6.4

CVSS3.1

CVE-2026-2358 - WP ULike <= 5.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute

The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[wp_ulike_likers_box]` shortcode `template` attribute in all versions up to, and including, 5.0.1. This is due to the use of `html_entity_decode()` on shortcode attributes without subsequent output sanitization,…

πŸ“… Published: March 11, 2026, 5:27 a.m. πŸ”„ Last Modified: March 11, 2026, 3:39 p.m.

9.3

CVSS4.0

CVE-2026-27842 -

Authentication bypass issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to bypass authentication and change the device configuration.

πŸ“… Published: March 11, 2026, 5:25 a.m. πŸ”„ Last Modified: March 11, 2026, 3:39 p.m.

9.3

CVSS4.0

CVE-2026-24448 -

Use of hard-coded credentials issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to obtain administrative access.

πŸ“… Published: March 11, 2026, 5:25 a.m. πŸ”„ Last Modified: March 11, 2026, 3:39 p.m.

8.6

CVSS4.0

CVE-2026-20892 -

Code injection vulnerability exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker with administrative privileges to execute arbitrary commands.

πŸ“… Published: March 11, 2026, 5:25 a.m. πŸ”„ Last Modified: March 11, 2026, 3:39 p.m.

5.1

CVSS4.0

CVE-2026-3884 -

Versions of the package spin.js before 3.0.0 are vulnerable to Cross-site Scripting (XSS) via the spin() function that allows a creation of more than 1 alert for each 'target' element. An attacker would need to set an arbitrary key-value pair on Object.prototype through a crafted URL achieving a pr…

πŸ“… Published: March 11, 2026, 5 a.m. πŸ”„ Last Modified: March 11, 2026, 3:45 p.m.

8.8

CVSS3.1

CVE-2025-13067 - Royal Addons for Elementor <= 1.7.1049 - Authenticated (Author+) Arbitrary File Upload via main.php…

The Royal Addons for Elementor plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 1.7.1049. This is due to insufficient file type validation detecting files named main.php, allowing a file with such a name to bypass sanitization. This makes it possible…

πŸ“… Published: March 11, 2026, 4:25 a.m. πŸ”„ Last Modified: March 11, 2026, 3:39 p.m.

7.5

CVSS3.1

CVE-2026-2413 - Ally – Web Accessibility & Usability <= 4.0.3 - Unauthenticated SQL Injection via URL Path

The Ally – Web Accessibility & Usability plugin for WordPress is vulnerable to SQL Injection via the URL path in all versions up to, and including, 4.0.3. This is due to insufficient escaping on the user-supplied URL parameter in the `get_global_remediations()` method, where it is directly concaten…

πŸ“… Published: March 11, 2026, 4:25 a.m. πŸ”„ Last Modified: March 11, 2026, 3:39 p.m.

9.3

CVSS4.0

CVE-2026-29515 - MiCode FileExplorer SwiFTP Server Authentication Bypass

MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers to log in without valid credentials. Attackers can send arbitrary username and password combinations to the PASS command handler, which unconditionally grant…

πŸ“… Published: March 11, 2026, 3:23 a.m. πŸ”„ Last Modified: March 11, 2026, 3:39 p.m.

6.5

CVSS3.1

CVE-2026-23817 - Unauthenticated Open Redirect allows URL Manipulation in Web Interface

A vulnerability in the web-based management interface of AOS-CX Switches could allow an unauthenticated remote attacker to redirect users to an arbitrary URL.

πŸ“… Published: March 11, 2026, 3:14 a.m. πŸ”„ Last Modified: March 11, 2026, 3:45 p.m.

7.2

CVSS3.1

CVE-2026-23816 - Authenticated Command Injection found in admin AOS-CX CLI command

A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.

πŸ“… Published: March 11, 2026, 3:13 a.m. πŸ”„ Last Modified: March 11, 2026, 3:43 p.m.
Total resulsts: 337541
Page 30 of 33,755
Β« previous page Β» next page
Filters