5.3

CVSS3.1

CVE-2026-4812 - Advanced Custom Fields (ACF®) <= 6.7.0 - Unauthenticated Missing Authorization to Arbitrary Post/Pa…

The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Post/Page Disclosure in versions up to and including 6.7.0. This is due to AJAX field query endpoints accepting user-supplied filter parameters that override field-configured restrictions witho…

📅 Published: April 15, 2026, 1:25 a.m. 🔄 Last Modified: April 15, 2026, 1:25 a.m.

7.2

CVSS3.1

CVE-2026-2834 - Age Verification & Identity Verification by Token of Trust <= 3.32.3 - Unauthenticated Stored Cross…

The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘description’ parameter in all versions up to, and including, 3.32.3 due to insufficient input sanitization and output escaping. This makes it possible for unauth…

📅 Published: April 15, 2026, 1:25 a.m. 🔄 Last Modified: April 15, 2026, 1:25 a.m.

8.1

CVSS3.1

CVE-2025-54550 - Apache Airflow: RCE by race condition in example_xcom dag

The example example_xcom that was included in airflow documentation implemented unsafe pattern of reading value from xcom in the way that could be exploited to allow UI user who had access to modify XComs to perform arbitrary execution of code on the worker. Since the UI users are already highly tr…

📅 Published: April 15, 2026, 12:22 a.m. 🔄 Last Modified: April 16, 2026, 1:16 p.m.

7.5

CVSS3.1

CVE-2026-33806 - fastify vulnerable to Body Schema Validation Bypass via Leading Space in Content-Type Header

Impact: Fastify applications using schema.body.content for per-content-type body validation can have validation bypassed entirely by prepending a space to the Content-Type header. The body is still parsed correctly but schema validation is skipped. This is a regression introduced in fastify >= 5.…

📅 Published: April 15, 2026, 12:14 a.m. 🔄 Last Modified: April 17, 2026, 8:15 a.m.

6.5

CVSS4.0

CVE-2026-40105 - XWiki has Reflected Cross-Site Scripting (XSS) in its page history compare functionality

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 10.4-rc-1, through 16.10.15, 17.0.0-rc-1, through 17.4.7 and 17.5.0-rc-1 through 17.10.0 contain a reflected cross-site scripting vulnerability (XSS) in the comparison view between rev…

📅 Published: April 15, 2026, 12:07 a.m. 🔄 Last Modified: April 15, 2026, 12:07 a.m.

6.9

CVSS4.0

CVE-2026-40104 - XWiki's REST APIs can list all pages/spaces, leading to unavailability

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 1.8-rc-1, 17.0.0-rc-1 and 17.5.0-rc-1 and prior include a resource exhaustion vulnerability in REST API endpoints such as /xwiki/rest/wikis/xwiki/spaces/AnnotationCode/pages/AnnotationC…

📅 Published: April 15, 2026, 12:01 a.m. 🔄 Last Modified: April 16, 2026, 2:08 p.m.

4.3

CVSS3.1

CVE-2026-6298 - chromium-browser: Heap buffer overflow in Skia

Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Critical)

📅 Published: April 15, 2026, midnight 🔄 Last Modified: April 17, 2026, 7 a.m.

9.6

CVSS3.1

CVE-2026-6296 - chromium-browser: Heap buffer overflow in ANGLE

Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

📅 Published: April 15, 2026, midnight 🔄 Last Modified: April 16, 2026, 9:15 a.m.

8.6

CVSS3.1

CVE-2026-30624 - Remote Code Execution via Malicious MCP Server Configuration in Agent Zero 0.9.8

Agent Zero 0.9.8 contains a remote code execution vulnerability in its External MCP Servers configuration feature. The application allows users to define MCP servers using a JSON configuration containing arbitrary command and args values. These values are executed by the application when the config…

📅 Published: April 15, 2026, midnight 🔄 Last Modified: April 15, 2026, 10:30 p.m.

7.3

CVSS3.1

CVE-2026-30616 - Remote Command Execution via MCP STDIO in Jaaz 1.0.30

Jaaz 1.0.30 contains a remote code execution vulnerability in its MCP STDIO command execution handling. A remote attacker can send crafted network requests to the network-accessible Jaaz application, causing attacker-controlled commands to be executed on the server. Successful exploitation results …

📅 Published: April 15, 2026, midnight 🔄 Last Modified: April 15, 2026, 10:30 p.m.
Total resulsts: 344974
Page 34 of 34,498
« previous page » next page
Filters