0.0

CVE-2026-41043 - Apache ActiveMQ, Apache ActiveMQ Web: ActiveMQ Web Console - XSS vulnerability when browsing queues

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. An authenticated attacker can show malicious content when browsing queues in the web console by overriding the content type to be HTML (instead of XML) and by inject…

📅 Published: April 24, 2026, 10:16 a.m. 🔄 Last Modified: April 24, 2026, 6:17 p.m.

0.0

CVE-2026-40466 - Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Possible bypass of CVE-2026-34197 via…

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated attacker may bypass the fix in CVE-2026-34197 by adding a connector using an HTTP Discovery transport via BrokerVie…

📅 Published: April 24, 2026, 10:15 a.m. 🔄 Last Modified: April 24, 2026, 6:17 p.m.

8.5

CVSS4.0

CVE-2026-6272 -

A client holding only a read JWT scope can still register itself as a signal provider through the production kuksa.val.v2 OpenProviderStream API by sending ProvideSignalRequest. 1. Obtain any valid token with only read scope. 2. Connect to the normal production gRPC API (kuksa.val.v2). 3. Open Ope…

📅 Published: April 24, 2026, 8:28 a.m. 🔄 Last Modified: April 24, 2026, 8:28 a.m.

7.5

CVSS3.1

CVE-2026-21728 - Tempo query limit results in unbounded memory allocation

Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18).

📅 Published: April 24, 2026, 8 a.m. 🔄 Last Modified: April 24, 2026, 8 a.m.

5.3

CVSS3.1

CVE-2026-3569 - Liaison Site Prober <= 1.2.1 - Missing Authorization to Unauthenticated Information Exposure in '/l…

The Liaison Site Prober plugin for WordPress is vulnerable to Information Exposure in all versions up to and including 1.2.1 via the /wp-json/site-prober/v1/logs REST API endpoint. The permissions_read() permission callback unconditionally returns true (via __return_true()) instead of checking for …

📅 Published: April 24, 2026, 7:45 a.m. 🔄 Last Modified: April 24, 2026, 7:45 a.m.

6.4

CVSS3.1

CVE-2026-4078 - ITERAS <= 1.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

The ITERAS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes (iteras-ordering, iteras-signup, iteras-paywall-login, iteras-selfservice) in all versions up to and including 1.8.2. This is due to insufficient input sanitization and output escaping in the combin…

📅 Published: April 24, 2026, 7:45 a.m. 🔄 Last Modified: April 24, 2026, 7:45 a.m.

4.3

CVSS3.1

CVE-2026-3565 - Taqnix <= 1.0.3 - Cross-Site Request Forgery to Account Deletion via 'taqnix_delete_my_account' AJA…

The Taqnix plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to a missing nonce verification in the taqnix_delete_my_account() function, where the check_ajax_referer() call is explicitly commented out on line 883. This makes it…

📅 Published: April 24, 2026, 7:45 a.m. 🔄 Last Modified: April 24, 2026, 7:45 a.m.

4.3

CVSS3.1

CVE-2025-11762 - HubSpot All-In-One Marketing - Forms, Popups, Live Chat <= 11.3.32 - Missing Authorization to Authe…

The HubSpot All-In-One Marketing - Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.32 via the leadin/public/admin/class-adminconstants.php file. This makes it possible for authenticated attackers, with Contribu…

📅 Published: April 24, 2026, 7:45 a.m. 🔄 Last Modified: April 24, 2026, 6:17 p.m.

9.8

CVSS3.1

CVE-2026-1951 - No checking of the length of the buffer with the directory name in AS320T

Delta Electronics AS320T has no checking of the length of the buffer with the directory name vulnerability.

📅 Published: April 24, 2026, 6:13 a.m. 🔄 Last Modified: April 24, 2026, 6:13 a.m.

9.8

CVSS3.1

CVE-2026-1952 - Denial of service via the undocumented subfunction in AS320T

Delta Electronics AS320T has denial of service via the undocumented subfunction vulnerability.

📅 Published: April 24, 2026, 6:08 a.m. 🔄 Last Modified: April 24, 2026, 3:26 p.m.
Total resulsts: 346528
Page 24 of 34,653
« previous page » next page
Filters