5.3

CVSS3.1

CVE-2026-1305 - Japanized for WooCommerce <= 2.8.4 - Missing Authorization to Unauthenticated Paidy Order Manipulat…

The Japanized for WooCommerce plugin for WordPress is vulnerable to Improper Authentication in versions up to, and including, 2.8.4. This is due to a flawed permission check in the `paidy_webhook_permission_check` function that unconditionally returns `true` when the webhook signature header is omi…

📅 Published: Feb. 27, 2026, 9:23 a.m. 🔄 Last Modified: April 15, 2026, 6:15 p.m.

6.4

CVSS3.1

CVE-2025-14142 - Electric Enquiries <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'button' S…

The Electric Enquiries plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button' parameter of the electric-enquiry shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack…

📅 Published: Feb. 27, 2026, 9:23 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-10938 - OVRI Payment 1.7.0 - Malicious .htaccess directive

The OVRI Payment plugin for WordPress contains malicious .htaccess files in version 1.7.0. The files contain directives to prevent the execution of certain scripts while allowing execution of known malicious PHP files. If moved outside of the plugin's directory, they may interfere with the proper f…

📅 Published: Feb. 27, 2026, 9:23 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2026-21660 - Johnson Controls-Frick Quantum HD-Hardcoded Email Credentials Saved as Plaintext in Firmware

Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, and potential misuse or system compromise This issue affects Frick…

📅 Published: Feb. 27, 2026, 9:18 a.m. 🔄 Last Modified: April 17, 2026, 2:15 p.m.

8.7

CVSS4.0

CVE-2026-21659 - Johnson Controls -Frick Quantum HD-Unauthenticated Remote Code Execution and Information Disclosure…

Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion (LFI) vulnerability in Johnson Controls Frick Controls Quantum HD allow an unauthenticated attacker to execute arbitrary code on the affected device, leading to full system compromise. This issue affects F…

📅 Published: Feb. 27, 2026, 9:08 a.m. 🔄 Last Modified: April 18, 2026, 10:30 a.m.

8.8

CVSS4.0

CVE-2026-21658 - Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code Execution

Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the securit…

📅 Published: Feb. 27, 2026, 8:59 a.m. 🔄 Last Modified: April 17, 2026, 2:15 p.m.

8.8

CVSS4.0

CVE-2026-21657 - Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code Execution

Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device before authentication occu…

📅 Published: Feb. 27, 2026, 8:54 a.m. 🔄 Last Modified: April 18, 2026, 10:30 a.m.

8.8

CVSS4.0

CVE-2026-21656 - Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code Execution

Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device before authentication occu…

📅 Published: Feb. 27, 2026, 8:47 a.m. 🔄 Last Modified: April 16, 2026, 3:30 p.m.

6.5

CVSS3.1

CVE-2026-1627 - Weak MAC Algorithms Compromise SSH Integrity on SICK LMS1000 and MRS1000

An attacker may exploit the use of outdated and weak MAC algorithms in the device’s SSH service to potentially compromise the integrity of the SSH session, allowing manipulation of transmitted data if the attacker can interact with the network traffic.

📅 Published: Feb. 27, 2026, 8:43 a.m. 🔄 Last Modified: April 16, 2026, 3:30 p.m.

6.5

CVSS3.1

CVE-2026-1626 - Weak CBC Cipher Suites Allow Possible Compromise of SSH Communication

An attacker may exploit the use of weak CBC-based cipher suites in the device’s SSH service to potentially observe or manipulate parts of the encrypted SSH communication, if they are able to intercept or interact with the network traffic.

📅 Published: Feb. 27, 2026, 8:40 a.m. 🔄 Last Modified: April 16, 2026, 3:30 p.m.
Total resulsts: 349182
Page 1406 of 34,919
« previous page » next page
Filters