Aggregator
CVE-2026-4668 | ameliabooking Booking for Appointments and Events Calendar Plugin Payments Listing Endpoint PaymentRepository.php sql injection
1 day 6 hours ago
A vulnerability described as critical has been identified in ameliabooking Booking for Appointments and Events Calendar Plugin up to 2.1.2 on WordPress. Affected by this issue is some unknown functionality of the file PaymentRepository.php of the component Payments Listing Endpoint. Executing a manipulation of the argument sort can lead to sql injection.
This vulnerability is registered as CVE-2026-4668. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-34546 | InternationalColorConsortium iccDEV 2.3.1.1/2.3.1.2/2.3.1.3/2.3.1.4/2.3.1.5 TIFF divide by zero (ID 719)
1 day 6 hours ago
A vulnerability marked as problematic has been reported in InternationalColorConsortium iccDEV 2.3.1.1/2.3.1.2/2.3.1.3/2.3.1.4/2.3.1.5. Affected by this vulnerability is an unknown functionality of the component TIFF Handler. Performing a manipulation results in divide by zero.
This vulnerability is cataloged as CVE-2026-34546. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-34555 | InternationalColorConsortium iccDEV 2.3.1.1/2.3.1.2/2.3.1.3/2.3.1.4/2.3.1.5 GetElemNumberValue stack-based overflow (ID 696)
1 day 6 hours ago
A vulnerability labeled as critical has been found in InternationalColorConsortium iccDEV 2.3.1.1/2.3.1.2/2.3.1.3/2.3.1.4/2.3.1.5. Affected is the function CIccTagStruct::GetElemNumberValue. Such manipulation leads to stack-based buffer overflow.
This vulnerability is listed as CVE-2026-34555. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2026-34547 | InternationalColorConsortium iccDEV 2.3.1.1/2.3.1.2/2.3.1.3/2.3.1.4/2.3.1.5 ICC Color Profile IccUtil.cpp reliance on undefined, unspecified, or implementation-defined behavior (ID 720)
1 day 6 hours ago
A vulnerability identified as problematic has been detected in InternationalColorConsortium iccDEV 2.3.1.1/2.3.1.2/2.3.1.3/2.3.1.4/2.3.1.5. This impacts an unknown function of the file IccUtil.cpp of the component ICC Color Profile Handler. This manipulation causes reliance on undefined, unspecified, or implementation-defined behavior.
This vulnerability is tracked as CVE-2026-34547. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
vuldb.com
CVE-2026-34383 | admidio up to 5.0.7 Inventory item_save cross-site request forgery (GHSA-4rwm-c5mj-wh7x)
1 day 6 hours ago
A vulnerability categorized as problematic has been discovered in admidio up to 5.0.7. This affects the function item_save of the component Inventory Module. The manipulation results in cross-site request forgery.
This vulnerability is identified as CVE-2026-34383. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-34556 | InternationalColorConsortium iccDEV 2.3.1.1/2.3.1.2/2.3.1.3/2.3.1.4/2.3.1.5 ICC Color Profile icAnsiToUtf8 out-of-bounds (ID 734)
1 day 6 hours ago
A vulnerability was found in InternationalColorConsortium iccDEV 2.3.1.1/2.3.1.2/2.3.1.3/2.3.1.4/2.3.1.5. It has been rated as problematic. The impacted element is the function icAnsiToUtf8 of the component ICC Color Profile Handler. The manipulation leads to out-of-bounds read.
This vulnerability is referenced as CVE-2026-34556. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-2480 | gn_themes WP Shortcodes Plugin up to 7.4.10 on WordPress Shortcode su_box max_width cross site scripting
1 day 6 hours ago
A vulnerability was found in gn_themes WP Shortcodes Plugin up to 7.4.10 on WordPress. It has been declared as problematic. The affected element is the function su_box of the component Shortcode Handler. Executing a manipulation of the argument max_width can lead to cross site scripting.
The identification of this vulnerability is CVE-2026-2480. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-34586 | mrmn2 PdfDing up to 1.7.0 Download Endpoint check_shared_access_allowed authorization (GHSA-vfqx-2464-38wf)
1 day 6 hours ago
A vulnerability was found in mrmn2 PdfDing up to 1.7.0. It has been classified as problematic. Impacted is the function check_shared_access_allowed of the component Download Endpoint. Performing a manipulation results in incorrect authorization.
This vulnerability was named CVE-2026-34586. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-34394 | WWBN AVideo up to 26.0 Admin Plugin Configuration Endpoint admin/save.json.php isGlobalTokenValid/verifyToken cross-site request forgery (GHSA-4wwr-7h7c-chqr)
1 day 6 hours ago
A vulnerability was found in WWBN AVideo up to 26.0 and classified as problematic. This issue affects the function isGlobalTokenValid/verifyToken of the file admin/save.json.php of the component Admin Plugin Configuration Endpoint. Such manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2026-34394. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2026-34395 | WWBN AVideo up to 26.0 Endpoint User::isLogged authorization (GHSA-77jp-mgcw-rfmr)
1 day 6 hours ago
A vulnerability has been found in WWBN AVideo up to 26.0 and classified as problematic. This vulnerability affects the function User::isLogged of the component Endpoint. This manipulation causes missing authorization.
This vulnerability is handled as CVE-2026-34395. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2026-34382 | admidio up to 5.0.7 mylist_function.php cross-site request forgery (GHSA-g3mx-8jm6-rc85)
1 day 6 hours ago
A vulnerability, which was classified as problematic, was found in admidio up to 5.0.7. This affects an unknown part of the file mylist_function.php. The manipulation results in cross-site request forgery.
This vulnerability is known as CVE-2026-34382. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2026-34384 | admidio up to 5.0.7 URL modules/registration.php create_user/assign_member/assign_user cross-site request forgery (GHSA-ph84-r98x-2j22)
1 day 6 hours ago
A vulnerability, which was classified as problematic, has been found in admidio up to 5.0.7. Affected by this issue is the function create_user/assign_member/assign_user of the file modules/registration.php of the component URL Handler. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2026-34384. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-3468 | SonicWall Email Security cross site scripting (WLID-2026-0002)
1 day 6 hours ago
A vulnerability classified as problematic was found in SonicWall Email Security. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to cross site scripting.
This vulnerability appears as CVE-2026-3468. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2026-34365 | InvoiceShelf up to 2.1.x Estimate PDF Generation Estimate Notes server-side request forgery (GHSA-pc5v-8xwc-v9xq)
1 day 6 hours ago
A vulnerability classified as critical has been found in InvoiceShelf up to 2.1.x. Affected is an unknown function of the component Estimate PDF Generation Module. Performing a manipulation of the argument Estimate Notes results in server-side request forgery.
This vulnerability is reported as CVE-2026-34365. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
AI大模型专场开启,MiSRC邀你来挖洞
1 day 6 hours ago
AI大模型专场开启,MiSRC邀你来挖洞
CVE-2026-34367 | InvoiceShelf up to 2.1.x Invoice PDF Generation Invoice Notes server-side request forgery (GHSA-q9wx-ggwq-mcgh)
1 day 6 hours ago
A vulnerability described as critical has been identified in InvoiceShelf up to 2.1.x. This impacts an unknown function of the component Invoice PDF Generation Module. Such manipulation of the argument Invoice Notes leads to server-side request forgery.
This vulnerability is documented as CVE-2026-34367. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-34366 | InvoiceShelf up to 2.1.x Email Attachment Payment Notes server-side request forgery (GHSA-38hf-fq8x-q49r)
1 day 6 hours ago
A vulnerability marked as critical has been reported in InvoiceShelf up to 2.1.x. This affects an unknown function of the component Email Attachment Handler. This manipulation of the argument Payment Notes causes server-side request forgery.
This vulnerability is registered as CVE-2026-34366. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
通过文件上传实现的xss
1 day 6 hours ago
【春锋行动】陌陌 SRC 联合狩猎,积分翻倍 + 新人专享 + 老带新福利+专项福利等你来!
1 day 6 hours ago
春日猎洞狂欢!陌陌 SRC 多重活动叠加,奖励直接拉满