| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67318. Reason: This candidate is a duplicate of CVE-2026-67318. Notes: All CVE users should reference CVE-2026-67318 instead of this candidate. |
| ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67317. Reason: This candidate is a duplicate of CVE-2026-67317. Notes: All CVE users should reference CVE-2026-67317 instead of this candidate. |
| ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67315. Reason: This candidate is a duplicate of CVE-2026-67315. Notes: All CVE users should reference CVE-2026-67315 instead of this candidate. |
| ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67316. Reason: This candidate is a duplicate of CVE-2026-67316. Notes: All CVE users should reference CVE-2026-67316 instead of this candidate. |
| ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67314. Reason: This candidate is a duplicate of CVE-2026-67314. Notes: All CVE users should reference CVE-2026-67314 instead of this candidate. |
| ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67313. Reason: This candidate is a duplicate of CVE-2026-67313. Notes: All CVE users should reference CVE-2026-67313 instead of this candidate. |
| ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67312. Reason: This candidate is a duplicate of CVE-2026-67312. Notes: All CVE users should reference CVE-2026-67312 instead of this candidate. |
| Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions. |
| A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the function SecretDialog.showSecretDialog of the file src/utils/secretDialog.ts of the component get_credential_from_user. This manipulation of the argument Description causes command injection. It is possible to launch the attack on the local host. The project was informed of the problem early through an issue report but has not responded yet. |
| Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions. |
| Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions. |
| Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions. |
| Subscriber SQL Injection in Creative Mail <= 1.6.9 versions. |
| Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions. |
| Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass. An attacker could construct a malicious URL that redirects a victim to an attacker-controlled site. Exploitation of this issue requires user interaction in that a victim must click on a malicious link. Scope is changed. |
| Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass. An attacker could construct a malicious URL that redirects a victim to an attacker-controlled site. Exploitation of this issue requires user interaction in that a victim must click on a malicious link. Scope is changed. |
| A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encode() validates only the standalone segment length via FileSegment_GetMaxDataSize() and does not verify the residual capacity of the current ASDU frame before encoding object fields and segment data |
| Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions. |
| Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions. |