0

CVSS3.1

CVE-2026-22740 - Spring Framework DoS with Multipart Temp Files in WebFlux

A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space. Older, unsupported versions are a…

πŸ“… Published: April 29, 2026, 10:46 a.m. πŸ”„ Last Modified: April 29, 2026, 10:46 a.m.

5.4

CVSS3.1

CVE-2026-42641 - WordPress Share This Image plugin <= 2.14 - Server Side Request Forgery (SSRF) vulnerability

Server-Side Request Forgery (SSRF) vulnerability in ILLID Share This Image share-this-image allows Server Side Request Forgery.This issue affects Share This Image: from n/a through <= 2.14.

πŸ“… Published: April 29, 2026, 10:40 a.m. πŸ”„ Last Modified: April 29, 2026, 10:47 a.m.

4.3

CVSS3.1

CVE-2026-42645 - WordPress Barcode Scanner with Inventory & Order Manager plugin <= 1.11.0 - Cross Site Request Forg…

Cross-Site Request Forgery (CSRF) vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders allows Cross Site Request Forgery.This issue affects Barcode Scanner with Inventory & Order Manager: f…

πŸ“… Published: April 29, 2026, 10:40 a.m. πŸ”„ Last Modified: April 29, 2026, 10:47 a.m.

4.3

CVSS3.1

CVE-2026-42648 - WordPress Spectra plugin <= 2.19.22 - Broken Access Control vulnerability

Missing Authorization vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through <= 2.19.22.

πŸ“… Published: April 29, 2026, 10:40 a.m. πŸ”„ Last Modified: April 29, 2026, 10:47 a.m.

5.3

CVSS3.1

CVE-2026-42642 - WordPress GiveWP plugin <= 4.14.5 - Broken Access Control vulnerability

Missing Authorization vulnerability in StellarWP GiveWP give allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GiveWP: from n/a through <= 4.14.5.

πŸ“… Published: April 29, 2026, 10:40 a.m. πŸ”„ Last Modified: April 29, 2026, 10:47 a.m.

7.6

CVSS3.1

CVE-2026-42646 - WordPress TaxoPress plugin <= 3.44.0 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Steve Burge TaxoPress simple-tags allows Blind SQL Injection.This issue affects TaxoPress: from n/a through <= 3.44.0.

πŸ“… Published: April 29, 2026, 10:40 a.m. πŸ”„ Last Modified: April 29, 2026, 10:47 a.m.

5.9

CVSS3.1

CVE-2026-42643 - WordPress Image Widget plugin <= 4.4.11 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StellarWP Image Widget image-widget allows Stored XSS.This issue affects Image Widget: from n/a through <= 4.4.11.

πŸ“… Published: April 29, 2026, 10:40 a.m. πŸ”„ Last Modified: April 29, 2026, 10:47 a.m.

5.3

CVSS3.1

CVE-2026-42644 - WordPress BetterDocs plugin <= 4.3.10 - Sensitive Data Exposure vulnerability

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPDeveloper BetterDocs betterdocs allows Retrieve Embedded Sensitive Data.This issue affects BetterDocs: from n/a through <= 4.3.10.

πŸ“… Published: April 29, 2026, 10:40 a.m. πŸ”„ Last Modified: April 29, 2026, 10:47 a.m.

7.1

CVSS3.1

CVE-2026-42652 - WordPress User Registration plugin <= 5.1.5 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Registration user-registration allows Reflected XSS.This issue affects User Registration: from n/a through <= 5.1.5.

πŸ“… Published: April 29, 2026, 10:40 a.m. πŸ”„ Last Modified: April 29, 2026, 10:47 a.m.

8.7

CVSS4.0

CVE-2026-42518 - Information Disclosure Vulnerability in e-Sushrut HMIS

This vulnerability exists in e-Sushrut due to disclosure of sensitive information and hardcoded AES encryption keys in client-side JavaScript. An unauthenticated remote attacker could exploit this vulnerability by accessing the client-side code to extract sensitive information and cryptographic key…

πŸ“… Published: April 29, 2026, 8:37 a.m. πŸ”„ Last Modified: April 29, 2026, 8:37 a.m.
Total resulsts: 347773
Page 67 of 34,778
Β« previous page Β» next page
Filters