8.6

CVSS4.0

CVE-2026-22666 - Dolibarr ERP/CRM < 23.0.2 Authenticated RCE via dol_eval_standard()

Dolibarr ERP/CRM versions prior to 23.0.2 contain an authenticated remote code execution vulnerability in the dol_eval_standard() function that fails to apply forbidden string checks in whitelist mode and does not detect PHP dynamic callable syntax. Attackers with administrator privileges can injec…

📅 Published: April 7, 2026, 12:41 p.m. 🔄 Last Modified: April 7, 2026, 1:43 p.m.

8.3

CVSS4.0

CVE-2026-28808 - ScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch)

Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias. When script_alias maps a URL prefix to a directory outside DocumentRoot, mod_auth evaluates directory-based access controls ag…

📅 Published: April 7, 2026, 12:28 p.m. 🔄 Last Modified: April 7, 2026, 2:38 p.m.

7.6

CVSS4.0

CVE-2026-32144 - OCSP designated-responder authorization bypass via missing signature verification

Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows OCSP designated-responder authorization bypass via missing signature verification. The OCSP response validation in public_key:pkix_ocsp_validate/5 does not verify that a CA-designated responder certi…

📅 Published: April 7, 2026, 12:28 p.m. 🔄 Last Modified: April 7, 2026, 2:38 p.m.

8.8

CVSS3.1

CVE-2026-23818 - Open Redirect Vulnerability in HPE Aruba Networking Private 5G Core On-Prem

A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Prem that could allow an attacker to abuse an open redirect vulnerability in the login flow using a crafted URL. Successful exploitation may redirect an authenticated user to an atta…

📅 Published: April 7, 2026, 12:18 p.m. 🔄 Last Modified: April 7, 2026, 2:16 p.m.

9.3

CVSS4.0

CVE-2025-39666 - omd: Local privilege escalation when executing omd commands as root

Local privilege escalation in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Checkmk 2.5.0 (beta) before 2.5.0b3 allows a site user to escalate their privileges to root, by manipulating files in the site context that are processed when the `omd` administrativ…

📅 Published: April 7, 2026, 12:09 p.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.

8.5

CVSS4.0

CVE-2026-3466 - Cross-site scripting in dashlet title

Insufficient sanitization of dashboard dashlet title links in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Checkmk 2.5.0 (beta) before 2.5.0b3 allows an attacker with dashboard creation privileges to perform stored cross-site scripting (XSS) attacks by tric…

📅 Published: April 7, 2026, 12:08 p.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.

8.7

CVSS4.0

CVE-2026-31842 - Tinyproxy HTTP request parsing desynchronization via case-sensitive Transfer-Encoding handling

Tinyproxy through 1.11.3 is vulnerable to HTTP request parsing desynchronization due to a case-sensitive comparison of the Transfer-Encoding header in src/reqs.c. The is_chunked_transfer() function uses strcmp() to compare the header value against "chunked", even though RFC 7230 specifies that tran…

📅 Published: April 7, 2026, 11:17 a.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.

5.1

CVSS4.0

CVE-2026-4420 - Stored XSS via Page Creating functionality in Bludit

Bludit is vulnerable to Stored Cross-Site Scripting (XSS) in its page creating functionality. An authenticated attacker with page creation privileges (such as Author, Editor, or Administrator) can embed a malicious JavaScript payload in the tags field of a newly created article. This payload will b…

📅 Published: April 7, 2026, 10:46 a.m. 🔄 Last Modified: April 7, 2026, 10:46 a.m.

5.4

CVSS3.1

CVE-2026-34903 - WordPress Ocean Extra plugin <= 2.5.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in OceanWP Ocean Extra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ocean Extra: from n/a through 2.5.3.

📅 Published: April 7, 2026, 8:57 a.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.

5.3

CVSS3.1

CVE-2026-34899 - WordPress LTL Freight Quotes – Worldwide Express Edition plugin <= 5.2.1 - Broken Access Control vu…

Missing Authorization vulnerability in Eniture technology LTL Freight Quotes – Worldwide Express Edition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LTL Freight Quotes – Worldwide Express Edition: from n/a through 5.2.1.

📅 Published: April 7, 2026, 8:31 a.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.
Total resulsts: 342823
Page 16 of 34,283
« previous page » next page
Filters