4.3

CVSS3.1

CVE-2026-0814 - Advanced CF7 DB <= 2.0.9 - Missing Authorization to Authenticated (Subscriber+) Form Submissions Ex…

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'vsz_cf7_export_to_excel' function in all versions up to, and including, 2.0.9. This makes it possible for authenticated attackers, with Subscriber-level access …

πŸ“… Published: April 8, 2026, 5:25 p.m. πŸ”„ Last Modified: April 9, 2026, 8:18 a.m.

9.8

CVSS3.1

CVE-2026-2942 - ProSolution WP Client <= 1.9.9 - Unauthenticated Arbitrary File Upload via proSol_fileUploadProcess

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadProcess' function in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated attackers to upload arbitrary files on the af…

πŸ“… Published: April 8, 2026, 5:25 p.m. πŸ”„ Last Modified: April 8, 2026, 7:25 p.m.

5.9

CVSS4.0

CVE-2026-35407 - Saleor has Cross-Account Email Change via Unbound Confirmation Token

Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a business-logic and authorization flaw was found in the account email change workflow, the confirmation flow did not verify that the email change confirmation token was issued for the given authentica…

πŸ“… Published: April 8, 2026, 5:24 p.m. πŸ”„ Last Modified: April 10, 2026, 8:36 p.m.

7.5

CVSS3.1

CVE-2026-35401 - Saleor has a resource exhaustion vulnerability in GraphQL queries

Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a malicious actor can include many GraphQL mutations or queries in a single API call using aliases or chaining multiple mutations, resulting in resource exhaustion. This vulnerability is fixed in 3.23.0…

πŸ“… Published: April 8, 2026, 5:22 p.m. πŸ”„ Last Modified: April 8, 2026, 7:25 p.m.

7.5

CVSS3.1

CVE-2026-33756 - Saleor Affected by Denial of Service via Unbounded GraphQL Query Batching

Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, Saleor supports query batching by submitting multiple GraphQL operations in a single HTTP request as a JSON array but wasn't enforcing any upper limit on the number of operations. This allowed an unauth…

πŸ“… Published: April 8, 2026, 5:07 p.m. πŸ”„ Last Modified: April 8, 2026, 9:26 p.m.

8.1

CVSS3.1

CVE-2026-33466 - Improper Limitation of a Pathname to a Restricted Directory in Logstash Leading to Arbitrary File W…

Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash can lead to arbitrary file write and potentially remote code execution via Relative Path Traversal (CAPEC-139). The archive extraction utilities used by Logstash do not properly validate file paths within compressed ar…

πŸ“… Published: April 8, 2026, 4:50 p.m. πŸ”„ Last Modified: April 10, 2026, 3:56 a.m.

6.8

CVSS3.1

CVE-2026-33458 - Server-Side Request Forgery (SSRF) in Kibana One Workflow Leading to Information Disclosure

Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user with workflow creation and execution privileges can bypass host allowlist restrictions in the Workflows Execution Engine, potentially exposing sensitive internal endpoints and data.

πŸ“… Published: April 8, 2026, 4:47 p.m. πŸ”„ Last Modified: April 8, 2026, 7:26 p.m.

6.5

CVSS3.1

CVE-2026-33459 - Uncontrolled Resource Consumption in Kibana Leading to Denial of Service

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with access to the automatic import feature can submit specially crafted requests with excessively large input values. When multiple such requests are sent…

πŸ“… Published: April 8, 2026, 4:46 p.m. πŸ”„ Last Modified: April 9, 2026, 2:24 p.m.

4.3

CVSS3.1

CVE-2026-33460 - Incorrect Authorization in Kibana Fleet Leading to Information Disclosure

Incorrect Authorization (CWE-863) in Kibana can lead to cross-space information disclosure via Privilege Abuse (CAPEC-122). A user with Fleet agent management privileges in one Kibana space can retrieve Fleet Server policy details from other spaces through an internal enrollment endpoint. The endpo…

πŸ“… Published: April 8, 2026, 4:43 p.m. πŸ”„ Last Modified: April 9, 2026, 2:26 p.m.

5.3

CVSS3.1

CVE-2025-14243 - Mirror-registry: openshift mirror registry: user enumeration via authentication error messages

A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enumerate valid usernames and email addresses via different error messages during authentication failures and account creation.

πŸ“… Published: April 8, 2026, 4:41 p.m. πŸ”„ Last Modified: April 8, 2026, 7:22 p.m.
Total resulsts: 343921
Page 66 of 34,393
Β« previous page Β» next page
Filters