6.5

CVSS3.1

CVE-2026-20078 - Cisco Unity Connection Arbitrary File Download Vulnerability

Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitrary files from an affected system. To exploit these vulnerabilities, the attacker must have valid administrative credentials.  These vulnerabilities are due to improper sa…

📅 Published: April 15, 2026, 4:03 p.m. 🔄 Last Modified: April 17, 2026, 3:09 p.m.

4.8

CVSS3.1

CVE-2026-20132 - Cisco Identity Services Engine Multiple Cross-Site Scripting Vulnerabilities

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative write privileges to conduct a stored cross-site scripting (XSS) attack or a reflected XSS attack against a user of the web-ba…

📅 Published: April 15, 2026, 4:03 p.m. 🔄 Last Modified: April 17, 2026, 3:09 p.m.

5.9

CVSS3.1

CVE-2026-6370 - WordPress Mini Ajax Cart for WooCommerce plugin <= 1.3.4 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HashThemes Mini Ajax Cart for WooCommerce allows Stored XSS.This issue affects Mini Ajax Cart for WooCommerce: from n/a through 1.3.4.

📅 Published: April 15, 2026, 4:02 p.m. 🔄 Last Modified: April 15, 2026, 9:02 p.m.

6.5

CVSS3.1

CVE-2025-15636 - WordPress YouTube Showcase plugin <= 3.5.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emarket-design YouTube Showcase allows Stored XSS.This issue affects YouTube Showcase: from n/a through 3.5.1.

📅 Published: April 15, 2026, 3:55 p.m. 🔄 Last Modified: April 15, 2026, 10:30 p.m.

4.3

CVSS3.1

CVE-2025-15635 - WordPress Smart Online Order for Clover plugin <= 1.6.0 - Cross Site Request Forgery (CSRF) vulnera…

Cross-Site Request Forgery (CSRF) vulnerability in Zaytech Smart Online Order for Clover allows Cross Site Request Forgery.This issue affects Smart Online Order for Clover: from n/a through 1.6.0.

📅 Published: April 15, 2026, 3:49 p.m. 🔄 Last Modified: April 15, 2026, 10:30 p.m.

4.3

CVSS3.1

CVE-2025-53444 - WordPress Userpro plugin < 5.1.11 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in DeluxeThemes Userpro allows Cross Site Request Forgery.This issue affects Userpro: from n/a before 5.1.11.

📅 Published: April 15, 2026, 3:43 p.m. 🔄 Last Modified: April 15, 2026, 10:30 p.m.

9.3

CVSS4.0

CVE-2026-5387 - AVEVA Pipeline Simulation Missing Authorization

The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simulator Instructor or Simulator Developer (Administrator) roles, resulting in privilege escalation with potential for modification of simulation parameters, training configuration, an…

📅 Published: April 15, 2026, 3:24 p.m. 🔄 Last Modified: April 17, 2026, 3:09 p.m.

7.2

CVSS3.1

CVE-2026-20205 - Sensitive Information Disclosure in ''_internal'' index in Splunk MCP Server app

In Splunk MCP Server app versions below 1.0.3 , a user who holds a role with access to the Splunk `_internal` index or possesses the high-privilege capability `mcp_tool_admin` could view users session and authorization tokens in clear text.<br><br>The vulnerability would require either local access…

📅 Published: April 15, 2026, 3:17 p.m. 🔄 Last Modified: April 17, 2026, 3:09 p.m.

4.3

CVSS3.1

CVE-2026-20203 - Improper Access Control in Data Model Acceleration in Splunk Enterprise

In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.6, 10.2.2510.10, 10.1.2507.19, 10.0.2503.13, and 9.3.2411.127, a low-privileged user that does not hold the `admin` or `power` Splunk roles, has write permission o…

📅 Published: April 15, 2026, 3:17 p.m. 🔄 Last Modified: April 17, 2026, 7:07 p.m.

7.1

CVSS3.1

CVE-2026-20204 - Improper Handling and Insufficient Isolation of Specific Temporary Files in Splunk Enterprise

In Splunk Enterprise versions below 10.2.1, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.5, 10.2.2510.9, 10.1.2507.19, 10.0.2503.13, and 9.3.2411.127, a low-privileged user that does not hold the `admin` or `power` Splunk roles could potentially perfor…

📅 Published: April 15, 2026, 3:17 p.m. 🔄 Last Modified: April 17, 2026, 3:09 p.m.
Total resulsts: 345152
Page 44 of 34,516
« previous page » next page
Filters