9.8

CVSS3.1

CVE-2025-12981 - Listee <= 1.1.6 - Unauthenticated Privilege Escalation

The Listee theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.6. This is due to a broken validation check in the bundled listee-core plugin's user registration function that fails to properly sanitize the user_role parameter. This makes it possible f…

πŸ“… Published: Feb. 27, 2026, 6:43 a.m. πŸ”„ Last Modified: April 21, 2026, 4 p.m.

6.4

CVSS3.1

CVE-2025-14149 - Xpro Addons β€” 140+ Widgets for Elementor <= 1.4.24 - Authenticated (Contributor+) Stored Cross-Site…

The Xpro Addons β€” 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Scroller widget box link attribute in all versions up to, and including, 1.4.24 due to insufficient input sanitization and output escaping on user supplied attribute…

πŸ“… Published: Feb. 27, 2026, 6:43 a.m. πŸ”„ Last Modified: April 21, 2026, 4 p.m.

6.4

CVSS3.1

CVE-2025-14040 - Automotive Car Dealership Business WordPress Theme <= 13.4 - Authenticated (Contributor+) Stored Cr…

The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Call to Action' custom fields in all versions up to, and including, 13.4. This is due to insufficient input sanitization and output escaping on user-supplied attributes in the …

πŸ“… Published: Feb. 27, 2026, 6:43 a.m. πŸ”„ Last Modified: April 22, 2026, 3:30 p.m.

5.3

CVSS4.0

CVE-2026-3302 - SourceCodester Doctor Appointment System Sign Up register.php cross site scripting

A weakness has been identified in SourceCodester Doctor Appointment System 1.0. Affected by this issue is some unknown functionality of the file /register.php of the component Sign Up Page. Executing a manipulation of the argument Email can lead to cross site scripting. The attack can be launched r…

πŸ“… Published: Feb. 27, 2026, 6:02 a.m. πŸ”„ Last Modified: April 16, 2026, 3:45 p.m.

5.4

CVSS4.0

CVE-2026-27653 -

The installers for multiple products provided by Soliton Systems K.K. contain an issue with incorrect default permissions, which may allow arbitrary code to be executed with SYSTEM privileges.

πŸ“… Published: Feb. 27, 2026, 5:39 a.m. πŸ”„ Last Modified: April 17, 2026, 2:15 p.m.

9.3

CVSS4.0

CVE-2026-3301 - Totolink N300RH Web Management cstecgi.cgi setWebWlanIdx os command injection

A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument webWlanIdx results in os command injection. …

πŸ“… Published: Feb. 27, 2026, 5:32 a.m. πŸ”„ Last Modified: April 17, 2026, 2:15 p.m.

4.8

CVSS4.0

CVE-2026-3293 - snowflakedb snowflake-jdbc JDBC URL SdkProxyRoutePlanner.java SdkProxyRoutePlanner redos

A weakness has been identified in snowflakedb snowflake-jdbc up to 4.0.1. Impacted is the function SdkProxyRoutePlanner of the file src/main/java/net/snowflake/client/internal/core/SdkProxyRoutePlanner.java of the component JDBC URL Handler. Executing a manipulation of the argument nonProxyHosts ca…

πŸ“… Published: Feb. 27, 2026, 5:32 a.m. πŸ”„ Last Modified: April 16, 2026, 3:45 p.m.

7.4

CVSS3.1

CVE-2026-28372 - Privilege Escalation via Telnetd and Systemd Credentials

telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-linux in release 2.40. This is related to client control over the CREDENTIALS_DIRECTORY environment variable, and requir…

πŸ“… Published: Feb. 27, 2026, 5:28 a.m. πŸ”„ Last Modified: April 16, 2026, 3:45 p.m.

5.3

CVSS4.0

CVE-2026-3292 - jizhiCMS Batch Model.php findAll sql injection

A security vulnerability has been detected in jizhiCMS up to 2.5.6. Affected is the function findAll in the library frphp/lib/Model.php of the component Batch Interface. The manipulation of the argument data leads to sql injection. The attack is possible to be carried out remotely. The exploit has …

πŸ“… Published: Feb. 27, 2026, 5:02 a.m. πŸ”„ Last Modified: April 17, 2026, 2:15 p.m.

9.1

CVSS3.1

CVE-2026-28370 -

In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger code execution on the Vitrage service host as the user the Vitrage service runs under. This may result in unauthorized access to the host and further compromise o…

πŸ“… Published: Feb. 27, 2026, 4:56 a.m. πŸ”„ Last Modified: April 17, 2026, 2:15 p.m.
Total resulsts: 349182
Page 1408 of 34,919
Β« previous page Β» next page
Filters