6.7

CVSS3.1

CVE-2026-21425 - Incorrect Privilege Assignment Enables Local Privilege Escalation in Dell PowerScale OneFS

Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an incorrect privilege assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

πŸ“… Published: March 4, 2026, 12:15 p.m. πŸ”„ Last Modified: April 16, 2026, 1:45 p.m.

6.6

CVSS4.0

CVE-2026-24732 - Improper permission checks in Extension:NSFileRepo

Files or Directories Accessible to External Parties, Incorrect Permission Assignment for Critical Resource vulnerability in Hallo Welt! GmbH BlueSpice (Extension:NSFileRepo modules) allows Accessing Functionality Not Properly Constrained by ACLs, Bypassing Electronic Locks and Access Controls.This …

πŸ“… Published: March 4, 2026, 12:13 p.m. πŸ”„ Last Modified: April 16, 2026, 1:45 p.m.

4.3

CVSS3.1

CVE-2026-3058 - Seraphinite Accelerator <= 2.28.14 - Authenticated (Subscriber+) Exposure of Sensitive Information …

The Seraphinite Accelerator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.28.14 via the `seraph_accel_api` AJAX action with `fn=GetData`. This is due to the `OnAdminApi_GetData()` function not performing any capability checks. This make…

πŸ“… Published: March 4, 2026, 11:22 a.m. πŸ”„ Last Modified: April 15, 2026, 5 p.m.

4.3

CVSS3.1

CVE-2026-3056 - Seraphinite Accelerator <= 2.28.14 - Missing Authorization to Authenticated (Subscriber+) Log Clear…

The Seraphinite Accelerator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `seraph_accel_api` AJAX action with `fn=LogClear` in all versions up to, and including, 2.28.14. This makes it possible for authenticated attackers, with Subs…

πŸ“… Published: March 4, 2026, 11:22 a.m. πŸ”„ Last Modified: April 22, 2026, 9:26 p.m.

6.5

CVSS3.1

CVE-2026-1674 - Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1…

The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization within the save_gutena_forms_schema() function in all versions up to, and including, 1.6.0. This ma…

πŸ“… Published: March 4, 2026, 11:22 a.m. πŸ”„ Last Modified: April 22, 2026, 9:26 p.m.

6.4

CVSS3.1

CVE-2026-2355 - My Calendar – Accessible Event Manager <= 3.7.3 - Authenticated (Contributor+) Stored Cross-Site Sc…

The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `template` attribute of the `[my_calendar_upcoming]` shortcode in all versions up to, and including, 3.7.3. This is due to the use of `stripcslashes()` on user-supplied shortcode att…

πŸ“… Published: March 4, 2026, 11:22 a.m. πŸ”„ Last Modified: April 22, 2026, 9:26 p.m.

6.1

CVSS3.1

CVE-2026-1706 - All-in-One Video Gallery <= 4.7.1 - Reflected Cross-Site Scripting via 'vi' Parameter

The All-in-One Video Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'vi' parameter in all versions up to, and including, 4.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary w…

πŸ“… Published: March 4, 2026, 9:24 a.m. πŸ”„ Last Modified: April 22, 2026, 9:26 p.m.

7.5

CVSS3.1

CVE-2023-7337 - JS Help Desk – AI-Powered Support & Ticketing System 2.8.2 - Unauthenticated SQL Injection via 'js-…

The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the 'js-support-ticket-token-tkstatus' cookie in version 2.8.2 due to an incomplete fix for CVE-2023-50839 where a second sink was left with insufficient escaping on the user supplied va…

πŸ“… Published: March 4, 2026, 9:24 a.m. πŸ”„ Last Modified: April 22, 2026, 9:26 p.m.

4.9

CVSS3.1

CVE-2026-3439 - SonicOS Certificate Handling Buffer Overflow Enables Firewall Crash

A post-authentication Stack-based Buffer Overflow vulnerability in SonicOS certificate handling allows a remote attacker to crash a firewall.

πŸ“… Published: March 4, 2026, 9:19 a.m. πŸ”„ Last Modified: April 17, 2026, 1:15 p.m.

9.5

CVSS4.0

CVE-2026-27441 - PDF Password CMDi

SEPPmail Secure Email Gateway before version 15.0.1 insufficiently neutralizes the PDF encryption password, allowing OS command execution.

πŸ“… Published: March 4, 2026, 8:49 a.m. πŸ”„ Last Modified: April 17, 2026, 1:15 p.m.
Total resulsts: 349182
Page 1349 of 34,919
Β« previous page Β» next page
Filters