Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Vulnerability List - Page 37

CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2026-68460 f2fs: fix potential deadlock in f2fs_balance_fs() LinuxLinux--2026-08-15 05:51:20 Deep Dive
CVE-2026-68458 binder: cache secctx size before release zeroes it LinuxLinux--2026-08-15 05:51:19 Deep Dive
CVE-2026-68457 ksmbd: use opener credentials for FSCTL mutations LinuxLinux--2026-08-15 05:51:18 Deep Dive
CVE-2026-68455 liveupdate: validate session type before performing operation LinuxLinux--2026-08-15 05:51:17 Deep Dive
CVE-2026-68456 usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect() LinuxLinux--2026-08-15 05:51:17 Deep Dive
CVE-2026-16007 Authenticated SQL Injection in AppFlowy AppFlowy-IOAppFlowy-Cloud High 7.1 2026-08-15 05:21:17 Deep Dive
CVE-2026-16145 Invisible Anti-Spam & CAPTCHA <= 5.1 - Unauthenticated Stored Cross-Site Scripting via 'action' Parameter matthiasnordwigInvisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms High 7.2 2026-08-15 03:26:00 Deep Dive
CVE-2026-13360 Cookie Banner for GDPR / CCPA <= 4.3.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'regionArray' Parameter wplegalpagesWPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode High 7.2 2026-08-15 03:26:00 Deep Dive
CVE-2026-15948 Hydra Booking <= 1.2.2 - Authenticated (Host+) Stored Cross-Site Scripting via 'first_name' Parameter themeficHydra Booking — Appointment Scheduling & Booking Calendar Medium 6.4 2026-08-15 03:25:59 Deep Dive
CVE-2026-15453 KiviCare <= 4.5.1 - Authenticated (Doctor+) SQL Injection via 'searchTerm' Parameter iqonicdesignKiviCare – Clinic & Patient Management System (EHR) Medium 6.5 2026-08-15 03:25:59 Deep Dive
CVE-2026-16146 Invisible Anti-Spam & CAPTCHA <= 5.1 - Authenticated (Editor+) SQL Injection via Pattern JSON Keys/Values matthiasnordwigInvisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms Medium 4.9 2026-08-15 03:25:59 Deep Dive
CVE-2026-16586 Contest Gallery <= 30.0.6 - Authenticated (Author+) Second-Order SQL Injection via MultipleFiles Second-Order Payload via 'cg_multiple_files_for_post' -> 'cgRealId' contest-galleryContest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Medium 6.5 2026-08-15 03:25:58 Deep Dive
CVE-2026-16094 Invisible Anti-Spam & CAPTCHA <= 5.1 - Authenticated (Editor+) SQL Injection via 'key' Parameter matthiasnordwigInvisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms Medium 4.9 2026-08-15 03:25:58 Deep Dive
CVE-2026-15993 Form Maker by 10Web <= 1.15.44 - Authenticated (Subscriber+) SQL Injection via '{username}' Placeholder in Dynamic-Choice Field WHERE Clause 10webForm Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Medium 5.3 2026-08-15 03:25:57 Deep Dive
CVE-2026-18387 Groundhogg <= 4.5.14 - Authenticated (Vendor+) SQL Injection via 'tag_query' Parameter trainingbusinessprosGroundhogg — CRM, Newsletters, and Marketing Automation Medium 6.5 2026-08-15 03:25:57 Deep Dive
CVE-2026-17090 Beaver Builder Page Builder <= 2.10.2.2 - Authenticated (Author+) Stored Cross-Site Scripting via Button Module 'button' Parameter beaverbuilderBeaver Builder Page Builder – Drag and Drop Website Builder Medium 6.4 2026-08-15 03:25:57 Deep Dive
CVE-2026-15341 User Session Synchronizer <= 1.4.0 - Unauthenticated Authentication Bypass to Account Takeover via 'ussync-key', 'ussync-token', and 'ussync-ref' Parameters rafasashiUser Session Synchronizer Critical 9.8 2026-08-15 02:26:18 Deep Dive
CVE-2026-15001 bLoyal: Loyalty & Promotions by bLoyal <= 3.1.611.78 - Authenticated (Subscriber+) Privilege Escalation via Unprotected AJAX API URL Settings connectordevbLoyal: Loyalty & Promotions by bLoyal High 8.8 2026-08-15 02:26:18 Deep Dive
CVE-2026-12128 Pinpoint Booking System <= 2.9.9.6.8 - Unauthenticated Improper Input Validation to Price Manipulation via 'cart_data' Parameter dotonpaperPinpoint Booking System – Version 2 Medium 5.3 2026-08-15 02:26:18 Deep Dive
CVE-2026-15303 6Storage Rentals <= 2.27.0 - Unauthenticated Account Takeover via 'email' Parameter sixstorage6Storage Rentals Critical 9.8 2026-08-15 02:26:17 Deep Dive