0.0

CVE-2026-4112 -

Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with read-only administrator privileges to escalate privileges to primary administrator.

📅 Published: April 9, 2026, 2:22 p.m. 🔄 Last Modified: April 10, 2026, 3:56 a.m.

7.5

CVSS3.1

CVE-2026-4660 - Go-getter may allow to arbitrary filesystem reads through git operations

HashiCorp’s go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This vulnerability, CVE-2026-4660, is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package.

📅 Published: April 9, 2026, 1:47 p.m. 🔄 Last Modified: April 10, 2026, 8:53 a.m.

5.3

CVSS3.1

CVE-2026-2519 - Online Scheduling and Appointment Booking System – Bookly <= 27.0 - Unauthenticated Price Manipulat…

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to price manipulation via the 'tips' parameter in all versions up to, and including, 27.0. This is due to the plugin trusting a user-supplied input without server-side validation against the configured …

📅 Published: April 9, 2026, 12:28 p.m. 🔄 Last Modified: April 10, 2026, 8:53 a.m.

6.4

CVSS3.1

CVE-2026-3005 - List category posts <= 0.94.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'catlist' S…

The List category posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catlist' shortcode in all versions up to, and including, 0.94.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticate…

📅 Published: April 9, 2026, 12:28 p.m. 🔄 Last Modified: April 9, 2026, 5:41 p.m.

9.1

CVSS3.1

CVE-2025-57735 - Apache Airflow: Airflow Logout Not Invalidating JWT

When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was intercepted. In Airflow 3.2 we implemented the mechanism that implements token invalidation at logout. Users who are concerned about the logout scenario a…

📅 Published: April 9, 2026, 11:12 a.m. 🔄 Last Modified: April 10, 2026, 9:32 a.m.

7.2

CVSS3.1

CVE-2024-1490 - Wago: Vulnerability in WBM through Open VPN

An authenticated remote attacker with high privileges can exploit the OpenVPN configuration via the web-based management interface of a WAGO PLC. If user-defined scripts are permitted, OpenVPN may allow the execution of arbitrary shell commands enabling the attacker to run arbitrary commands on the…

📅 Published: April 9, 2026, 10:52 a.m. 🔄 Last Modified: April 10, 2026, 8:53 a.m.

3.7

CVSS3.1

CVE-2026-24661 - Unbounded Request Body Read in MS Teams Plugin {{/changes}} Webhook Endpoint

Mattermost Plugins versions <=2.1.3.0 fail to limit the request body size on the {{/changes}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-00611

📅 Published: April 9, 2026, 10:12 a.m. 🔄 Last Modified: April 10, 2026, 8:53 a.m.

3.7

CVSS3.1

CVE-2026-21388 - Unbounded Request Body Read in MS Teams Plugin {{/lifecycle}} Webhook Endpoint

Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-00610

📅 Published: April 9, 2026, 10:09 a.m. 🔄 Last Modified: April 10, 2026, 8:53 a.m.

8.7

CVSS4.0

CVE-2026-34185 - SQL Injection in Hydrosystem Control System

Hydrosystem Control System is vulnerable to SQL Injection across most scripts and input parameters. Because no protections are in place, an authenticated attacker can inject arbitrary SQL commands, potentially gaining full control over the database.This issue was fixed in Hydrosystem Control System…

📅 Published: April 9, 2026, 9:41 a.m. 🔄 Last Modified: April 10, 2026, 8:53 a.m.

8.8

CVSS4.0

CVE-2026-34184 - Missing Authorization in Hydrosystem Control System

Hydrosystem Control System does not enforce authorization for some directories. This allows an unauthorized attacker to read all files in these directories and even execute some of them. Critically the attacker could run PHP scripts directly on the connected database.This issue was fixed in Hydrosy…

📅 Published: April 9, 2026, 9:41 a.m. 🔄 Last Modified: April 10, 2026, 8:53 a.m.
Total resulsts: 343935
Page 48 of 34,394
« previous page » next page
Filters