4.3

CVSS3.1

CVE-2025-53444 - WordPress Userpro plugin < 5.1.11 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in DeluxeThemes Userpro allows Cross Site Request Forgery.This issue affects Userpro: from n/a before 5.1.11.

📅 Published: April 15, 2026, 3:43 p.m. 🔄 Last Modified: April 15, 2026, 10:30 p.m.

9.3

CVSS4.0

CVE-2026-5387 - AVEVA Pipeline Simulation Missing Authorization

The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simulator Instructor or Simulator Developer (Administrator) roles, resulting in privilege escalation with potential for modification of simulation parameters, training configuration, an…

📅 Published: April 15, 2026, 3:24 p.m. 🔄 Last Modified: April 17, 2026, 3:09 p.m.

7.2

CVSS3.1

CVE-2026-20205 - Sensitive Information Disclosure in ''_internal'' index in Splunk MCP Server app

In Splunk MCP Server app versions below 1.0.3 , a user who holds a role with access to the Splunk `_internal` index or possesses the high-privilege capability `mcp_tool_admin` could view users session and authorization tokens in clear text.<br><br>The vulnerability would require either local access…

📅 Published: April 15, 2026, 3:17 p.m. 🔄 Last Modified: April 17, 2026, 3:09 p.m.

4.3

CVSS3.1

CVE-2026-20203 - Improper Access Control in Data Model Acceleration in Splunk Enterprise

In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.6, 10.2.2510.10, 10.1.2507.19, 10.0.2503.13, and 9.3.2411.127, a low-privileged user that does not hold the `admin` or `power` Splunk roles, has write permission o…

📅 Published: April 15, 2026, 3:17 p.m. 🔄 Last Modified: April 17, 2026, 7:07 p.m.

7.1

CVSS3.1

CVE-2026-20204 - Improper Handling and Insufficient Isolation of Specific Temporary Files in Splunk Enterprise

In Splunk Enterprise versions below 10.2.1, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.5, 10.2.2510.9, 10.1.2507.19, 10.0.2503.13, and 9.3.2411.127, a low-privileged user that does not hold the `admin` or `power` Splunk roles could potentially perfor…

📅 Published: April 15, 2026, 3:17 p.m. 🔄 Last Modified: April 17, 2026, 3:09 p.m.

6.6

CVSS3.1

CVE-2026-20202 - Improper Input Validation during User Account Creation in Splunk Enterprise

In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.6, 10.2.2510.10, 10.1.2507.20, 10.0.2503.13, and 9.3.2411.127, a user who holds a role that contains the high-privilege capability `edit_user`could create a specia…

📅 Published: April 15, 2026, 3:17 p.m. 🔄 Last Modified: April 17, 2026, 7:10 p.m.

1.3

CVSS4.0

CVE-2025-12141 - Grafana Alerting Editors can edit destination of webhooks they did not create

In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role "Contact Point Writer", which is part of the basic role Editor - can edit contac…

📅 Published: April 15, 2026, 2:59 p.m. 🔄 Last Modified: April 17, 2026, 7 a.m.

8.7

CVSS4.0

CVE-2026-4682 - Certain HP DeskJet All In One (AIO) Devices – Potential Remote Code Execution & Potential Buffer Ov…

Certain HP DeskJet All in One devices may be vulnerable to remote code execution caused by a buffer overflow when specially crafted Web Services for Devices (WSD) scan requests are improperly validated and handled by the MFP. WSD Scan is a Microsoft Windows–based network scanning protocol that a…

📅 Published: April 15, 2026, 2:32 p.m. 🔄 Last Modified: April 17, 2026, 3:09 p.m.

7.3

CVSS4.0

CVE-2026-4667 - HP System Optimizer - Escalation of Privilege

HP System Optimizer might potentially be vulnerable to escalation of privilege. HP is releasing an update to mitigate this potential vulnerability.

📅 Published: April 15, 2026, 2:22 p.m. 🔄 Last Modified: April 17, 2026, 3:09 p.m.

6.5

CVSS3.1

CVE-2026-25219 - Apache Airflow: Sensitive Azure Service Bus connection string (and possibly other providers) expose…

The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. This means that user with read permission could see the values in Connection UI, as well as when Connection was accidentaly logged to logs, those values could be seen in the logs. Az…

📅 Published: April 15, 2026, 12:30 p.m. 🔄 Last Modified: April 17, 2026, 6:37 p.m.
Total resulsts: 345157
Page 45 of 34,516
« previous page » next page
Filters