8.1

CVSS3.1

CVE-2025-9661 - OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual S…

OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One Block 23, 24, 26 and 28. This issue affects Hitachi Virtual Storage Platform One Block 23/24/26/28: before DKCMAIN A3-04-21-40/00, ESM A3-04-21/00.

📅 Published: May 7, 2026, 7:08 a.m. 🔄 Last Modified: May 7, 2026, 9:25 p.m.

5.7

CVSS3.1

CVE-2026-44406 - DLL Hijacking Vulnerability in ZTE Cloud PC Client uSmartview

ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.contains a DLL hijacking vulnerability; since uSmartViewServi…

📅 Published: May 7, 2026, 6:49 a.m. 🔄 Last Modified: May 7, 2026, 6:49 a.m.

9.3

CVSS4.0

CVE-2026-41586 - ObjectInputStream.readObject() without ObjectInputFilter in fabric-sdk-java allows Java deserializa…

Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. From versions 1.0.0 to 2.2.26, Channel.java implements readObject() and exposes deSerializeChannel() which call ObjectInputStream.readObject() on untrusted byte arrays with…

📅 Published: May 7, 2026, 5:12 a.m. 🔄 Last Modified: May 7, 2026, 5:12 a.m.

8.8

CVSS3.1

CVE-2026-41143 - YesWiki vulnerable to authenticated SQL Injection via id_fiche in EntryManager::formatDataBeforeSav…

YesWiki is a wiki system written in PHP. Prior to version 4.6.1, YesWiki bazar module contains a SQL injection vulnerability in tools/bazar/services/EntryManager.php at line 704. The $data['id_fiche'] value (sourced from $_POST['id_fiche']) is concatenated directly into a raw SQL query without any …

📅 Published: May 7, 2026, 5:08 a.m. 🔄 Last Modified: May 7, 2026, 5:08 a.m.

8.8

CVSS3.1

CVE-2026-41139 - Unsafe array index getter in mathjs

Math.js is an extensive math library for JavaScript and Node.js. From version 13.1.0 to before version 15.2.0, arbitrary JavaScript can be executed via the expression parser of mathjs. This issue has been patched in version 15.2.0.

📅 Published: May 7, 2026, 5:06 a.m. 🔄 Last Modified: May 7, 2026, 3:15 p.m.

8.1

CVSS3.1

CVE-2026-7252 - WP-Optimize <= 4.5.2 - Authenticated (Author+) Arbitrary File Deletion via 'original-file' Post Meta

The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unscheduled_original_file_deletion function in all versions up to, and including, 4.5.2 T…

📅 Published: May 7, 2026, 4:27 a.m. 🔄 Last Modified: May 7, 2026, 4:27 a.m.

8.8

CVSS3.1

CVE-2026-6692 - Slider Revolution 7.0.0 - 7.0.10 - Authenticated (Subscriber+) Arbitrary File Upload via _get_media…

The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7.0.0 to 7.0.10 via the '_get_media_url' and '_check_file_path' function. This is due to insufficient file type validation. This makes it possible for authenticated attackers, with subscriber-level access …

📅 Published: May 7, 2026, 4:27 a.m. 🔄 Last Modified: May 7, 2026, 4:27 a.m.

7.5

CVSS3.1

CVE-2026-4348 - BetterDocs Pro <= 3.7.0 - Unauthenticated SQL Injection via Encyclopedia 'limit' Parameter

The BetterDocs Pro plugin for WordPress is vulnerable to SQL Injection via the `get_current_letter_docs` and `docs_sort_by_letter` AJAX actions in all versions up to, and including, 3.7.0. This is due to the `limit` POST parameter being interpolated directly into a SQL query string before being pas…

📅 Published: May 7, 2026, 4:27 a.m. 🔄 Last Modified: May 7, 2026, 9:25 p.m.

5

CVSS3.1

CVE-2026-41413 - Istio Vulnerable to SSRF via RequestAuthentication jwksUri

Istio is an open platform to connect, manage, and secure microservices. Prior to versions 1.28.6 and 1.29.2, when a RequestAuthentication resource is created with a jwksUri pointing to an internal service, istiod makes an unauthenticated HTTP GET request to that URL without filtering out localhost …

📅 Published: May 7, 2026, 4:18 a.m. 🔄 Last Modified: May 7, 2026, 4:18 a.m.

7.2

CVSS3.1

CVE-2026-41641 - NocoBase Vulnerable to SQL Validation Bypass via `sqlCollection:update` Missing `checkSQL` Call

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.39, the checkSQL() validation function that blocks dangerous SQL keywords (e.g., pg_read_file, LOAD_FILE, dblink) is applied on the collections:create and sqlCollect…

📅 Published: May 7, 2026, 4:13 a.m. 🔄 Last Modified: May 7, 2026, 8:23 p.m.
Total resulsts: 349182
Page 50 of 34,919
« previous page » next page
Filters