8.8

CVSS3.1

CVE-2026-27952 - Agenta has Python Sandbox Escape, Leading to Remote Code Execution (RCE)

Agenta is an open-source LLMOps platform. In Agenta-API prior to version 0.48.1, a Python sandbox escape vulnerability existed in Agenta's custom code evaluator. Agenta used RestrictedPython as a sandboxing mechanism for user-supplied evaluator code, but incorrectly whitelisted the `numpy` package โ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 1:38 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 2:45 p.m.

5.4

CVSS3.1

CVE-2026-27948 - Copyparty vulnerable to eflected cross-site scripting via setck parameter

Copyparty is a portable file server. In versions prior to 1.20.9, an XSS allows for reflected cross-site scripting via URL-parameter `?setck=...`. Version 1.20.9 fixes the issue.

๐Ÿ“… Published: Feb. 26, 2026, 1:32 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 5:45 p.m.

6.5

CVSS3.1

CVE-2026-27943 - OpenEMR's Eye Exam View Trusts form_id Without Verifying Patient/Encounter Ownership

OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, the eye exam (eye_mag) view loads data by `form_id` (or equivalent) without verifying that the form belongs to the current userโ€™s patient/encounter contextโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 1:30 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 10:30 a.m.

4.4

CVSS3.1

CVE-2026-2499 - Custom Logo <= 2.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via Logo Path Settiโ€ฆ

The Custom Logo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and aboโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 1:24 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2026-2029 - Livemesh Addons for Beaver Builder <= 3.9.2 - Authenticated (Contributor+) Stored Cross-Site Scriptโ€ฆ

The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[labb_pricing_item]` shortcode's `title` and `value` attributes in all versions up to, and including, 3.9.2 due to insufficient input sanitization and output escaping. Specifically, theโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 1:24 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.4

CVSS3.1

CVE-2026-2489 - TP2WP Importer <= 1.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Watched domโ€ฆ

The TP2WP Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Watched domains' textarea on the attachment importer settings page in all versions up to, and including, 1.1. This is due to insufficient input sanitization and output escaping when domains are saved via Aโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 1:24 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 8:15 p.m.

4.4

CVSS3.1

CVE-2026-2498 - WP Social Meta <= 1.0.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via Settings

The WP Social Meta plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions anโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 1:24 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, midnight

7.5

CVSS3.1

CVE-2026-1557 - WP Responsive Images <= 1.0 - Unauthenticated Path Traversal to Arbitrary File Read via src

The WP Responsive Images plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0 via the 'src' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

๐Ÿ“… Published: Feb. 26, 2026, 1:24 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 11:45 p.m.

6.1

CVSS3.1

CVE-2026-2506 - EM Cost Calculator <= 2.3.1 - Unauthenticated Stored Cross-Site Scripting via 'customer_name'

The EM Cost Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.1. This is due to the plugin storing attacker-controlled 'customer_name' data and rendering it in the admin customer list without output escaping. This makes it possible foโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 1:24 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 8:15 p.m.

2.7

CVSS4.0

CVE-2026-27942 - fast-xml-parser has stack overflow in XMLBuilder with preserveOrder

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. Prior to version 5.3.8, the application crashes with stack overflow when user use XML builder with `preserveOrder:true`. Version 5.3.8 fixes the issue. Asโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 1:22 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 2:45 p.m.
Total resulsts: 347246
Page 1235 of 34,725
ยซ previous page ยป next page
Filters