🔓 CVEs & KEV
- CVE-2026-15341 — CVSS 9.8 — User Session Synchronizer through 1.4.0 - Unauthenticated Authentication Bypass to...
- CVE-2026-15303 — CVSS 9.8 — 6Storage Rentals through 2.27.0 - Unauthenticated Account Takeover via 'email' Par...
- CVE-2026-14484 — CVSS 9.1 — RapiSafe through 1.0.4 - Unauthenticated Arbitrary File Deletion via 'rsmfcf7_sess...
- CVE-2026-15001 — CVSS 8.8 — bLoyal: Loyalty & Promotions by bLoyal through 3.1.611.78 - Authenticated (Subscri...
- CVE-2026-15965 — CVSS 8.8 — MaxUpload through 1.4.0 - Unauthenticated Arbitrary File Upload via 'resumableFile...
- CVE-2026-15312 — CVSS 8.8 — Propovoice: All-in-One Client Management System through 1.7.8 - Authenticated (ndp...
- CVE-2026-15162 — CVSS 7.5 — Object Sync for Salesforce through 2.2.13 - Unauthenticated SQL InjectionThe Objec...
- CVE-2026-16145 — CVSS 7.2 — Invisible Anti-Spam & CAPTCHA through 5.1 - Unauthenticated Stored Cross-Site Scri...
- CVE-2026-15453 — CVSS 6.5 — KiviCare through 4.5.1 - Authenticated (Doctor+) SQL Injection via 'searchTerm' Pa...
- CVE-2026-16586 — CVSS 6.5 — Contest Gallery through 30.0.6 - Authenticated (Author+) Second-Order SQL Injectio...
- CVE-2026-18387 — CVSS 6.5 — Groundhogg through 4.5.14 - Authenticated (Vendor+) SQL Injection via 'tag_query' ...
- CVE-2026-16080 — CVSS 6.5 — Image Uploader for Welcart through 1.4.6 - Authenticated (Author+) SQL Injection v...