CVE-2026-62022Critical· 9.8▾ MidnightUnauthenticated Privilege Escalation in Tonda Membership <= 1.0.1 versions.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Unauthenticated Privilege Escalation in Tonda Membership <= 1.0.1 versions.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-39801Critical· 9.8Subscriber Privilege Escalation in AIWU <= 1.5.9 versions.
CVE-2026-106610Critical· 9.8Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This issue affects miniorange otp verification: from n/a through 5.5.7.
CVE-2026-106608High· 7.2Incorrect Privilege Assignment vulnerability in Automattic WooCommerce woocommerce allows Privilege Escalation.This issue affects WooCommerce: from 9.8.0 through 11.1.2.
CVE-2025-11050Medium· 6.3A flaw has been found in Portabilis i-Educar up to 2.10
CVE-2025-11049Medium· 6.3A vulnerability was detected in Portabilis i-Educar up to 2.10
CVE-2025-59945High· 8.1SysReptor is a fully customizable pentest reporting platform