6.5

CVSS3.1

CVE-2026-4749 - NVD-CWE-noinfo in albfan miraclecast

NVD-CWE-noinfo vulnerability in albfan miraclecast.This issue affects miraclecast: before v1.0.

📅 Published: March 24, 2026, 5:35 a.m. 🔄 Last Modified: March 24, 2026, 5:35 a.m.

7.5

CVSS3.1

CVE-2026-4662 - JetEngine <= 3.8.6.1 - Unauthenticated SQL Injection via Listing Grid 'filtered_query' Parameter

The JetEngine plugin for WordPress is vulnerable to SQL Injection via the `listing_load_more` AJAX action in all versions up to, and including, 3.8.6.1. This is due to the `filtered_query` parameter being excluded from the HMAC signature validation (allowing attacker-controlled input to bypass secu…

📅 Published: March 24, 2026, 4:27 a.m. 🔄 Last Modified: March 24, 2026, 4:27 a.m.

9.1

CVSS3.1

CVE-2026-4283 - WP DSGVO Tools (GDPR) <= 3.1.38 - Missing Authorization to Unauthenticated Account Destruction of N…

The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, and including, 3.1.38. This is due to the `super-unsubscribe` AJAX action accepting a `process_now` parameter from unauthenticated users, which bypasses the intended email-confirm…

📅 Published: March 24, 2026, 4:27 a.m. 🔄 Last Modified: March 24, 2026, 4:27 a.m.

6.5

CVSS3.1

CVE-2026-3138 - Product Filter for WooCommerce by WBW <= 3.1.2 - Missing Authorization to Unauthenticated Filter Da…

The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check in all versions up to, and including, 3.1.2. This is due to the plugin's MVC framework dynamically registering unauthenticated AJAX handlers via `wp_ajax_nopriv_`…

📅 Published: March 24, 2026, 4:27 a.m. 🔄 Last Modified: March 24, 2026, 4:27 a.m.

8.7

CVSS4.0

CVE-2026-4640 - Galaxy Software Services|Vitals ESP - Missing Authentication

Vitals ESP developed by Galaxy Software Services has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to execute certain functions to obtain sensitive information.

📅 Published: March 24, 2026, 4:20 a.m. 🔄 Last Modified: March 24, 2026, 4:20 a.m.

8.7

CVSS4.0

CVE-2026-4639 - Galaxy Software Services|Vitals ESP - Incorrect Authorization

Vitals ESP developed by Galaxy Software Services has a Incorrect Authorization vulnerability, allowing authenticated remote attackers to perform certain administrative functions, thereby escalating privileges.

📅 Published: March 24, 2026, 4:17 a.m. 🔄 Last Modified: March 24, 2026, 4:17 a.m.

5.9

CVSS3.1

CVE-2026-3260 - Undertow: undertow: denial of service due to premature multipart/form-data parsing in get requests

A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending an HTTP GET request containing multipart/form-data content. If the underlying application processes parameters using methods like `getParameterMap()`, the server prematurely parses and stores this content to…

📅 Published: March 24, 2026, 4:11 a.m. 🔄 Last Modified: March 24, 2026, 4:12 a.m.

6.9

CVSS4.0

CVE-2026-4632 - itsourcecode Online Enrollment System Parameter index.php sql injection

A weakness has been identified in itsourcecode Online Enrollment System 1.0. This vulnerability affects unknown code of the file /sms/user/index.php?view=add of the component Parameter Handler. Executing a manipulation of the argument Name can lead to sql injection. The attack may be performed from…

📅 Published: March 24, 2026, 4:09 a.m. 🔄 Last Modified: March 24, 2026, 4:09 a.m.

8.6

CVSS4.0

CVE-2026-4627 - D-Link DIR-825/DIR-825R NTP Service libdeuteron_modules.so handler_update_system_time os command in…

A vulnerability was found in D-Link DIR-825 and DIR-825R 1.0.5/4.5.1. Affected is the function handler_update_system_time of the file libdeuteron_modules.so of the component NTP Service. The manipulation results in os command injection. The attack may be launched remotely. This vulnerability only a…

📅 Published: March 24, 2026, 3:32 a.m. 🔄 Last Modified: March 24, 2026, 3:32 a.m.

10

CVSS4.0

CVE-2026-4746 - Heap Buffer Over-Write Vulenrabilty in timeplus-io/proton

Out-of-bounds Write vulnerability in timeplus-io proton (base/poco/Foundation/src‎ modules). This vulnerability is associated with program files inflate.C. This issue affects proton: before 1.6.16.

📅 Published: March 24, 2026, 3:28 a.m. 🔄 Last Modified: March 24, 2026, 6:25 p.m.
Total resulsts: 340365
Page 75 of 34,037
« previous page » next page
Filters