CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 24d ago | 8.8 | Improper input validation in the SSH Elevate Shell feature allows an authenticated user with permission to create or modify a shared SSH entry to execute arbitrary commands on a remote SSH host using stored elevation credentials via a crafted alternate username and user interaction with the Elevate Shell action. This affects : - Remote Desktop Manager 2026.2.5.0 through 2026.2.7.0 - Remote Desktop Manager 2026.1.23.0 and earlier |
| Exploit 24d ago | 7.8 | The browserstack-cypress-cli is BrowserStack's CLI which allows users to run Cypress tests on BrowserStack. Versions prior to 1.36.4 are vulnerable to OS command injection via the cypress_config_file configuration parameter. In readCypressConfigUtil.js, the loadJsFile() function constructs a shell command by interpolating the user-controlled cypress_config_filepath value into a template literal, then executes it via child_process.execSync(). Shell metacharacters in the config path (specifically " and ;) allow breaking out of the quoted argument and injecting arbitrary commands. This issue has been fixed in version 1.36.6. |
| Exploit 24d ago | 8.8 | DbGate is cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reader endpoint in DbGate accepts a functionName parameter that is directly interpolated into a JavaScript code template without any sanitization or validation. An authenticated user (with basic access, no special permissions required) can inject arbitrary JavaScript code that executes on the server with full process privileges, bypassing the require=null sandbox restriction. An authenticated user with basic access (no admin role, no run-shell-script permission required) can: execute arbitrary OS commands on the DbGate server with the privileges of the Node.js process, read/write any file accessible to the process, pivot to connected databases by reading connection credentials from DbGate's storage, and compromise the host system - in Docker deployments, this typically means root access within the container. Version 7.1.9 contains a patch. |
| 24d ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in SEO Redirection <= 9.17 versions. |
| 24d ago | 8.5 | Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions. |
| 24d ago | 7.5 | Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar <= 1.4.5 versions. |
| 24d ago | 8.5 | Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions. |
| 24d ago | 7.5 | Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions. |
| 24d ago | 7.5 | Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions. |
| 24d ago | 7.5 | Unauthenticated Sensitive Data Exposure in Affiliates Manager <= 2.9.50 versions. |
| 24d ago | 8.8 | Customer Privilege Escalation in Dokan <= 5.0.2 versions. |
| 24d ago | 7.5 | Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions. |
| 24d ago | 7.5 | Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce <= 3.1.4 versions. |
| 24d ago | 7.5 | Contributor Privilege Escalation in LatePoint <= 5.5.1 versions. |
| 24d ago | 7.4 | Subscriber Sensitive Data Exposure in Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons <= 1.4.8 versions. |
| 24d ago | 7.5 | Unauthenticated Other Vulnerability Type in WP Travel Engine <= 6.7.10 versions. |
| 24d ago | 7.5 | Unauthenticated Broken Access Control in Knit Pay <= 9.4.0.0 versions. |
| 24d ago | 7.5 | Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions. |
| 24d ago | 7.5 | Unauthenticated Sensitive Data Exposure in Conekta Payment Gateway <= 6.0.0 versions. |
| 24d ago | 8.2 | Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions. |
| 24d ago | 7.3 | Unauthenticated Privilege Escalation in Listdom <= 5.5.0 versions. |
| 24d ago | 7.5 | Unauthenticated Arbitrary File Download in WPC Product Options for WooCommerce <= 3.2.1 versions. |
| 24d ago | 7.5 | Unauthenticated Sensitive Data Exposure in WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.9.4 versions. |
| 24d ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.9.7 versions. |
| 24d ago | 8.1 | Unauthenticated Broken Authentication in Really Simple SSL <= 9.5.10 versions. |
| 24d ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Funnel Builder by FunnelKit <= 3.15.0.2 versions. |
| 24d ago | 8.5 | Subscriber SQL Injection in ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.6 versions. |
| 24d ago | 8.8 | Subscriber Privilege Escalation in Amelia <= 2.3 versions. |
| 24d ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in HollerBox <= 2.3.10.1 versions. |
| 24d ago | 7.5 | Unauthenticated Broken Access Control in WPC Product Bundles for WooCommerce <= 8.5.3 versions. |