last Modified: 24 Aug 2026Unauthenticated Privilege Escalation in Digits <= 9.2 versions.
CVE-2026-28162
Last Modified: 24 Aug 2026Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions.
CVE-2026-28153
Last Modified: 24 Aug 2026Unauthenticated Broken Access Control in Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More <= 1.7.1 versions.
CVE-2026-28152
Last Modified: 24 Aug 2026Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions.
CVE-2026-28151
Last Modified: 24 Aug 2026Unauthenticated Local File Inclusion in Tonda < 2.6 versions.
CVE-2026-66671
Last Modified: 24 Aug 2026Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions.
CVE-2026-78290
Last Modified: 24 Aug 2026Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions.
CVE-2026-78280
Last Modified: 24 Aug 2026Unauthenticated Cross Site Request Forgery (CSRF) in Hash Form <= 1.4.0 versions.
CVE-2026-78279
Last Modified: 24 Aug 2026Unauthenticated Cross Site Request Forgery (CSRF) in Fluent Support Pro <= 2.3.1 versions.
CVE-2026-78278
Last Modified: 24 Aug 2026Subscriber Insecure Direct Object References (IDOR) in Fluent Boards Pro <= 2.0.11 versions.
CVE-2026-78277
Last Modified: 24 Aug 2026Subscriber Server Side Request Forgery (SSRF) in FluentCRM Pro <= 3.1.12 versions.
CVE-2026-78272
Last Modified: 24 Aug 2026Subscriber Broken Access Control in Fluent Support Pro <= 2.3.1 versions.
CVE-2026-78270
Last Modified: 24 Aug 2026Author SQL Injection in FluentCRM Pro <= 3.1.12 versions.
CVE-2026-78269
Last Modified: 24 Aug 2026Contributor Server Side Request Forgery (SSRF) in Shared Files <= 1.7.69 versions.
CVE-2026-78258
Last Modified: 24 Aug 2026Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.5 versions.
CVE-2026-66623
Last Modified: 24 Aug 2026Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions.
CVE-2026-66599
Last Modified: 24 Aug 2026Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 2.9.5.6 versions.
CVE-2026-66584
Last Modified: 24 Aug 2026Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions.
CVE-2026-78291
Last Modified: 24 Aug 2026Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 versions.
CVE-2026-78246
Last Modified: 24 Aug 2026A vulnerability has been found in itsourcecode Online Clinic Management System 1.0. This vulnerability affects unknown code of the file success/login.php of the component Admin Login. The manipulation of the argument Username leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
CVE-2025-63080
Last Modified: 24 Aug 2026Firmware in KAON PG5298A and PG5298B routers allow an authenticated user to send crafted JSON-RPC requests and perform operations not possible via GUI, e.g. system file read or command execution. This vulnerability has been fixed in firmware version: 3.0.82 for PG5298A and 4.0.82 for PG5298B.
CVE-2026-6017
Last Modified: 24 Aug 2026Firmware in KAON PG5298A and PG5298B routers allow an unauthenticated user to query a specific endpoint and acquire sensitive information such as a password to the administrative portal. This vulnerability has been fixed in firmware version: 3.0.82 for PG5298A and 4.0.82 for PG5298B.
CVE-2026-78337
Last Modified: 24 Aug 2026Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow CRM before 5.15.13 allows an authenticated user holding the create company and update company permissions to execute arbitrary JavaScript in the application origin via an SVG document containing an embedded script element.
CVE-2026-78245
Last Modified: 24 Aug 2026A flaw has been found in itsourcecode Online Pharmacy System 1.0. This affects the function move_uploaded_file of the file all_users/register.php of the component User Registration. Executing a manipulation of the argument photo can lead to unrestricted upload. The attack may be launched remotely. The exploit has been published and may be used.
CVE-2026-78244
Last Modified: 27 Aug 2026A vulnerability was detected in itsourcecode Real Estate Management System 1.0. Affected by this issue is some unknown functionality of the file search.php. Performing a manipulation of the argument search/delivery_type/search_price/property_type results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used.
