5.3

CVSS3.1

CVE-2026-1558 - WP Recipe Maker <= 10.3.2 - Insecure Direct Object Reference to Unauthenticated Arbitrary Post Meta…

The WP Recipe Maker plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) in versions up to, and including, 10.3.2. This is due to the /wp-json/wp-recipe-maker/v1/integrations/instacart REST API endpoint's permission_callback being set to __return_true and a lack of subse…

πŸ“… Published: Feb. 27, 2026, 4:33 a.m. πŸ”„ Last Modified: April 15, 2026, 8:15 p.m.

5.3

CVSS4.0

CVE-2026-3289 - Sanluan PublicCMS Template Cache Generation TemplateCacheComponent.java saveMetadata path traversal

A weakness has been identified in Sanluan PublicCMS 6.202506.d. This impacts the function saveMetadata of the file TemplateCacheComponent.java of the component Template Cache Generation. Executing a manipulation can lead to path traversal. The attack can be executed remotely. The exploit has been m…

πŸ“… Published: Feb. 27, 2026, 4:32 a.m. πŸ”„ Last Modified: April 18, 2026, 5:45 p.m.

7.8

CVSS3.1

CVE-2026-1442 - Unitree UPK files Hard-Coded Key

Since the encryption algorithm used to protect firmware updates is itself encrypted using key material available to an attacker (or anyone paying attention), the firmware updates may be altered by an unauthorized user, and then trusted by a Unitree product, such as the Unitree Go2 and other models.…

πŸ“… Published: Feb. 27, 2026, 4:28 a.m. πŸ”„ Last Modified: April 18, 2026, 5:45 p.m.

5.3

CVSS4.0

CVE-2026-3287 - youlaitech youlai-mall App-side Product Pagination Endpoint SpuController.java listPagedSpuForApp s…

A security flaw has been discovered in youlaitech youlai-mall 2.0.0. This affects the function listPagedSpuForApp of the file mall-pms/pms-boot/src/main/java/com/youlai/mall/pms/controller/app/SpuController.java of the component App-side Product Pagination Endpoint. Performing a manipulation of the…

πŸ“… Published: Feb. 27, 2026, 4:02 a.m. πŸ”„ Last Modified: April 16, 2026, 3:45 p.m.

7.9

CVSS3.1

CVE-2026-28364 - ocaml: OCaml: Remote code execution via buffer over-read in Marshal deserialization

In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() opera…

πŸ“… Published: Feb. 27, 2026, 3:54 a.m. πŸ”„ Last Modified: April 17, 2026, 2:15 p.m.

5.3

CVSS4.0

CVE-2026-3286 - itwanger paicoding Image Save Endpoint ImageRestController.java save server-side request forgery

A vulnerability was identified in itwanger paicoding 1.0.0/1.0.1/1.0.2/1.0.3. The impacted element is the function Save of the file paicoding-web/src/main/java/com/github/paicoding/forum/web/common/image/rest/ImageRestController.java of the component Image Save Endpoint. Such manipulation of the ar…

πŸ“… Published: Feb. 27, 2026, 3:32 a.m. πŸ”„ Last Modified: April 17, 2026, 2:15 p.m.

7.5

CVSS3.1

CVE-2026-2428 - Fluent Forms Pro Add On Pack <= 6.1.17 - Missing Authorization to Unauthenticated Payment Status mo…

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 6.1.17. This is due to the PayPal IPN (Instant Payment Notification) verification being disabled by default (`disable_ipn_verification` default…

πŸ“… Published: Feb. 27, 2026, 3:23 a.m. πŸ”„ Last Modified: April 15, 2026, 5 p.m.

9.9

CVSS3.1

CVE-2026-28363 - Unsafe SafeBins Validation in OpenClaw Sort Enables Execution of Unapproved Commands

In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviations (such as --compress-prog) in allowlist mode, leading to approval-free execution paths that were intended to require approval. Only an exact string such as --compress-program was…

πŸ“… Published: Feb. 27, 2026, 3:17 a.m. πŸ”„ Last Modified: April 18, 2026, 10:30 a.m.

4.8

CVSS4.0

CVE-2026-3285 - berry-lang berry be_lexer.c scan_string out-of-bounds

A vulnerability was determined in berry-lang berry up to 1.1.0. The affected element is the function scan_string of the file src/be_lexer.c. This manipulation causes out-of-bounds read. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Patch name: 7149c5…

πŸ“… Published: Feb. 27, 2026, 3:02 a.m. πŸ”„ Last Modified: April 16, 2026, 3:45 p.m.

4.8

CVSS4.0

CVE-2026-3284 - libvips extract.c vips_extract_area_build integer overflow

A vulnerability was found in libvips 8.19.0. Impacted is the function vips_extract_area_build of the file libvips/conversion/extract.c. The manipulation of the argument extract_area results in integer overflow. The attack requires a local approach. The exploit has been made public and could be used…

πŸ“… Published: Feb. 27, 2026, 3:02 a.m. πŸ”„ Last Modified: April 18, 2026, 10:30 a.m.
Total resulsts: 349182
Page 1409 of 34,919
Β« previous page Β» next page
Filters