8.7

CVSS4.0

CVE-2026-1874 - Denial-of-Service (DoS) vulnerability in Ethernet function of MELSEC iQ-F Series EtherNet/IP module…

Always-Incorrect Control Flow Implementation vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP versions 1.106 and prior and Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-EIP EtherNet/IP Module FX5-EIP versions 1.000 and prior allows…

📅 Published: March 3, 2026, 6:46 a.m. 🔄 Last Modified: May 4, 2026, 2:27 p.m.

8.7

CVSS4.0

CVE-2025-12345 - LLM-Claw Agent Deployment initiate.c agent_deploy_init buffer overflow

A security vulnerability has been detected in LLM-Claw 0.1.0/0.1.1/0.1.1a/0.1.1a-p1. The affected element is the function agent_deploy_init of the file /agents/deploy/initiate.c of the component Agent Deployment. Such manipulation leads to buffer overflow. It is possible to launch the attack remote…

📅 Published: March 3, 2026, 6:32 a.m. 🔄 Last Modified: April 22, 2026, 9:26 p.m.

5.7

CVSS4.0

CVE-2025-15595 - Privilege escalation via dll hijacking in Inno Setup

Privilege escalation via dll hijacking in Inno Setup 6.2.1 and ealier versions.

📅 Published: March 3, 2026, 6:13 a.m. 🔄 Last Modified: March 13, 2026, 5:55 p.m.

5.1

CVSS4.0

CVE-2026-3455 - mailparser Cross‑Site Scripting via textToHtml URL Sanitization

Versions of the package mailparser before 3.9.3 are vulnerable to Cross-site Scripting (XSS) via the textToHtml() function due to the improper sanitisation of URLs in the email content. An attacker can execute arbitrary scripts in victim browsers by adding extra quote " to the URL with embedded ma…

📅 Published: March 3, 2026, 5 a.m. 🔄 Last Modified: April 17, 2026, 1:30 p.m.

4.8

CVSS4.0

CVE-2026-3449 - @tootallnate/once: @tootallnate/once: Denial of Service due to incorrect control flow scoping with …

Versions of the package @tootallnate/once before 3.0.1 are vulnerable to Incorrect Control Flow Scoping in promise resolving when AbortSignal option is used. The Promise remains in a permanently pending state after the signal is aborted, causing any await or .then() usage to hang indefinitely. This…

📅 Published: March 3, 2026, 5 a.m. 🔄 Last Modified: April 17, 2026, 1:30 p.m.

9.8

CVSS3.1

CVE-2026-1492 - User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership Regis…

The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including, 5.1.2. This is due to the plugin accepting a user…

📅 Published: March 3, 2026, 4:33 a.m. 🔄 Last Modified: April 22, 2026, 9:26 p.m.

5.6

CVSS3.1

CVE-2026-20801 - Cleartext Transmission of Live Video Streams via Gallagher VMS Integrations

Cleartext Transmission of Sensitive Information (CWE-319) in a component used in the Gallagher Hanwha VMS and Gallagher NxWitness VMS integrations allows unprivileged users with local network access to view live video streams. This issue affects all versions of Gallagher NxWitness VMS integrat…

📅 Published: March 3, 2026, 2:41 a.m. 🔄 Last Modified: April 16, 2026, 2:15 p.m.

2.5

CVSS3.1

CVE-2026-20757 - Improper Locking in Gallagher Morpho Integration Causes Limited Denial-of-Service

Improper Locking vulnerability (CWE-667) in Gallagher Morpho integration allows a privileged operator to cause a limited denial-of-service in the Command Centre Server. This issue affects Command Centre Server: 9.40 prior to vEL9.40.1976(MR1), 9.30 prior to vEL9.30.3382 (MR4), 9.20 prior to vE…

📅 Published: March 3, 2026, 2:40 a.m. 🔄 Last Modified: April 16, 2026, 2:15 p.m.

5.7

CVSS3.1

CVE-2025-47147 -

Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow an attacker with access to a logged-in Operator's mobile device to extract the session token and exploit access for a limited duration. This issue affects Command Centre Mobi…

📅 Published: March 3, 2026, 2:39 a.m. 🔄 Last Modified: March 4, 2026, 2:54 p.m.

6.5

CVSS3.1

CVE-2026-1487 - LatePoint <= 5.2.7 - Authenticated (Administrator+) SQL Injection via JSON Import

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to SQL Injection via the JSON Import in all versions up to, and including, 5.2.7 due to insufficient validation on the user-supplied JSON data. This makes it possible for authenticated attackers,…

📅 Published: March 3, 2026, 1:21 a.m. 🔄 Last Modified: April 22, 2026, 9:26 p.m.
Total resulsts: 349182
Page 1364 of 34,919
« previous page » next page
Filters