6.9

CVSS4.0

CVE-2026-0827 - Local Privilege Escalation via Arbitrary File Write in Lenovo Diagnostics and Vantage

During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage that, during installation or when using hardware scan, could allow a local authenticated user to perform an arbitrary file write with elevated priv…

πŸ“… Published: April 15, 2026, 12:27 p.m. πŸ”„ Last Modified: April 17, 2026, 3:09 p.m.

6.1

CVSS3.1

CVE-2026-1852 - Product Pricing Table by WooBeWoo <= 1.1.0 - Cross-Site Request Forgery to Stored XSS and Pricing T…

The Product Pricing Table by WooBeWoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing or incorrect nonce validation on the updateLabel() and remove() functions. This makes it possible for unauthenticated attackers …

πŸ“… Published: April 15, 2026, 11:30 a.m. πŸ”„ Last Modified: April 15, 2026, 11:30 a.m.

6.5

CVSS3.1

CVE-2026-3590 - Race Condition in Guest Magic Link Authentication Allows Token Reuse

Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to enforce atomic single-use consumption of guest magic link tokens, which allows an attacker with access to a valid magic link to establish multiple independent authenticated sessions via concurrent …

πŸ“… Published: April 15, 2026, 11 a.m. πŸ”„ Last Modified: April 17, 2026, 3:09 p.m.

7.5

CVSS3.1

CVE-2026-30778 - Apache SkyWalking: The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configurat…

The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL. This issue affects Apache SkyWalking: from 9.7.0 through 10.3.0. Users are recommended to upgrade to version 10.4.0, which fixes the issue.

πŸ“… Published: April 15, 2026, 10:54 a.m. πŸ”„ Last Modified: April 16, 2026, 1:16 p.m.

4.3

CVSS3.1

CVE-2026-40786 - WordPress MyRewards plugin <= 5.7.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in Long Watch Studio MyRewards woorewards allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MyRewards: from n/a through <= 5.7.3.

πŸ“… Published: April 15, 2026, 10:21 a.m. πŸ”„ Last Modified: April 17, 2026, 8 a.m.

8.1

CVSS3.1

CVE-2026-40784 - WordPress FluentBoards plugin <= 1.91.2 - Insecure Direct Object References (IDOR) vulnerability

Authorization Bypass Through User-Controlled Key vulnerability in Mahmudul Hasan Arif FluentBoards fluent-boards allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FluentBoards: from n/a through <= 1.91.2.

πŸ“… Published: April 15, 2026, 10:21 a.m. πŸ”„ Last Modified: April 16, 2026, 2:45 a.m.

5.3

CVSS3.1

CVE-2026-40778 - WordPress Majestic Support plugin <= 1.1.2 - Broken Access Control vulnerability

Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a through <= 1.1.2.

πŸ“… Published: April 15, 2026, 10:21 a.m. πŸ”„ Last Modified: April 17, 2026, 7 a.m.

8.1

CVSS3.1

CVE-2026-40764 - WordPress Contact Form by WPForms plugin <= 1.10.0.2 - Cross Site Request Forgery (CSRF) vulnerabil…

Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Cross Site Request Forgery.This issue affects Contact Form by WPForms: from n/a through <= 1.10.0.2.

πŸ“… Published: April 15, 2026, 10:21 a.m. πŸ”„ Last Modified: April 15, 2026, 7:30 p.m.

5.3

CVSS3.1

CVE-2026-40763 - WordPress Royal Elementor Addons plugin <= 1.7.1056 - Broken Access Control vulnerability

Missing Authorization vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Royal Elementor Addons: from n/a through <= 1.7.1056.

πŸ“… Published: April 15, 2026, 10:21 a.m. πŸ”„ Last Modified: April 17, 2026, 7:15 a.m.

7.6

CVSS3.1

CVE-2026-40745 - WordPress Element Pack Elementor Addons plugin <= 8.4.2 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bdthemes Element Pack Elementor Addons bdthemes-element-pack-lite allows Blind SQL Injection.This issue affects Element Pack Elementor Addons: from n/a through <= 8.4.2.

πŸ“… Published: April 15, 2026, 10:21 a.m. πŸ”„ Last Modified: April 15, 2026, 10:30 p.m.
Total resulsts: 345253
Page 56 of 34,526
Β« previous page Β» next page
Filters