7.3

CVSS3.1

CVE-2026-42377 - WordPress SureForms Pro plugin <= 2.8.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in Brainstorm Force SureForms Pro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms Pro: from n/a through 2.8.0.

πŸ“… Published: April 29, 2026, 7:27 a.m. πŸ”„ Last Modified: April 29, 2026, 7:27 a.m.

6.9

CVSS4.0

CVE-2026-21023 -

Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local attackers to modify the installation restriction of specific application.

πŸ“… Published: April 29, 2026, 4:46 a.m. πŸ”„ Last Modified: April 29, 2026, 4:46 a.m.

7.1

CVSS3.1

CVE-2026-35155 -

Dell iDRAC10, versions 1.20.70.50 and 1.30.05.10, contains an Insufficiently Protected Credentials vulnerability. A race condition vulnerability exists that could allow an authenticated low‑privileged attacker to gain elevated access.

πŸ“… Published: April 29, 2026, 3:50 a.m. πŸ”„ Last Modified: April 29, 2026, 3:50 a.m.

4.3

CVSS3.1

CVE-2026-23773 -

Dell Disk Library for Mainframe, version(s) DLm 8700/2700 contain(s) a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.

πŸ“… Published: April 29, 2026, 3:39 a.m. πŸ”„ Last Modified: April 29, 2026, 3:39 a.m.

7.2

CVSS3.1

CVE-2026-42615 -

GCHQ CyberChef before 11.0.0 allows XSS via Show Base64 offsets, as demonstrated by the /#recipe=Show_Base64_offsets('%3Cscript substring.

πŸ“… Published: April 29, 2026, 2:55 a.m. πŸ”„ Last Modified: April 29, 2026, 2:56 a.m.

0.0

CVE-2026-36837 -

TOTOLINK A3002RU V3 <= V3.0.0-B20220304.1804 was discovered to contain a stack-based buffer overflow via the hostname parameter in the formMapDelDevice function.

πŸ“… Published: April 29, 2026, midnight πŸ”„ Last Modified: April 29, 2026, 2:17 p.m.

0.0

CVE-2026-30769 -

An issue in the TVicPort64.sys component of EnTech Taiwan TVicPort Product v4.0, File v5.2.1.0 allows attackers to escalate privileges via sending crafted IOCTL 0x80002008 requests.

πŸ“… Published: April 29, 2026, midnight πŸ”„ Last Modified: April 29, 2026, 4:02 p.m.

0.0

CVE-2025-56535 -

A cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the zone attribute parameter.

πŸ“… Published: April 29, 2026, midnight πŸ”„ Last Modified: April 29, 2026, 3:57 p.m.

0.0

CVE-2026-36841 -

TOTOLINK N200RE V5 was discovered to contain a command injection vulnerability via the macstr and bandstr parameters in the formMapDelDevice function.

πŸ“… Published: April 29, 2026, midnight πŸ”„ Last Modified: April 29, 2026, 2:21 p.m.

3.7

CVSS3.1

CVE-2026-6276 - curl: libcurl: Information disclosure due to cookie leak when reusing connections with custom Host …

A flaw was found in libcurl. This vulnerability allows for information disclosure when a custom `Host:` header is used in an initial HTTP request, and a subsequent request reuses the same connection without specifying a new `Host:` header. This can lead to libcurl incorrectly sending cookies intend…

πŸ“… Published: April 29, 2026, midnight πŸ”„ Last Modified: April 29, 2026, midnight
Total resulsts: 347814
Page 73 of 34,782
Β« previous page Β» next page
Filters