4.3

CVSS3.1

CVE-2026-6703 - Responsive Blocks <= 2.2.1 - Missing Authorization to Authenticated (Contributor+) Arbitrary Modifi…

The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated…

📅 Published: April 21, 2026, 6:43 a.m. 🔄 Last Modified: April 22, 2026, 11:46 a.m.

7.8

CVSS3.1

CVE-2026-31368 - Privilege Bypass in AiAssistant

AiAssistant is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availability.

📅 Published: April 21, 2026, 6:40 a.m. 🔄 Last Modified: April 21, 2026, 11:15 p.m.

6.3

CVSS3.1

CVE-2026-31370 - Information Leak Vulnerability in Honor E

Honor E APP is affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confidentiality.

📅 Published: April 21, 2026, 6:30 a.m. 🔄 Last Modified: April 21, 2026, 11:15 p.m.

3.2

CVSS3.1

CVE-2026-31369 - Privilege Bypass in PcManager

PcManager is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availability

📅 Published: April 21, 2026, 6:26 a.m. 🔄 Last Modified: April 22, 2026, 11:46 a.m.

9.3

CVSS4.0

CVE-2026-5965 - NewSoft|NewSoftOA - OS Command Injection

NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.

📅 Published: April 21, 2026, 3:32 a.m. 🔄 Last Modified: April 22, 2026, 3:30 a.m.

6.5

CVSS3.1

CVE-2026-6674 - Plugin: CMS für Motorrad Werkstätten <= 1.0.0 - Authenticated (Subscriber+) SQL Injection via 'artt…

The Plugin: CMS für Motorrad Werkstätten plugin for WordPress is vulnerable to SQL Injection via the 'arttype' parameter in all versions up to, and including, 1.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes i…

📅 Published: April 21, 2026, 2:25 a.m. 🔄 Last Modified: April 22, 2026, 11:46 a.m.

5.3

CVSS3.1

CVE-2026-6675 - Responsive Blocks <= 2.2.0 - Unauthenticated Open Email Relay via REST API 'email_to' Parameter

The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to Unauthenticated Open Email Relay in all versions up to, and including, 2.2.0. This is due to insufficient authorization checks and missing server-side validation of the recipient email address supplied …

📅 Published: April 21, 2026, 2:25 a.m. 🔄 Last Modified: April 22, 2026, 11:46 a.m.

8.1

CVSS3.1

CVE-2026-40497 - FreeScout Vulnerable to CSS Injection via Stored Style Tag in Mailbox Signature (CSRF Token Exfiltr…

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's `Helper::stripDangerousTags()` removes `<script>`, `<form>`, `<iframe>`, `<object>` but does NOT strip `<style>` tags. The mailbox signature field is saved via POST /mailbox/settings/{id} and later r…

📅 Published: April 21, 2026, 1:45 a.m. 🔄 Last Modified: April 21, 2026, 3:37 p.m.

4.5

CVSS3.1

CVE-2026-6058 - Denial of Service via Improper Encoding in Zyxel WRE6505 Web Management Interface

** UNSUPPORTED WHEN ASSIGNED ** An improper encoding or escaping vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the WLAN to cause a denial-of-service (DoS) condition in the web management interface by convincing an authentic…

📅 Published: April 21, 2026, 1:42 a.m. 🔄 Last Modified: April 22, 2026, 11:46 a.m.

8.8

CVSS4.0

CVE-2026-40496 - FreeScout has Predictable Attachment Token that Allows Unauthenticated Private File Download via Br…

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, attachment download tokens are generated using a weak and predictable formula: `md5(APP_KEY + attachment_id + size)`. Since attachment_id is sequential and size can be brute-forced in a small range, an unauthent…

📅 Published: April 21, 2026, 1:38 a.m. 🔄 Last Modified: April 21, 2026, 1:50 p.m.
Total resulsts: 346103
Page 68 of 34,611
« previous page » next page
Filters