6

CVSS4.0

CVE-2026-5446 - wolfSSL ARIA-GCM TLS 1.2/DTLS 1.2 GCM nonce reuse

In wolfSSL, ARIA-GCM cipher suites used in TLS 1.2 and DTLS 1.2 reuse an identical 12-byte GCM nonce for every application-data record. Because wc_AriaEncrypt is stateless and passes the caller-supplied IV verbatim to the MagicCrypto SDK with no internal counter, and because the explicit IV is zeroโ€ฆ

๐Ÿ“… Published: April 9, 2026, 9:02 p.m. ๐Ÿ”„ Last Modified: April 10, 2026, 6:11 p.m.

4.8

CVSS4.0

CVE-2026-35206 - Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment

Helm is a package manager for Charts for Kubernetes. In Helm versions <=3.20.1 and <=4.1.3, a specially crafted Chart will cause helm pull --untar [chart URL | repo/chartname] to write the Chart's contents to the immediate output directory (as defaulted to the current working directory; or as giveโ€ฆ

๐Ÿ“… Published: April 9, 2026, 9:02 p.m. ๐Ÿ”„ Last Modified: April 9, 2026, 9:02 p.m.

8.7

CVSS4.0

CVE-2026-5980 - D-Link DIR-605L POST Request formSetMACFilter buffer overflow

A flaw has been found in D-Link DIR-605L 2.13B01. Affected by this issue is the function formSetMACFilter of the file /goform/formSetMACFilter of the component POST Request Handler. This manipulation of the argument curTime causes buffer overflow. The attack may be initiated remotely. The exploit hโ€ฆ

๐Ÿ“… Published: April 9, 2026, 9 p.m. ๐Ÿ”„ Last Modified: April 9, 2026, 9 p.m.

5.1

CVSS4.0

CVE-2023-54364 - Joomla HikaShop 4.7.4 Reflected XSS via Product Filter

Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating GET parameters in the product filter endpoint. Attackers can craft malicious URLs containing XSS payloads in the from_option, from_ctrl, frโ€ฆ

๐Ÿ“… Published: April 9, 2026, 8:54 p.m. ๐Ÿ”„ Last Modified: April 10, 2026, 6:10 p.m.

5.1

CVSS4.0

CVE-2023-54363 - Joomla Solidres 2.13.3 Reflected XSS via Multiple Parameters

Joomla Solidres 2.13.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating multiple GET parameters including show, reviews, type_id, distance, facilities, categories, prices, location, and Itemid. Attackers can crโ€ฆ

๐Ÿ“… Published: April 9, 2026, 8:54 p.m. ๐Ÿ”„ Last Modified: April 10, 2026, 3:55 p.m.

5.1

CVSS4.0

CVE-2023-54362 - Joomla VirtueMart Shopping-Cart 4.0.12 Reflected XSS via keyword

Joomla VirtueMart Shopping-Cart 4.0.12 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the keyword parameter. Attackers can craft malicious URLs containing script payloads in the keyword parameter of the product-variants endpโ€ฆ

๐Ÿ“… Published: April 9, 2026, 8:54 p.m. ๐Ÿ”„ Last Modified: April 9, 2026, 8:55 p.m.

5.1

CVSS4.0

CVE-2023-54361 - Joomla iProperty Real Estate 4.1.1 Reflected XSS via filter_keyword

Joomla iProperty Real Estate 4.1.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the filter_keyword parameter. Attackers can craft URLs containing JavaScript payloads in the filter_keyword GET parameter of the all-propertieโ€ฆ

๐Ÿ“… Published: April 9, 2026, 8:54 p.m. ๐Ÿ”„ Last Modified: April 9, 2026, 8:55 p.m.

5.1

CVSS4.0

CVE-2023-54360 - Joomla JLex Review 6.0.1 Reflected XSS via review_id Parameter

Joomla JLex Review 6.0.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the review_id URL parameter. Attackers can craft malicious links containing JavaScript payloads that execute in victims' browsers when clicked, enablingโ€ฆ

๐Ÿ“… Published: April 9, 2026, 8:54 p.m. ๐Ÿ”„ Last Modified: April 9, 2026, 8:55 p.m.

8.8

CVSS4.0

CVE-2023-54359 - WordPress adivaha Travel Plugin 2.3 SQL Injection via pid

WordPress adivaha Travel Plugin 2.3 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'pid' GET parameter. Attackers can send requests to the /mobile-app/v3/ endpoint with crafted 'pid' valuโ€ฆ

๐Ÿ“… Published: April 9, 2026, 8:54 p.m. ๐Ÿ”„ Last Modified: April 9, 2026, 8:55 p.m.

5.1

CVSS4.0

CVE-2023-54358 - WordPress adivaha Travel Plugin 2.3 Reflected XSS via isMobile

WordPress adivaha Travel Plugin 2.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the isMobile parameter. Attackers can craft malicious URLs containing JavaScript payloads in the isMobile GET parameter at thโ€ฆ

๐Ÿ“… Published: April 9, 2026, 8:54 p.m. ๐Ÿ”„ Last Modified: April 10, 2026, 6:10 p.m.
Total resulsts: 343982
Page 41 of 34,399
ยซ previous page ยป next page
Filters