9.3

CVSS4.0

CVE-2026-32311 - Command Injection and Docker container escape allows root on host machine

Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Flowsint allows a user to create investigations, which are used to manage sketches and analyses. Sketches have controllable graphs, which are comprised of nodes and rela…

📅 Published: April 20, 2026, 7:56 p.m. 🔄 Last Modified: April 23, 2026, 6:41 p.m.

8.1

CVSS3.1

CVE-2026-5478 - Everest Forms <= 3.4.4 - Unauthenticated Arbitrary File Read and Deletion via Upload Field 'old_fil…

The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in all versions up to, and including, 3.4.4. This is due to the plugin trusting attacker-controlled old_files data from public form submissions as legitimate server-side upload state, and converting attacker-su…

📅 Published: April 20, 2026, 7:27 p.m. 🔄 Last Modified: April 22, 2026, 8:22 p.m.

7.7

CVSS4.0

CVE-2026-32135 - NanoMQ has Heap Buffer Overflow in URI Parameter Parsing

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.11 have a remotely triggerable heap buffer overflow in the `uri_param_parse` function of NanoMQ's REST API. The vulnerability occurs due to an off-by-one error when allocating memory for query parameter key…

📅 Published: April 20, 2026, 7:23 p.m. 🔄 Last Modified: April 22, 2026, 5:32 p.m.

5.7

CVSS4.0

CVE-2026-6550 - Key commitment policy bypass via shared key cache in AWS Encryption SDK for Python

Cryptographic algorithm downgrade in the caching layer of Amazon AWS Encryption SDK for Python before version 3.3.1 and before version 4.0.5 might allow an authenticated local threat actor to bypass key commitment policy enforcement via a shared key cache, resulting in ciphertext that can be decry…

📅 Published: April 20, 2026, 7:20 p.m. 🔄 Last Modified: April 22, 2026, 11:47 a.m.

9.2

CVSS4.0

CVE-2026-6257 - Vvveb CMS v1.0.8 Remote Code Execution via Media Management

Vvveb CMS v1.0.8 contains a remote code execution vulnerability in its media management functionality where a missing return statement in the file rename handler allows authenticated attackers to rename files to blocked extensions .php or .htaccess. Attackers can exploit this logic flaw by first up…

📅 Published: April 20, 2026, 7:09 p.m. 🔄 Last Modified: April 22, 2026, 11:47 a.m.

8.1

CVSS3.1

CVE-2026-6248 - wpForo Forum <= 3.0.5 - Authenticated (Subscriber+) Arbitrary File Deletion via Custom Profile Fiel…

The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.5. This is due to two compounding flaws: the Members::update() method does not validate or restrict the value of file-type custom profile fields, allowing authenticated users to store …

📅 Published: April 20, 2026, 6:31 p.m. 🔄 Last Modified: April 22, 2026, 8:22 p.m.

4.5

CVSS3.1

CVE-2026-6060 - Possible DoS via SQL Box

A vulnerability in the SQL Box in the admin interface of OTRS leads to an uncontrolled resource consumption leading to a DoS against the webserver. will be killed by the systemThis issue affects OTRS:  * 7.0.X * 8.0.X * 2023.X * 2024.X * 2025.X * 2026.X before 2026.3.X

📅 Published: April 20, 2026, 6:20 p.m. 🔄 Last Modified: April 22, 2026, 11:47 a.m.

6.3

CVSS4.0

CVE-2026-41389 - OpenClaw 2026.4.7 < 2026.4.15 - Arbitrary File Read via Unvalidated Tool-Result Media Paths

OpenClaw versions 2026.4.7 before 2026.4.15 fail to enforce local-root containment on tool-result media paths, allowing arbitrary local and UNC file access. Attackers can craft malicious tool-result media references to trigger host-side file reads or Windows network path access, potentially disclos…

📅 Published: April 20, 2026, 5:48 p.m. 🔄 Last Modified: April 20, 2026, 8:45 p.m.

4.8

CVSS4.0

CVE-2026-23753 - GFI HelpDesk < 4.99.9 Stored XSS via charset Parameter

GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the language management functionality where the charset POST parameter is passed directly to SWIFT_Language::Create() without HTML sanitization and subsequently rendered unsanitized by View_Language.RenderGrid(). An …

📅 Published: April 20, 2026, 5:33 p.m. 🔄 Last Modified: April 22, 2026, 11:47 a.m.

4.8

CVSS4.0

CVE-2026-23752 - GFI HelpDesk < 4.99.9 Stored XSS via companyname Parameter

GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the template group creation and editing functionality that allows authenticated administrators to inject arbitrary JavaScript by manipulating the companyname POST parameter without HTML sanitization. Attackers can in…

📅 Published: April 20, 2026, 5:33 p.m. 🔄 Last Modified: April 22, 2026, 11:47 a.m.
Total resulsts: 346671
Page 134 of 34,668
« previous page » next page
Filters