9.8

CVSS3.0

CVE-2026-1114 - Improper Access Control via Weak JWT Token in parisneo/lollms

In parisneo/lollms version 2.1.0, the application's session management is vulnerable to improper access control due to the use of a weak secret key for signing JSON Web Tokens (JWT). This vulnerability allows an attacker to perform an offline brute-force attack to recover the secret key. Once the sโ€ฆ

๐Ÿ“… Published: April 7, 2026, 6:19 a.m. ๐Ÿ”„ Last Modified: April 7, 2026, 6:19 a.m.

0.0

CVE-2026-4079 - SQL Chart Builder < 2.3.8 - Unauthenticated SQL Injection

The SQL Chart Builder WordPress plugin before 2.3.8 does not properly escape user input as it is concatened to SQL queries, making it possible for attackers to conduct SQL Injection attacks against the dynamic filter functionality.

๐Ÿ“… Published: April 7, 2026, 6 a.m. ๐Ÿ”„ Last Modified: April 7, 2026, 6 a.m.

0.0

CVE-2026-1900 - Link Whisper Free < 0.9.1 - Unauthenticated Settings and User Meta Update

The Link Whisper Free WordPress plugin before 0.9.1 has a publicly accessible REST endpoint that allows unauthenticated settings updates.

๐Ÿ“… Published: April 7, 2026, 6 a.m. ๐Ÿ”„ Last Modified: April 7, 2026, 6 a.m.

0.0

CVE-2025-15611 - Popup Box AYS Pro < 5.5.0 - Admin+ Stored Cross-Site Scripting (XSS) via CSRF

The Popup Box WordPress plugin before 5.5.0 does not properly validate nonces in the add_or_edit_popupbox() function before saving popup data, allowing unauthenticated attackers to perform Cross-Site Request Forgery attacks. When an authenticated admin visits a malicious page, the attacker can creโ€ฆ

๐Ÿ“… Published: April 7, 2026, 6 a.m. ๐Ÿ”„ Last Modified: April 7, 2026, 6 a.m.

5.5

CVSS3.1

CVE-2025-65116 - Buffer Overflow Vulnerability in JP1/IT Desktop Management 2 and JP1/NETM/DM

Buffer Overflow Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows, Job Management Partner 1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management - Manager on Windows, Job Management Partner 1/IT Desktopโ€ฆ

๐Ÿ“… Published: April 7, 2026, 5:43 a.m. ๐Ÿ”„ Last Modified: April 7, 2026, 6:16 a.m.

6.5

CVSS3.0

CVE-2026-1839 - Arbitrary Code Execution via Unsafe torch.load() in Trainer Checkpoint Loading in huggingface/transโ€ฆ

A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_state()` method in `src/transformers/trainer.py` at line 3059 calls `torch.load()` without the `weights_only=True` parameter. This issue affects all versโ€ฆ

๐Ÿ“… Published: April 7, 2026, 5:22 a.m. ๐Ÿ”„ Last Modified: April 7, 2026, 6:16 a.m.

8.8

CVSS3.1

CVE-2025-65115 - Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 and JP1/NETM/DM

Remote Code Execution Vulnerabilityย in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows, Job Management Partner 1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management - Manager on Windows, Job Management Partner 1/IT Dโ€ฆ

๐Ÿ“… Published: April 7, 2026, 5:19 a.m. ๐Ÿ”„ Last Modified: April 7, 2026, 6:16 a.m.

9.8

CVSS3.1

CVE-2026-0740 - Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload

The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Controllers_Uploads::handle_upload' function in all versions up to, and including, 3.3.26. This makes it possible for unauthenticated attackers to uploaโ€ฆ

๐Ÿ“… Published: April 7, 2026, 4:25 a.m. ๐Ÿ”„ Last Modified: April 7, 2026, 5:16 a.m.

0.0

CVE-2026-20446 -

In sec boot, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service, if an attacker has physical access to the device, with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09963054; Issue ID: MSโ€ฆ

๐Ÿ“… Published: April 7, 2026, 3:25 a.m. ๐Ÿ”„ Last Modified: April 7, 2026, 4:17 a.m.

0.0

CVE-2026-20433 -

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. โ€ฆ

๐Ÿ“… Published: April 7, 2026, 3:25 a.m. ๐Ÿ”„ Last Modified: April 7, 2026, 4:17 a.m.
Total resulsts: 342654
Page 2 of 34,266
ยซ previous page ยป next page
Filters