|
1031
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngine allows SQL Injection.
This issue affects JetEngine: from n/a through 3.8.8.…
New
|
CWE-89
SQL Injection
|
CVE-2026-42774
|
2026-05-27 04:31 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1032
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Sunshine Photo Cart: from n/a throu…
New
|
CWE-862
Missing Authorization
|
CVE-2026-42776
|
2026-05-27 04:31 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1033
|
7.5 |
HIGH
Network
|
-
|
-
|
Missing Authorization vulnerability in edward_plainview MyCryptoCheckout allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects MyCryptoCheckout: from n/a throug…
New
|
CWE-862
Missing Authorization
|
CVE-2026-45209
|
2026-05-27 04:31 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1034
|
8.8 |
HIGH
Network
|
-
|
-
|
Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation.
This issue affects Smart Manager: from n/a through 8.85.0.
New
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-45216
|
2026-05-27 04:31 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1035
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Authentication Bypass Using an Alternate Path or Channel vulnerability in ThemeHigh Stripe Payment Gateway for WooCommerce allows Password Recovery Exploitation.
This issue affects Stripe Payment Ga…
New
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-45217
|
2026-05-27 04:31 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1036
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activity Log allows DOM-Based XSS.
This issue affects WP Activity Log: from n/a thr…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-45435
|
2026-05-27 04:31 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1037
|
7.5 |
HIGH
Network
|
-
|
-
|
Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Smart Coupons for WooCommer…
New
|
CWE-862
Missing Authorization
|
CVE-2026-45438
|
2026-05-27 04:31 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1038
|
8.5 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements For Elementor allows Blind SQL Injection.
This issue affects Unlimited Elemen…
New
|
CWE-89
SQL Injection
|
CVE-2026-48837
|
2026-05-27 04:31 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1039
|
3.7 |
LOW
Network
|
-
|
-
|
PuTTY 0.72 before 0.84 has a double free in RSA KEX.
New
|
CWE-415
Double Free
|
CVE-2026-48850
|
2026-05-27 04:29 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1040
|
3.1 |
LOW
Network
|
-
|
-
|
PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not cleared between proxy authentication and the main session.
New
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-48851
|
2026-05-27 04:29 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|