|
2341
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inclusion.
This issue affects RD Station: from n/a through 5.6.0.
|
CWE-94
Code Injection
|
CVE-2026-49774
|
2026-06-16 23:52 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2342
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Broken Access Control in WooCommerce POS <= 1.8.14 versions.
|
CWE-862
Missing Authorization
|
CVE-2026-52711
|
2026-06-16 23:52 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2343
|
7.6 |
HIGH
Network
|
-
|
-
|
Subscriber SQL Injection in Attendance Manager <= 0.6.2 versions.
|
CWE-89
SQL Injection
|
CVE-2026-52712
|
2026-06-16 23:52 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2344
|
5.9 |
MEDIUM
Network
|
-
|
-
|
Unauthenticated Broken Access Control in SEO Plugin by Squirrly SEO <= 12.4.16 versions.
|
CWE-862
Missing Authorization
|
CVE-2026-52714
|
2026-06-16 23:52 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2345
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions.
|
CWE-89
SQL Injection
|
CVE-2026-52715
|
2026-06-16 23:52 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2346
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Unauthenticated Broken Access Control in Envira Photo Gallery <= 1.12.5 versions.
|
CWE-862
Missing Authorization
|
CVE-2026-54190
|
2026-06-16 23:52 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2347
|
7.1 |
HIGH
Network
|
-
|
-
|
Unauthenticated Cross Site Scripting (XSS) in Pods <= 3.3.8 versions.
|
CWE-79
Cross-site Scripting
|
CVE-2026-54191
|
2026-06-16 23:52 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2348
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Unauthenticated Sensitive Data Exposure in GetGenie <= 4.4.1 versions.
|
CWE-201
Insertion of Sensitive Information Into Sent Data
|
CVE-2026-54197
|
2026-06-16 23:52 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2349
|
7.1 |
HIGH
Network
|
-
|
-
|
Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions.
|
CWE-79
Cross-site Scripting
|
CVE-2026-54198
|
2026-06-16 23:52 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2350
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server.
This issue affects Kids Online Store: from n/a through 0.…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-40750
|
2026-06-16 23:52 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|