6.1

CVSS4.0

CVE-2026-22202 - wpDiscuz before 7.6.47 - Destructive GET Action Deletes All Comments by Email

wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability that allows attackers to delete all comments associated with an email address by crafting a malicious GET request with a valid HMAC key. Attackers can embed the deletecomments action URL in image tags or other resources to t…

πŸ“… Published: March 13, 2026, 1:18 a.m. πŸ”„ Last Modified: March 23, 2026, 9:59 a.m.

6.9

CVSS4.0

CVE-2026-22201 - wpDiscuz before 7.6.47 - IP Address Spoofing in getIP()

wpDiscuz before 7.6.47 contains an IP spoofing vulnerability in the getIP() function that allows attackers to bypass IP-based rate limiting and ban enforcement by trusting untrusted HTTP headers. Attackers can set HTTP_CLIENT_IP or HTTP_X_FORWARDED_FOR headers to spoof their IP address and circumve…

πŸ“… Published: March 13, 2026, 1:18 a.m. πŸ”„ Last Modified: March 23, 2026, 9:59 a.m.

8.7

CVSS4.0

CVE-2026-22199 - Voltronic Power SNMP Web Pro 1.1 Path Traversal via upload.cgi

Voltronic Power SNMP Web Pro version 1.1 contains a pre-authentication path traversal vulnerability in the upload.cgi endpoint that allows unauthenticated attackers to read arbitrary files on the device filesystem by supplying directory traversal sequences in the params parameter. Attackers can exp…

πŸ“… Published: March 13, 2026, 1:18 a.m. πŸ”„ Last Modified: April 23, 2026, 1:16 p.m.

9.2

CVSS4.0

CVE-2026-22193 - wpDiscuz before 7.6.47 - SQL Injection in getAllSubscriptions()

wpDiscuz before 7.6.47 contains an SQL injection vulnerability in the getAllSubscriptions() function where string parameters lack proper quote escaping in SQL queries. Attackers can inject malicious SQL code through email, activation_key, subscription_date, and imported_from parameters to manipulat…

πŸ“… Published: March 13, 2026, 1:18 a.m. πŸ”„ Last Modified: March 23, 2026, 9:59 a.m.

8.8

CVSS4.0

CVE-2026-22192 - Voltronic Power SNMP Web Pro 1.1 Authentication Bypass via localStorage

Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to access privileged management functions by manipulating browser localStorage values. Attackers can modify client-side authentication state to bypass server-side access co…

πŸ“… Published: March 13, 2026, 1:18 a.m. πŸ”„ Last Modified: April 22, 2026, 7:17 p.m.

5.1

CVSS4.0

CVE-2026-22191 - Beghelli Sicuro24 SicuroWeb AngularJS Template Injection

Beghelli Sicuro24 SicuroWeb contains a template injection vulnerability that allows attackers to inject arbitrary AngularJS expressions by exploiting improper rendering of untrusted input in AngularJS template contexts. Attackers can inject malicious expressions that are compiled and executed by th…

πŸ“… Published: March 13, 2026, 1:18 a.m. πŸ”„ Last Modified: April 22, 2026, 7:17 p.m.

5.3

CVSS4.0

CVE-2026-22183 - wpDiscuz before 7.6.47 - Stored Cross-Site Scripting in Inline Comment Preview

wpDiscuz before 7.6.47 contains a stored cross-site scripting vulnerability in the inline comment preview functionality that allows authenticated users to inject malicious scripts by submitting comments with unescaped content. Attackers with unfiltered_html capabilities can inject JavaScript direct…

πŸ“… Published: March 13, 2026, 1:18 a.m. πŸ”„ Last Modified: March 23, 2026, 10 a.m.

8.7

CVSS4.0

CVE-2026-22182 - wpDiscuz before 7.6.47 - Unauthenticated Email Notification Flood via wpdCheckNotificationType

wpDiscuz before 7.6.47 contains an unauthenticated denial of service vulnerability that allows anonymous users to trigger mass notification emails by exploiting the checkNotificationType() function. Attackers can repeatedly call the wpdiscuz-ajax.php endpoint with arbitrary postId and comment_id pa…

πŸ“… Published: March 13, 2026, 1:17 a.m. πŸ”„ Last Modified: March 23, 2026, 10 a.m.

7.7

CVSS3.1

CVE-2026-3312 - pagure: Pagure: Information disclosure via unrestricted reStructuredText include directive

A flaw was found in Pagure's rendering engine for reStructuredText (RST) files. An authenticated user can exploit an unrestricted `.. include::` directive within RST files to read arbitrary internal files from the server hosting Pagure. This information disclosure vulnerability allows unauthorized …

πŸ“… Published: March 13, 2026, midnight πŸ”„ Last Modified: March 18, 2026, 12:13 p.m.

6.7

CVSS3.1

CVE-2026-4105 - Systemd: systemd: privilege escalation via improper access control in registermachine d-bus method

A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a …

πŸ“… Published: March 13, 2026, midnight πŸ”„ Last Modified: April 30, 2026, 4:59 p.m.
Total resulsts: 347731
Page 1000 of 34,774
Β« previous page Β» next page
Filters