5.3

CVSS3.1

CVE-2026-2028 - Maxi Blocks <= 2.1.8 - Missing Authorization to Authenticated (Author+) Media File Deletion via 'ol…

The MaxiBlocks Builder plugin for WordPress is vulnerable to arbitrary media file deletion due to insufficient file ownership validation on the 'maxi_remove_custom_image_size' AJAX action in all versions up to, and including, 2.1.8. This makes it possible for authenticated attackers, with Author-le…

📅 Published: April 24, 2026, 3:27 a.m. 🔄 Last Modified: April 28, 2026, 9:25 a.m.

5.3

CVSS3.1

CVE-2026-5488 - ExactMetrics <= 9.1.2 - Authenticated (Subscriber+) Missing Authorization to Google Ads Access Toke…

The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 9.1.2. This is due to missing capability checks in the get_ads_access_token() and reset_experience() AJAX handlers. While the mi-admin-nonce is loc…

📅 Published: April 24, 2026, 3:27 a.m. 🔄 Last Modified: April 24, 2026, 6:17 p.m.

4.3

CVSS3.1

CVE-2026-6393 - BetterDocs <= 4.3.11 - Missing Authorization to Authenticated (Subscriber+) Unauthorized AI API Usa…

The BetterDocs plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.3.11. This is due to a missing capability check in the generate_openai_content_callback() function, which relies solely on a nonce rather than verifying user permissions. This makes it possi…

📅 Published: April 24, 2026, 3:27 a.m. 🔄 Last Modified: April 27, 2026, 11 p.m.

8.1

CVSS3.1

CVE-2026-41323 - Kyverno: ServiceAccount token leaked to external servers via apiCall service URL

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.18.0-rc1, 1.17.2-rc1, and 1.16.4, Kyverno's apiCall feature in ClusterPolicy automatically attaches the admission controller's ServiceAccount token to outgoing HTTP requests. The service URL has no …

📅 Published: April 24, 2026, 3:21 a.m. 🔄 Last Modified: April 27, 2026, 5:53 p.m.

7.7

CVSS3.1

CVE-2026-41068 - Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix)

Kyverno is a policy engine designed for cloud native platform engineering teams. The patch for CVE-2026-22039 fixed cross-namespace privilege escalation in Kyverno's `apiCall` context by validating the `URLPath` field. However, the ConfigMap context loader has the identical vulnerability — the `con…

📅 Published: April 24, 2026, 3:14 a.m. 🔄 Last Modified: April 24, 2026, 4:22 p.m.

6.5

CVSS3.1

CVE-2026-41319 - MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism dow…

MailKit is a cross-platform mail client library built on top of MimeKit. A STARTTLS Response Injection vulnerability in versions prior to 4.16.0 allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechan…

📅 Published: April 24, 2026, 3:07 a.m. 🔄 Last Modified: April 25, 2026, 1:46 a.m.

5.4

CVSS3.1

CVE-2026-41318 - AnythingLLM vulnerable to stored DOM XSS in chart caption renderer - LLM-driven prompt injection pr…

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to version 1.12.1, AnythingLLM's in-chat markdown renderer has an unsafe custom rule for images that interpolates the markdown image's `alt` text into an HTML `alt="..."…

📅 Published: April 24, 2026, 2:57 a.m. 🔄 Last Modified: April 24, 2026, 6:17 p.m.

1.3

CVSS4.0

CVE-2026-41430 - Press vulnerable to reflected XSS on login redirection

Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). Redirect parameter on login page is vulnerable to reflected XSS. The patch in commit 16d1b6ca2559f858a1de77bcb03fd7f1b81671c6 fixes the issue by restricting redire…

📅 Published: April 24, 2026, 2:42 a.m. 🔄 Last Modified: April 24, 2026, 6:17 p.m.

6.6

CVSS4.0

CVE-2026-41317 - Frappe Press has an unsafe HTTP method / CSRF-adjacent issue on API secret generation

Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS).`press.api.account.create_api_secret` is prone to CSRF-like exploits. This endpoint writes to database and it is also accessible via GET method. The patch in commit…

📅 Published: April 24, 2026, 2:40 a.m. 🔄 Last Modified: April 27, 2026, 11 p.m.

8.1

CVSS3.1

CVE-2026-41316 - ERB has an @_init deserialization guard bypass via def_module / def_method / def_class

ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` instance variable guard in `ERB#result` and `ERB#run` to prevent code execution when an ERB object is reconstructed via `Marshal.load` (deserialization). However, three other publ…

📅 Published: April 24, 2026, 2:35 a.m. 🔄 Last Modified: April 24, 2026, 2:50 p.m.
Total resulsts: 349182
Page 289 of 34,919
« previous page » next page
Filters