6.4

CVSS3.1

CVE-2026-2949 - Xpro Addons — 140+ Widgets for Elementor <= 1.4.24 - Authenticated (Contributor+) Stored Cross-Site…

The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Icon Box widget in versions up to, and including, 1.4.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contri…

📅 Published: April 4, 2026, 2:26 a.m. 🔄 Last Modified: April 24, 2026, 6:13 p.m.

6.4

CVSS3.1

CVE-2026-2924 - Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem <= 3.4.6 - Authenticated (Contributor…

The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'imageLoad' parameter in versions up to, and including, 3.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authentica…

📅 Published: April 4, 2026, 2:26 a.m. 🔄 Last Modified: April 24, 2026, 6:13 p.m.

6.5

CVSS3.1

CVE-2026-3571 - Pie Register – User Registration, Profiles & Content Restriction <= 3.8.4.8 - Missing Authorization…

The Pie Register – User Registration, Profiles & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pie_main() function in all versions up to, and including, 3.8.4.8. This makes it possible for unauthenticated attacke…

📅 Published: April 4, 2026, 1:24 a.m. 🔄 Last Modified: April 24, 2026, 6:13 p.m.

9.1

CVSS3.1

CVE-2026-35616 -

A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

📅 Published: April 4, 2026, 12:38 a.m. 🔄 Last Modified: April 28, 2026, 9:45 p.m.

8.4

CVSS3.1

CVE-2026-34780 - Electron: Context Isolation bypass via contextBridge VideoFrame transfer

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 39.0.0-alpha.1 to before 39.8.0, 40.0.0-alpha.1 to before 40.7.0, and 41.0.0-alpha.1 to before 41.0.0-beta.8, apps that pass VideoFrame objects (from the WebCodecs API) across the c…

📅 Published: April 4, 2026, 12:02 a.m. 🔄 Last Modified: April 15, 2026, 4:30 p.m.

6.5

CVSS3.1

CVE-2026-34779 - Electron: AppleScript injection in app.moveToApplicationsFolder on macOS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on macOS, app.moveToApplicationsFolder() used an AppleScript fallback path that did not properly handle certain characters in the appl…

📅 Published: April 4, 2026, midnight 🔄 Last Modified: April 15, 2026, 4:30 p.m.

5.9

CVSS3.1

CVE-2026-34778 - Electron: Service worker can spoof executeJavaScript IPC replies

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, a service worker running in a session could spoof reply messages on the internal IPC channel used by webContents.executeJavaScript() and rela…

📅 Published: April 3, 2026, 11:59 p.m. 🔄 Last Modified: April 20, 2026, 2:22 p.m.

5.4

CVSS3.1

CVE-2026-34777 - Electron: Incorrect origin passed to permission request handler for iframe requests

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, when an iframe requests fullscreen, pointerLock, keyboardLock, openExternal, or media permissions, the origin passed to session.setPermission…

📅 Published: April 3, 2026, 11:57 p.m. 🔄 Last Modified: April 20, 2026, 2:19 p.m.

5.3

CVSS3.1

CVE-2026-34776 - Electron: Out-of-bounds read in second-instance IPC on macOS and Linux

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, on macOS and Linux, apps that call app.requestSingleInstanceLock() were vulnerable to an out-of-bounds heap read when parsing a crafted secon…

📅 Published: April 3, 2026, 11:56 p.m. 🔄 Last Modified: April 27, 2026, 1:09 p.m.

6.8

CVSS3.1

CVE-2026-34775 - Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.4, 40.8.4, and 41.0.0, the nodeIntegrationInWorker webPreference was not correctly scoped in all configurations. In certain process-sharing scenarios, workers spawn…

📅 Published: April 3, 2026, 11:55 p.m. 🔄 Last Modified: April 22, 2026, 5:49 p.m.
Total resulsts: 349182
Page 694 of 34,919
« previous page » next page
Filters