5.4

CVSS3.1

CVE-2026-0901 -

Inappropriate implementation in Blink in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)

๐Ÿ“… Published: Jan. 20, 2026, 4:14 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4 p.m.

5.3

CVSS3.1

CVE-2025-14798 - LearnPress โ€“ WordPress LMS Plugin <= 4.3.2.4 - Missing Authorization to Unauthenticated Sensitive Uโ€ฆ

The LearnPress โ€“ WordPress LMS Plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.3.2.4 via the get_item_permissions_check function. This makes it possible for unauthenticated attackers to extract sensitive data including user first names and laโ€ฆ

๐Ÿ“… Published: Jan. 20, 2026, 3:25 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, midnight

5.3

CVSS3.1

CVE-2025-14351 - Custom Fonts โ€“ Host Your Fonts Locally <= 2.1.16 - Missing Authorization to Unauthenticated Font Deโ€ฆ

The Custom Fonts โ€“ Host Your Fonts Locally plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'BCF_Google_Fonts_Compatibility' class constructor function in all versions up to, and including, 2.1.16. This makes it possible for unauthenticated atโ€ฆ

๐Ÿ“… Published: Jan. 20, 2026, 3:25 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 4:30 p.m.

4.3

CVSS3.1

CVE-2026-1051 - Newsletter โ€“ Send awesome emails from WordPress <= 9.1.0 - Cross-Site Request Forgery to Newsletterโ€ฆ

The Newsletter โ€“ Send awesome emails from WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.1.0. This is due to missing or incorrect nonce validation on the hook_newsletter_action() function. This makes it possible for unauthenticatedโ€ฆ

๐Ÿ“… Published: Jan. 20, 2026, 1:22 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-14978 - PeachPay โ€” Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.โ€ฆ

The PeachPay โ€” Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on the ConvesioPay webhook REST endpoint in all versions up to, and including, 1.119โ€ฆ

๐Ÿ“… Published: Jan. 20, 2026, 1:22 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, midnight

6.3

CVSS4.0

CVE-2026-1203 - CRMEB JSON Token LoginServices.php remoteRegister improper authentication

A weakness has been identified in CRMEB up to 5.6.3. The impacted element is the function remoteRegister of the file crmeb/app/services/user/LoginServices.php of the component JSON Token Handler. Executing a manipulation of the argument uid can lead to improper authentication. The attack may be perโ€ฆ

๐Ÿ“… Published: Jan. 20, 2026, 1:02 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4 p.m.

6.9

CVSS4.0

CVE-2026-1202 - CRMEB LoginController.php appleLogin improper authentication

A security flaw has been discovered in CRMEB up to 5.6.3. The affected element is the function appleLogin of the file crmeb/app/api/controller/v1/LoginController.php. Performing a manipulation of the argument openId results in improper authentication. The attack is possible to be carried out remoteโ€ฆ

๐Ÿ“… Published: Jan. 20, 2026, 1:02 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 5 a.m.

8.1

CVSS3.1

CVE-2026-23876 - Heap buffer overflow with attacker-controlled data in XBM parser

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-13 and 6.9.13-38, a heap buffer overflow vulnerability in the XBM image decoder (ReadXBMImage) allows an attacker to write controlled data past the allocated heap buffer when proceโ€ฆ

๐Ÿ“… Published: Jan. 20, 2026, 1:01 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 5 a.m.

5.5

CVSS3.1

CVE-2026-23874 - ImageMagick's MSL: Stack overflow via infinite recursion in ProcessMSLScript

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-13 have a stack overflow via infinite recursion in MSL (Magick Scripting Language) `<write>` command when writing to MSL format. Version 7.1.2-13 fixes the issue.

๐Ÿ“… Published: Jan. 20, 2026, 12:52 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 5 a.m.

6.5

CVSS3.1

CVE-2026-22770 - ImageMagick vulnerable to Release of Invalid Pointer in BilateralBlur when memory allocation fails

ImageMagick is free and open-source software used for editing and manipulating digital images. The BilateralBlurImage method will allocate a set of double buffers inside AcquireBilateralTLS. But, in versions prior to 7.1.2-13, the last element in the set is not properly initialized. This will resulโ€ฆ

๐Ÿ“… Published: Jan. 20, 2026, 12:48 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 5 a.m.
Total resulsts: 349182
Page 2066 of 34,919
ยซ previous page ยป next page
Filters