9.3

CVSS4.0

CVE-2026-8076 - Weak credentials vulnerability in the CashDro 3 web administration panel

Weak credentials in the CashDro 3 web administration panel, version 24.01.00.26, where the platform allows the use of numeric PINs for user authentication. The system supports the use of PIN-based credentials, maintaining compatibility with POS software integrations deployed since 2012. This could …

📅 Published: May 8, 2026, 11:55 a.m. 🔄 Last Modified: May 8, 2026, 12:48 p.m.

9.8

CVSS3.1

CVE-2026-8153 - Command injection in Dashboard Server interface

OS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.21.1 allows unauthenticated attacker to craft commands that will execute code on the robot's OS.

📅 Published: May 8, 2026, 11:45 a.m. 🔄 Last Modified: May 8, 2026, 12:47 p.m.

5.3

CVSS4.0

CVE-2026-3318 - Multiple vulnerabilities in Cradle e-commerce

Open redirection vulnerability in the latest demo version of the Cradle eCommerce platform. The vulnerability occurs in the login form endpoint, where the ‘returnUrl’ parameter allows redirection because the web application accepts a URL as a parameter without properly validating it. As a result, i…

📅 Published: May 8, 2026, 11:24 a.m. 🔄 Last Modified: May 8, 2026, 1 p.m.

6.4

CVSS3.1

CVE-2026-7475 - Sky Addons <= 3.3.2 - Authenticated (Author+) Stored Cross-Site Scripting via Custom Script

The Sky Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `sky-custom-scripts` custom post type in all versions up to, and including, 3.3.2. This is due to the custom post type being registered with `capability_type => 'post'` and `show_in_rest => true`, combined with…

📅 Published: May 8, 2026, 9:26 a.m. 🔄 Last Modified: May 8, 2026, 12:12 p.m.

6.4

CVSS3.1

CVE-2026-5341 - NMR Strava activities <= 1.0.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shor…

The NMR Strava activities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `strava_nmr_connect` shortcode in all versions up to, and including, 1.0.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…

📅 Published: May 8, 2026, 9:26 a.m. 🔄 Last Modified: May 8, 2026, 11:30 a.m.

6.4

CVSS3.1

CVE-2026-7650 - E2Pdf – Export Pdf Tool for WordPress <= 1.32.17 - Authenticated (Contributor+) Stored Cross-Site S…

The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute of the `e2pdf-download` shortcode in all versions up to, and including, 1.32.17. This is due to insufficient input sanitization and output escaping on the shortcode att…

📅 Published: May 8, 2026, 9:26 a.m. 🔄 Last Modified: May 8, 2026, 12:45 p.m.

10

CVSS4.0

CVE-2026-6213 - Remote Spark SparkView RCE

A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check and achieve arbitrary code execution as root on the server side. Depending on implementation the vulnerability can be exploited by an unauthenticated attacker.

📅 Published: May 8, 2026, 9:04 a.m. 🔄 Last Modified: May 8, 2026, 12:45 p.m.

7.2

CVSS3.1

CVE-2026-7330 - Auto Affiliate Links <= 6.8.8 - Unauthenticated Stored Cross-Site Scripting via 'url' Parameter

The Auto Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.8.8 This is due to insufficient input sanitization on the 'url' POST parameter in the aal_url_stats_save_action() function and a complete absence of output escaping in aal_…

📅 Published: May 8, 2026, 8:26 a.m. 🔄 Last Modified: May 8, 2026, 8:26 a.m.

8.8

CVSS3.1

CVE-2026-5127 - User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration…

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Deserialization of Untrusted Data in versions up to, and including, 4.3.1 This is due to insufficient input validation and type checking on the wpuf_files pa…

📅 Published: May 8, 2026, 8:26 a.m. 🔄 Last Modified: May 8, 2026, 10:30 a.m.

0.0

CVE-2013-10075 - Apache::Session versions through 1.94 for Perl re-creates deleted sessions

Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apache::Session::Store::File and Apache::Session::Store::DB_File will create a session that does not exist. This can lead to sessions being revived, potentially with data that was to be deleted.

📅 Published: May 8, 2026, 7:44 a.m. 🔄 Last Modified: May 8, 2026, 7:44 a.m.
Total resulsts: 349182
Page 27 of 34,919
« previous page » next page
Filters