6.9

CVSS4.0

CVE-2026-5258 - Sanster IOPaint File Manager file_manager.py _get_file path traversal

A vulnerability was found in Sanster IOPaint 1.5.3. Impacted is the function _get_file of the file iopaint/file_manager/file_manager.py of the component File Manager. Performing a manipulation of the argument filename results in path traversal. The attack is possible to be carried out remotely. The…

πŸ“… Published: April 1, 2026, 6:45 a.m. πŸ”„ Last Modified: April 24, 2026, 6:12 p.m.

7.5

CVSS3.1

CVE-2026-4748 - pf silently ignores certain rules

A regression in the way hashes were calculated caused rules containing the address range syntax (x.x.x.x - y.y.y.y) that only differ in the address range(s) involved to be silently dropped as duplicates. Only the first of such rules is actually loaded into pf. Ranges expressed using the address[/…

πŸ“… Published: April 1, 2026, 6:18 a.m. πŸ”„ Last Modified: April 3, 2026, 9:19 a.m.

6.9

CVSS4.0

CVE-2026-5257 - code-projects Simple Laundry System Parameter delstaffinfo.php sql injection

A vulnerability has been found in code-projects Simple Laundry System 1.0. This issue affects some unknown processing of the file /delstaffinfo.php of the component Parameter Handler. Such manipulation of the argument userid leads to sql injection. The attack can be executed remotely. The exploit h…

πŸ“… Published: April 1, 2026, 6 a.m. πŸ”„ Last Modified: April 3, 2026, 9:17 p.m.

6.9

CVSS4.0

CVE-2026-5256 - code-projects Simple Laundry System Parameter modify.php sql injection

A flaw has been found in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /modify.php of the component Parameter Handler. This manipulation of the argument firstName causes sql injection. Remote exploitation of the attack is possible. The exploit has been…

πŸ“… Published: April 1, 2026, 6 a.m. πŸ”„ Last Modified: April 3, 2026, 9:17 p.m.

5.3

CVSS3.1

CVE-2026-2696 - Export All URLs < 5.1 - Unauthenticated Sensitive Data Exposure

The Export All URLs WordPress plugin before 5.1 generates CSV filenames containing posts URLS (including private posts) in a predictable pattern using a random 6-digit number. These files are stored in the publicly accessible wp-content/uploads/ directory. As a result, any unauthenticated user can …

πŸ“… Published: April 1, 2026, 6 a.m. πŸ”„ Last Modified: April 15, 2026, 3:05 p.m.

9.1

CVSS3.1

CVE-2025-15484 - Order Notification for WooCommerce < 3.6.3 - Unauthenticated WooCommerce REST Permission Bypass

The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant full access to all unauthenticated requests, enabling complete read/write access to store resources like products, coupons, and customers.

πŸ“… Published: April 1, 2026, 6 a.m. πŸ”„ Last Modified: April 15, 2026, 3:05 p.m.

5.3

CVSS4.0

CVE-2026-5255 - code-projects Simple Laundry System Parameter delstaffinfo.php cross site scripting

A vulnerability was detected in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /delstaffinfo.php of the component Parameter Handler. The manipulation of the argument userid results in cross site scripting. The attack may be launched remotely. The exploit is now pu…

πŸ“… Published: April 1, 2026, 5:15 a.m. πŸ”„ Last Modified: April 7, 2026, 8:07 a.m.

8.8

CVSS3.1

CVE-2026-5292 - Out-Of-Bounds Read Vulnerability in Chrome WebCodecs

Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)

πŸ“… Published: April 1, 2026, 4:41 a.m. πŸ”„ Last Modified: April 2, 2026, 8:18 p.m.

9.6

CVSS3.1

CVE-2026-5290 - Use‑After‑Free in Chrome Compositing Allows Remote Sandbox Escape

Use after free in Compositing in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: April 1, 2026, 4:41 a.m. πŸ”„ Last Modified: April 2, 2026, 8:18 p.m.

9.6

CVSS3.1

CVE-2026-5289 - Use‑After‑Free in Chrome Navigation Enables Sandbox Escape

Use after free in Navigation in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: April 1, 2026, 4:41 a.m. πŸ”„ Last Modified: April 2, 2026, 8:18 p.m.
Total resulsts: 349182
Page 757 of 34,919
Β« previous page Β» next page
Filters