7.3

CVSS3.1

CVE-2026-42377 - WordPress SureForms Pro plugin <= 2.8.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in Brainstorm Force SureForms Pro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms Pro: from n/a through 2.8.0.

๐Ÿ“… Published: April 29, 2026, 7:27 a.m. ๐Ÿ”„ Last Modified: April 29, 2026, 1:16 p.m.

6.9

CVSS4.0

CVE-2026-21023 -

Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local attackers to modify the installation restriction of specific application.

๐Ÿ“… Published: April 29, 2026, 4:46 a.m. ๐Ÿ”„ Last Modified: April 29, 2026, 4:46 a.m.

7.1

CVSS3.1

CVE-2026-35155 - Authenticated Lowโ€‘Privileged Attacker Can Gain Elevated Access in Dell iDRAC10 via Race Condition

Dell iDRAC10, versions 1.20.70.50 and 1.30.05.10, contains an Insufficiently Protected Credentials vulnerability. A race condition vulnerability exists that could allow an authenticated lowโ€‘privileged attacker to gain elevated access.

๐Ÿ“… Published: April 29, 2026, 3:50 a.m. ๐Ÿ”„ Last Modified: May 1, 2026, 5:40 p.m.

4.3

CVSS3.1

CVE-2026-23773 - SSRF Vulnerability in Dell Disk Library for Mainframe

Dell Disk Library for Mainframe, version(s) DLm 8700/2700 contain(s) a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.

๐Ÿ“… Published: April 29, 2026, 3:39 a.m. ๐Ÿ”„ Last Modified: April 29, 2026, 1:55 p.m.

7.2

CVSS3.1

CVE-2026-42615 - Crossโ€‘Site Scripting in CyberChefโ€™s Base64 Offset Feature

GCHQ CyberChef before 11.0.0 allows XSS via Show Base64 offsets, as demonstrated by the /#recipe=Show_Base64_offsets('%3Cscript substring.

๐Ÿ“… Published: April 29, 2026, 2:55 a.m. ๐Ÿ”„ Last Modified: April 29, 2026, 1:14 p.m.

7.5

CVSS3.1

CVE-2026-36837 -

TOTOLINK A3002RU V3 <= V3.0.0-B20220304.1804 was discovered to contain a stack-based buffer overflow via the hostname parameter in the formMapDelDevice function.

๐Ÿ“… Published: April 29, 2026, midnight ๐Ÿ”„ Last Modified: April 30, 2026, 2:15 p.m.

3.7

CVSS3.1

CVE-2026-6276 - curl: libcurl: Information disclosure due to cookie leak when reusing connections with custom Host โ€ฆ

A flaw was found in libcurl. This vulnerability allows for information disclosure when a custom `Host:` header is used in an initial HTTP request, and a subsequent request reuses the same connection without specifying a new `Host:` header. This can lead to libcurl incorrectly sending cookies intendโ€ฆ

๐Ÿ“… Published: April 29, 2026, midnight ๐Ÿ”„ Last Modified: May 1, 2026, 1:30 a.m.

6.5

CVSS3.1

CVE-2026-38993 - Cockpit: Cockpit: Arbitrary file write via directory traversal in Buckets component

Cockpit 2.13.5 and earlier is vulnerable to directory traversal via the Buckets component. This vulnerability allows authenticated attackers to write files to arbitrary locations within the uploads directory or overwrite assets with malicious versions.

๐Ÿ“… Published: April 29, 2026, midnight ๐Ÿ”„ Last Modified: April 30, 2026, 2:15 p.m.

8.8

CVSS3.1

CVE-2026-38991 - Authenticated File Rename Allows PHP Execution in Cockpit CMS

Cockpit 2.13.5 and earlier is affected by a misconfiguration within the Bucket component _isFileTypeAllowed function where a specially crafted filename bypasses an extension filter. This allows an authenticated attacker to rename arbitrary files with the .php file extension enabling arbitrary code โ€ฆ

๐Ÿ“… Published: April 29, 2026, midnight ๐Ÿ”„ Last Modified: May 2, 2026, 12:45 a.m.

5.3

CVSS3.1

CVE-2026-6253 - curl: curl: Proxy credential disclosure via redirects to unauthenticated proxies

A flaw was found in curl. When curl is configured to use distinct proxies for different URL schemes, a redirect from a URL using an authenticated proxy to one using an unauthenticated proxy can inadvertently expose the initial proxy's credentials. This improper credential management (CWE-522) may aโ€ฆ

๐Ÿ“… Published: April 29, 2026, midnight ๐Ÿ”„ Last Modified: May 1, 2026, 1:30 a.m.
Total resulsts: 348147
Page 106 of 34,815
ยซ previous page ยป next page
Filters