7.2

CVSS3.1

CVE-2026-23815 - Authenticated Command Injection found in AOS-CX Administrative CLI Command

A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute unauthorized commands.

πŸ“… Published: March 11, 2026, 3:12 a.m. πŸ”„ Last Modified: March 12, 2026, 3:55 a.m.

8.8

CVSS3.1

CVE-2026-23814 - Authenticated Command Injection found in AOS-CX CLI Command

A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privilege authenticated remote attacker to inject malicious commands resulting in unwanted behavior.

πŸ“… Published: March 11, 2026, 3:11 a.m. πŸ”„ Last Modified: March 12, 2026, 3:55 a.m.

9.8

CVSS3.1

CVE-2026-23813 - Authentication Bypass in Web Interface allows Unauthenticated Admin Password Reset

A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable resetting the admin password.

πŸ“… Published: March 11, 2026, 3:08 a.m. πŸ”„ Last Modified: March 12, 2026, 3:55 a.m.

8.1

CVSS3.1

CVE-2026-3453 - ProfilePress <= 4.16.11 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary…

The ProfilePress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.16.11. This is due to missing ownership validation on the change_plan_sub_id parameter in the process_checkout() function. The ppress_process_checkout AJAX handler accepts…

πŸ“… Published: March 11, 2026, 2:22 a.m. πŸ”„ Last Modified: March 11, 2026, 3:39 p.m.

4.8

CVSS3.1

CVE-2026-21291 - Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Exploitation of this is…

πŸ“… Published: March 11, 2026, 2:19 a.m. πŸ”„ Last Modified: March 11, 2026, 5:33 p.m.

5.5

CVSS3.1

CVE-2026-21293 - Adobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A high-privileged attacker could exploit this vulnerability to manipulate server-s…

πŸ“… Published: March 11, 2026, 2:19 a.m. πŸ”„ Last Modified: March 11, 2026, 5:51 p.m.

5.3

CVSS3.1

CVE-2026-21282 - Adobe Commerce | Improper Input Validation (CWE-20)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Input Validation vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability by providing specially crafted input, causi…

πŸ“… Published: March 11, 2026, 2:19 a.m. πŸ”„ Last Modified: March 11, 2026, 5:23 p.m.

5.3

CVSS3.1

CVE-2026-21286 - Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited u…

πŸ“… Published: March 11, 2026, 2:19 a.m. πŸ”„ Last Modified: March 11, 2026, 5:31 p.m.

5.5

CVSS3.1

CVE-2026-21294 - Adobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A high-privileged attacker could exploit this vulnerability to manipulate server-s…

πŸ“… Published: March 11, 2026, 2:19 a.m. πŸ”„ Last Modified: March 11, 2026, 5:36 p.m.

8.1

CVSS3.1

CVE-2026-21284 - Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript ma…

πŸ“… Published: March 11, 2026, 2:19 a.m. πŸ”„ Last Modified: March 12, 2026, 3:55 a.m.
Total resulsts: 337541
Page 31 of 33,755
Β« previous page Β» next page
Filters