Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Vulnerability List - Page 47

CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2026-17090 Beaver Builder Page Builder <= 2.10.2.2 - Authenticated (Author+) Stored Cross-Site Scripting via Button Module 'button' Parameter beaverbuilderBeaver Builder Page Builder – Drag and Drop Website Builder Medium 6.4 2026-08-15 03:25:57 Deep Dive
CVE-2026-15341 User Session Synchronizer <= 1.4.0 - Unauthenticated Authentication Bypass to Account Takeover via 'ussync-key', 'ussync-token', and 'ussync-ref' Parameters rafasashiUser Session Synchronizer Critical 9.8 2026-08-15 02:26:18 Deep Dive
CVE-2026-15001 bLoyal: Loyalty & Promotions by bLoyal <= 3.1.611.78 - Authenticated (Subscriber+) Privilege Escalation via Unprotected AJAX API URL Settings connectordevbLoyal: Loyalty & Promotions by bLoyal High 8.8 2026-08-15 02:26:18 Deep Dive
CVE-2026-12128 Pinpoint Booking System <= 2.9.9.6.8 - Unauthenticated Improper Input Validation to Price Manipulation via 'cart_data' Parameter dotonpaperPinpoint Booking System – Version 2 Medium 5.3 2026-08-15 02:26:18 Deep Dive
CVE-2026-15303 6Storage Rentals <= 2.27.0 - Unauthenticated Account Takeover via 'email' Parameter sixstorage6Storage Rentals Critical 9.8 2026-08-15 02:26:17 Deep Dive
CVE-2026-8840 Booking calendar, Appointment Booking System <= 3.2.36 - Missing Authorization to Unauthenticated Arbitrary Modification via wpdevart_payment AJAX Action wpdevartBooking calendar, Appointment Booking System Medium 5.3 2026-08-15 02:26:17 Deep Dive
CVE-2026-15965 MaxUpload <= 1.4.0 - Unauthenticated Arbitrary File Upload via 'resumableFilename' Parameter sadathimelMaxUpload – Big File Uploads – Increase Maximum File Upload Size High 8.8 2026-08-15 02:26:16 Deep Dive
CVE-2026-15312 Propovoice: All-in-One Client Management System <= 1.7.8 - Authenticated (ndpv_manager+) Privilege Escalation via 'role' Parameter fassionstoragePropovoice: All-in-One Client Management System High 8.8 2026-08-15 02:26:16 Deep Dive
CVE-2026-15162 Object Sync for Salesforce <= 2.2.13 - Unauthenticated SQL Injection minnpostObject Sync for Salesforce High 7.5 2026-08-15 02:26:16 Deep Dive
CVE-2026-16080 Image Uploader for Welcart <= 1.4.6 - Authenticated (Author+) SQL Injection via Attachment 'post_title' Parameter fishpieImage Uploader for Welcart Medium 6.5 2026-08-15 02:26:15 Deep Dive
CVE-2026-14484 RapiSafe <= 1.0.4 - Unauthenticated Arbitrary File Deletion via 'rsmfcf7_session' and 'file_name' Parameters pietror91RapiSafe – Secure Multi File Upload for Contact Form 7 Critical 9.1 2026-08-15 02:26:15 Deep Dive
CVE-2026-14433 Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 - Unauthenticated Stored Cross-Site Scripting via REST API 'business_id' Parameter vcitaOnline Booking & Scheduling Calendar for WordPress by vcita High 7.2 2026-08-15 02:26:15 Deep Dive
CVE-2026-74250 OpenStack Ironic<38.0.1自动检测部署接口缺陷 OpenStackIronic Medium 6.3 2026-08-14 22:53:18 Deep Dive
CVE-2026-74247 Quay: ssrf via build archive_url in quay build api Red HatRed Hat OpenShift Update Service Medium 4.2 2026-08-14 22:43:15 Deep Dive
CVE-2026-74245 Quay: unauthenticated exported logs download in quay Red HatRed Hat OpenShift Update Service Medium 5.9 2026-08-14 22:43:11 Deep Dive
CVE-2026-74244 Quay: stripe webhook accepts forged events without signature verification in quay Red HatRed Hat OpenShift Update Service Medium 5.9 2026-08-14 22:43:06 Deep Dive
CVE-2026-74243 Quay: unauthenticated secscan notification endpoint in quay when psk is unset Red HatRed Hat OpenShift Update Service Medium 6.5 2026-08-14 22:43:06 Deep Dive
CVE-2026-74242 Quay: repository notification uuid idor in quay api Red HatRed Hat OpenShift Update Service Medium 5.3 2026-08-14 22:43:04 Deep Dive
CVE-2026-74241 Quay: ldap referral filter injection in quay external ldap authentication Red HatRed Hat OpenShift Update Service Medium 4.8 2026-08-14 22:43:02 Deep Dive
CVE-2026-74240 Quay: jwt claim validation bypasses in quay federated robot and sso authentication Red HatRed Hat OpenShift Update Service Medium 5.4 2026-08-14 22:43:01 Deep Dive