8.1

CVSS3.1

CVE-2026-6248 - wpForo Forum <= 3.0.5 - Authenticated (Subscriber+) Arbitrary File Deletion via Custom Profile Fiel…

The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.5. This is due to two compounding flaws: the Members::update() method does not validate or restrict the value of file-type custom profile fields, allowing authenticated users to store …

📅 Published: April 20, 2026, 6:31 p.m. 🔄 Last Modified: April 21, 2026, 5:35 p.m.

4.5

CVSS3.1

CVE-2026-6060 - Possible DoS via SQL Box

A vulnerability in the SQL Box in the admin interface of OTRS leads to an uncontrolled resource consumption leading to a DoS against the webserver. will be killed by the systemThis issue affects OTRS:  * 7.0.X * 8.0.X * 2023.X * 2024.X * 2025.X * 2026.X before 2026.3.X

📅 Published: April 20, 2026, 6:20 p.m. 🔄 Last Modified: April 22, 2026, 11:47 a.m.

6.3

CVSS4.0

CVE-2026-41389 - OpenClaw 2026.4.7 < 2026.4.15 - Arbitrary File Read via Unvalidated Tool-Result Media Paths

OpenClaw versions 2026.4.7 before 2026.4.15 fail to enforce local-root containment on tool-result media paths, allowing arbitrary local and UNC file access. Attackers can craft malicious tool-result media references to trigger host-side file reads or Windows network path access, potentially disclos…

📅 Published: April 20, 2026, 5:48 p.m. 🔄 Last Modified: April 20, 2026, 5:51 p.m.

4.8

CVSS4.0

CVE-2026-23753 - GFI HelpDesk < 4.99.9 Stored XSS via charset Parameter

GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the language management functionality where the charset POST parameter is passed directly to SWIFT_Language::Create() without HTML sanitization and subsequently rendered unsanitized by View_Language.RenderGrid(). An …

📅 Published: April 20, 2026, 5:33 p.m. 🔄 Last Modified: April 22, 2026, 11:47 a.m.

4.8

CVSS4.0

CVE-2026-23752 - GFI HelpDesk < 4.99.9 Stored XSS via companyname Parameter

GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the template group creation and editing functionality that allows authenticated administrators to inject arbitrary JavaScript by manipulating the companyname POST parameter without HTML sanitization. Attackers can in…

📅 Published: April 20, 2026, 5:33 p.m. 🔄 Last Modified: April 22, 2026, 11:47 a.m.

5.1

CVSS4.0

CVE-2026-23756 - GFI HelpDesk < 4.99.9 Stored XSS via Troubleshooter Step Subject

GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the Troubleshooter module where the subject POST parameter is not sanitized in Controller_Step.InsertSubmit() and EditSubmit() before being rendered by View_Step.RenderViewSteps(). An authenticated staff member can i…

📅 Published: April 20, 2026, 5:30 p.m. 🔄 Last Modified: April 22, 2026, 11:47 a.m.

6.4

CVSS4.0

CVE-2026-23758 - GFI HelpDesk < 4.99.9 Stored XSS via editsubject Parameter

GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the ticket subject field that allows authenticated staff members to inject malicious JavaScript by manipulating the editsubject POST parameter. Attackers can inject XSS payloads through inadequate sanitization in Con…

📅 Published: April 20, 2026, 5:30 p.m. 🔄 Last Modified: April 22, 2026, 11:47 a.m.

5.1

CVSS4.0

CVE-2026-23757 - GFI HelpDesk < 4.99.10 Stored XSS via Reports Module

GFI HelpDesk before 4.99.10 contains a stored cross-site scripting vulnerability in the Reports module where the title parameter is passed directly to SWIFT_Report::Create() without HTML sanitization. Attackers can inject arbitrary JavaScript into the report title field when creating or editing a r…

📅 Published: April 20, 2026, 5:27 p.m. 🔄 Last Modified: April 22, 2026, 11:47 a.m.

6.9

CVSS4.0

CVE-2026-6662 - ericc-ch copilot-api Token Endpoint server.ts cors cross-domain policy

A vulnerability was found in ericc-ch copilot-api up to 0.7.0. The impacted element is the function cors of the file src/server.ts of the component Token Endpoint. Performing a manipulation results in permissive cross-domain policy with untrusted domains. It is possible to initiate the attack remot…

📅 Published: April 20, 2026, 5 p.m. 🔄 Last Modified: April 22, 2026, 11:47 a.m.

6.3

CVSS3.1

CVE-2026-35154 - IDRAC Privilege Escalation via Improper Access Control

Dell PowerProtect Data Domain appliances, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper privilege management vulnerability in IDRAC. A high privileged attacker with local access could pote…

📅 Published: April 20, 2026, 4:50 p.m. 🔄 Last Modified: April 22, 2026, 3:56 a.m.
Total resulsts: 346515
Page 119 of 34,652
« previous page » next page
Filters