7.8

CVSS3.1

CVE-2026-3779 - Foxit PDF Editor/Reader List Box Calculate Array Use-After-Free Vulnerability

The application's list box calculate array logic keeps stale references to page or form objects after they are deleted or re-created, which allows crafted documents to trigger a use-after-free when the calculation runs and can potentially lead to arbitrary code execution.

πŸ“… Published: April 1, 2026, 1:40 a.m. πŸ”„ Last Modified: April 28, 2026, 2:15 p.m.

5.5

CVSS3.1

CVE-2026-3777 - Use after free of view cache in Foxit PDF Editor/Reader

The application does not properly validate the lifetime and validity of internal view cache pointers after JavaScript changes the document zoom and page state. When a script modifies the zoom property and then triggers a page change, the original view object may be destroyed while stale pointers ar…

πŸ“… Published: April 1, 2026, 1:40 a.m. πŸ”„ Last Modified: April 15, 2026, 4:45 p.m.

7.1

CVSS3.1

CVE-2026-4947 - Insecure Direct Object Reference (IDOR) Leading to Signature Forgery in Foxit eSign

Addressed a potential insecure direct object reference (IDOR) vulnerability in the signing invitation acceptance process. Under certain conditions, this issue could have allowed an attacker to access or modify unauthorized resources by manipulating user-supplied object identifiers, potentially lead…

πŸ“… Published: April 1, 2026, 1:40 a.m. πŸ”„ Last Modified: April 27, 2026, 1:14 p.m.

5.1

CVSS4.0

CVE-2026-5249 - gougucms Record Endpoint record.html cross site scripting

A vulnerability was found in gougucms 4.08.18. This impacts an unknown function of the file \gougucms-master\app\admin\view\user\record.html of the component Record Endpoint. Performing a manipulation of the argument value.content results in cross site scripting. It is possible to initiate the atta…

πŸ“… Published: April 1, 2026, 1:30 a.m. πŸ”„ Last Modified: April 24, 2026, 6:12 p.m.

4.3

CVSS3.1

CVE-2026-3831 - Database for Contact Form 7, WPforms, Elementor forms <= 1.4.9 - Missing Authorization to Authenti…

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the entries_shortcode() function in all versions up to, and including, 1.4.9. This makes it possible for authenticated attackers, with Con…

πŸ“… Published: April 1, 2026, 1:24 a.m. πŸ”„ Last Modified: April 24, 2026, 6:12 p.m.

7

CVSS4.0

CVE-2026-4374 - Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Ro…

Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Routing Service,Observability Collector,Recording Service,Queueing Service,Cloud Discovery Service) allows Serialized Data External Linking, Data Serializat...

πŸ“… Published: April 1, 2026, 1:06 a.m. πŸ”„ Last Modified: April 21, 2026, 12:06 a.m.

4.8

CVSS4.0

CVE-2026-2394 - Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.

Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 4.3x before 5.2.*.

πŸ“… Published: April 1, 2026, 12:52 a.m. πŸ”„ Last Modified: April 15, 2026, 4:45 p.m.

5.3

CVSS4.0

CVE-2026-5248 - gougucms User Registration Login.php reg_submit dynamically-determined object attributes

A vulnerability has been found in gougucms 4.08.18. This affects the function reg_submit of the file gougucms-master\app\home\controller\Login.php of the component User Registration Handler. Such manipulation of the argument level leads to dynamically-determined object attributes. The attack may be…

πŸ“… Published: April 1, 2026, 12:45 a.m. πŸ”„ Last Modified: April 24, 2026, 6:12 p.m.

5.1

CVSS4.0

CVE-2026-35057 - XenForo Stored Cross-Site Scripting via Structured Text Mentions

XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, primarily affecting legacy profile post content. An attacker can inject malicious scripts through crafted mentions that are stored and executed when other users view the content.

πŸ“… Published: April 1, 2026, 12:30 a.m. πŸ”„ Last Modified: April 2, 2026, 8:18 p.m.

8.6

CVSS4.0

CVE-2026-35056 - XenForo Remote Code Execution via Authenticated Admin

XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary code on the server.

πŸ“… Published: April 1, 2026, 12:30 a.m. πŸ”„ Last Modified: April 2, 2026, 8:18 p.m.
Total resulsts: 349182
Page 759 of 34,919
Β« previous page Β» next page
Filters