6.4

CVSS3.1

CVE-2026-2509 - Page Builder: Pagelayer <= 2.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via But…

The Page Builder: Pagelayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button widget's Custom Attributes field in all versions up to, and including, 2.0.8. This is due to an incomplete event handler blocklist in the 'pagelayer_xss_content' XSS filtering function, whic…

📅 Published: April 8, 2026, 1:26 p.m. 🔄 Last Modified: April 8, 2026, 1:26 p.m.

9.3

CVSS4.0

CVE-2025-14816 - Information Disclosure, Tampering, and Denial-of-Service Vulnerabilities in GENESIS64, ICONICS Suit…

Cleartext Storage of Sensitive Information in GUI vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric MobileHMI versions 10.97.3 and prior, Mitsubishi Electric Hyper Historian versions 10.97.3 a…

📅 Published: April 8, 2026, 1:23 p.m. 🔄 Last Modified: April 8, 2026, 1:23 p.m.

9.3

CVSS4.0

CVE-2025-14815 - Information Disclosure, Tampering, and Denial-of-Service Vulnerabilities in GENESIS64, ICONICS Suit…

Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric MobileHMI versions 10.97.3 and prior, Mitsubishi Electric Hyper Historian versions 10.97.3 and prio…

📅 Published: April 8, 2026, 1:15 p.m. 🔄 Last Modified: April 8, 2026, 1:20 p.m.

0.0

CVE-2026-31411 - net: atm: fix crash due to unvalidated vcc pointer in sigd_send()

In the Linux kernel, the following vulnerability has been resolved: net: atm: fix crash due to unvalidated vcc pointer in sigd_send() Reproducer available at [1]. The ATM send path (sendmsg -> vcc_sendmsg -> sigd_send) reads the vcc pointer from msg->vcc and uses it directly without any validati…

📅 Published: April 8, 2026, 1:06 p.m. 🔄 Last Modified: April 8, 2026, 1:06 p.m.

5.3

CVSS4.0

CVE-2026-35023 - Wimi Teamwork On-Premises < 8.2.0 IDOR via preview.php

Wimi Teamwork On-Premises versions prior to 8.2.0 contain an insecure direct object reference vulnerability in the preview.php endpoint where the item_id parameter lacks proper authorization checks. Attackers can enumerate sequential item_id values to access and retrieve image previews from other u…

📅 Published: April 8, 2026, 12:59 p.m. 🔄 Last Modified: April 8, 2026, 12:59 p.m.

7.8

CVSS3.1

CVE-2026-28261 -

Dell Elastic Cloud Storage, version 3.8.1.7 and prior, and Dell ObjectScale, versions prior to 4.1.0.3 and version 4.2.0.0, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading t…

📅 Published: April 8, 2026, 12:43 p.m. 🔄 Last Modified: April 8, 2026, 1:55 p.m.

4.4

CVSS3.1

CVE-2026-24511 -

Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.0, contains a generation of error message containing sensitive information vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to information d…

📅 Published: April 8, 2026, 12:28 p.m. 🔄 Last Modified: April 8, 2026, 12:28 p.m.

5.5

CVSS4.0

CVE-2026-5600 -

A new API endpoint introduced in pretix 2025 that is supposed to return all check-in events of a specific event in fact returns all check-in events belonging to the respective organizer. This allows an API consumer to access information for all other events under the same organizer, even those …

📅 Published: April 8, 2026, 12:24 p.m. 🔄 Last Modified: April 8, 2026, 12:24 p.m.

6.6

CVSS3.1

CVE-2026-27102 -

Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.1, contains an incorrect privilege assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.

📅 Published: April 8, 2026, 12:11 p.m. 🔄 Last Modified: April 8, 2026, 12:11 p.m.

6.3

CVSS3.1

CVE-2026-5302 - Permissive Cross-domain Policy with Untrusted Domains in coolercontrold

CORS misconfiguration in CoolerControl/coolercontrold <4.0.0 allows unauthenticated remote attackers to read data and send commands to the service via malicious websites

📅 Published: April 8, 2026, 12:05 p.m. 🔄 Last Modified: April 8, 2026, 12:05 p.m.
Total resulsts: 343183
Page 3 of 34,319
« previous page » next page
Filters