Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Vulnerability List - Page 76

CVE ID Title Vendor Product Severity CVSS Score Published At AI Analysis
CVE-2026-75098 Product Designer App <= 1.1.3 - Unauthenticated Arbitrary File Read via 'svg' Parameter in pdapp-render-design productdesignerapp Product Designer App High 7.5 2026-09-30 08:28:05 Deep Dive
CVE-2026-92712 ReactPress <= 3.4.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'permalink' Parameter rockiger ReactPress – Create React App for WordPress Medium 6.4 2026-09-30 08:28:05 Deep Dive
CVE-2026-93908 Real Estate Manager <= 7.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'before_price_text' Parameter rameez_iqbal Real Estate Manager – Property Listing and Agent Management Medium 6.4 2026-09-30 08:28:04 Deep Dive
CVE-2025-14564 Viable URL Media Uploader <= 1.0.0 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ahsangadit Viable URL Media Uploader Medium 6.4 2026-09-30 08:28:04 Deep Dive
CVE-2026-97347 Post Views Stats Counter <= 1.1.7 - Unauthenticated Stored Cross-Site Scripting via User-Agent Header kazukiyanamoto Post Views Stats Counter High 7.2 2026-09-30 08:28:03 Deep Dive
CVE-2026-102454 DigiWin|EasyFlow .NET - Arbitrary File Upload DigiWin EasyFlow .NET High 7.2 2026-09-30 08:26:07 Deep Dive
CVE-2026-102511 Apache PLC4X, Apache PLC4X, Apache PLC4X, Apache PLC4X: ADS discovery accepts spoofed responses and derives the connection target from them Apache Software Foundation Apache PLC4X High 8.5 2026-09-30 08:03:04 Deep Dive
CVE-2026-102510 Apache PLC4X: Go binding: unbounded allocation and framing failures on wire-controlled lengths Apache Software Foundation Apache PLC4X High 8.7 2026-09-30 08:01:43 Deep Dive
CVE-2026-102509 Apache PLC4X, Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver and the Java SPI parser Apache Software Foundation Apache PLC4X High 8.7 2026-09-30 08:00:28 Deep Dive
CVE-2026-92873 Pgpool-II认证算法缺陷致未授权提升看门狗节点 Pgpool Global Development Group Pgpool-II Medium 6.9 2026-09-30 07:51:52 Deep Dive
CVE-2026-92872 Pgpool-II敏感信息泄露至日志文件漏洞 Pgpool Global Development Group Pgpool-II Medium 5.3 2026-09-30 07:47:50 Deep Dive
CVE-2026-92871 Pgpool-II空指针解引用致看门狗进程异常终止 Pgpool Global Development Group Pgpool-II High 8.7 2026-09-30 07:47:32 Deep Dive
CVE-2026-102508 Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, and silent downgrade Apache Software Foundation Apache PLC4X Critical 9.2 2026-09-30 07:42:44 Deep Dive
CVE-2026-93462 baserCMS关键功能缺失认证致敏感信息泄露漏洞 baserCMS User Community baserCMS Medium 6.9 2026-09-30 07:42:32 Deep Dive
CVE-2026-6170 Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_css_image_grid 'images' Shortcode Attribute boldthemes Bold Page Builder Medium 6.4 2026-09-30 07:41:07 Deep Dive
CVE-2026-6173 Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'background_image' Parameter boldthemes Bold Page Builder Medium 6.4 2026-09-30 07:41:07 Deep Dive
CVE-2026-16596 WP Directory Kit <= 1.5.4 - Authenticated (Custom+) SQL Injection via 'data_fields_list' Parameter wpdirectorykit WP Directory Kit Medium 6.5 2026-09-30 07:41:07 Deep Dive
CVE-2026-6171 Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'target' Shortcode Attribute boldthemes Bold Page Builder Medium 6.4 2026-09-30 07:41:06 Deep Dive
CVE-2026-6806 Motors <= 1.4.109 - Unauthenticated Blind SQL Injection via 'stm_lat'/'stm_lng' Parameters stylemix Motors – Car Dealership & Classified Listings Plugin High 7.5 2026-09-30 07:41:06 Deep Dive
CVE-2026-14876 Smart Slider 3 <= 3.5.1.38 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-href' Attribute in Custom HTML Block nextendweb Smart Slider 3 Medium 6.4 2026-09-30 07:41:06 Deep Dive