5.3

CVSS4.0

CVE-2026-39851 - Saleor has a user enumeration vulnerability due to different error messages

Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, the requestEmailChange() mutation was revealing the existence of user-provided email addresses in error messages. This vulnerability is fixed in 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118.

πŸ“… Published: April 8, 2026, 5:33 p.m. πŸ”„ Last Modified: April 8, 2026, 7:25 p.m.

8.4

CVSS4.0

CVE-2025-30650 - Junos OS: Privileged local user can gain access to a Linux-based FPC as root

AΒ Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to line cards running Junos OS Evolved as root. This issue affects systems running Junos OS using Linux-based line cards. Affected lin…

πŸ“… Published: April 8, 2026, 5:26 p.m. πŸ”„ Last Modified: April 9, 2026, 9:32 p.m.

5.4

CVSS3.1

CVE-2026-0811 - Advanced CF7 DB <= 2.0.9 - Cross-Site Request Forgery to Form Entry Deletion

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.9. This is due to missing or incorrect nonce validation on the 'vsz_cf7_save_setting_callback' function. This makes it possible for unauthenticated attackers to …

πŸ“… Published: April 8, 2026, 5:25 p.m. πŸ”„ Last Modified: April 8, 2026, 7:24 p.m.

4.3

CVSS3.1

CVE-2026-0814 - Advanced CF7 DB <= 2.0.9 - Missing Authorization to Authenticated (Subscriber+) Form Submissions Ex…

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'vsz_cf7_export_to_excel' function in all versions up to, and including, 2.0.9. This makes it possible for authenticated attackers, with Subscriber-level access …

πŸ“… Published: April 8, 2026, 5:25 p.m. πŸ”„ Last Modified: April 9, 2026, 8:18 a.m.

9.8

CVSS3.1

CVE-2026-2942 - ProSolution WP Client <= 1.9.9 - Unauthenticated Arbitrary File Upload via proSol_fileUploadProcess

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadProcess' function in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated attackers to upload arbitrary files on the af…

πŸ“… Published: April 8, 2026, 5:25 p.m. πŸ”„ Last Modified: April 8, 2026, 7:25 p.m.

5.9

CVSS4.0

CVE-2026-35407 - Saleor has Cross-Account Email Change via Unbound Confirmation Token

Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a business-logic and authorization flaw was found in the account email change workflow, the confirmation flow did not verify that the email change confirmation token was issued for the given authentica…

πŸ“… Published: April 8, 2026, 5:24 p.m. πŸ”„ Last Modified: April 10, 2026, 9:16 p.m.

7.5

CVSS3.1

CVE-2026-35401 - Saleor has a resource exhaustion vulnerability in GraphQL queries

Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a malicious actor can include many GraphQL mutations or queries in a single API call using aliases or chaining multiple mutations, resulting in resource exhaustion. This vulnerability is fixed in 3.23.0…

πŸ“… Published: April 8, 2026, 5:22 p.m. πŸ”„ Last Modified: April 8, 2026, 7:25 p.m.

7.5

CVSS3.1

CVE-2026-33756 - Saleor Affected by Denial of Service via Unbounded GraphQL Query Batching

Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, Saleor supports query batching by submitting multiple GraphQL operations in a single HTTP request as a JSON array but wasn't enforcing any upper limit on the number of operations. This allowed an unauth…

πŸ“… Published: April 8, 2026, 5:07 p.m. πŸ”„ Last Modified: April 8, 2026, 9:26 p.m.

8.1

CVSS3.1

CVE-2026-33466 - Improper Limitation of a Pathname to a Restricted Directory in Logstash Leading to Arbitrary File W…

Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash can lead to arbitrary file write and potentially remote code execution via Relative Path Traversal (CAPEC-139). The archive extraction utilities used by Logstash do not properly validate file paths within compressed ar…

πŸ“… Published: April 8, 2026, 4:50 p.m. πŸ”„ Last Modified: April 10, 2026, 3:56 a.m.

6.8

CVSS3.1

CVE-2026-33458 - Server-Side Request Forgery (SSRF) in Kibana One Workflow Leading to Information Disclosure

Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user with workflow creation and execution privileges can bypass host allowlist restrictions in the Workflows Execution Engine, potentially exposing sensitive internal endpoints and data.

πŸ“… Published: April 8, 2026, 4:47 p.m. πŸ”„ Last Modified: April 8, 2026, 7:26 p.m.
Total resulsts: 343924
Page 66 of 34,393
Β« previous page Β» next page
Filters