7.3

CVSS4.0

CVE-2026-23928 - Stored XSS vulnerability in the Item history/Plain text widget

The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript wou…

📅 Published: May 6, 2026, 7 a.m. 🔄 Last Modified: May 6, 2026, 12:59 p.m.

5.1

CVSS4.0

CVE-2026-23927 - Agent 2 Oracle plugin TNS connection string injection via the 'service' parameter

A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an attacker-controlled server and leaking Oracle database credentials if they are saved in a named session.

📅 Published: May 6, 2026, 6:59 a.m. 🔄 Last Modified: May 6, 2026, 1 p.m.

7.3

CVSS4.0

CVE-2026-23926 - Stored XSS vulnerability in Host navigator widget maintenance tooltip

An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on which user opens th…

📅 Published: May 6, 2026, 6:58 a.m. 🔄 Last Modified: May 6, 2026, 12:59 p.m.

8.8

CVSS3.1

CVE-2026-7841 - GV-ASWeb Remote Code Execution (RCE) vulnerability

A remote code execution vulnerability exists in Notification Settings on GeoVision GV-ASWeb 6.2.0. An authenticated user with System Setting permissions can execute arbitrary commands on the server by sending a crafted HTTP POST request to the ASWebCommon.srf backend endpoint to bypass the frontend…

📅 Published: May 6, 2026, 6:47 a.m. 🔄 Last Modified: May 6, 2026, 12:54 p.m.

7.2

CVSS3.1

CVE-2026-7448 - LatePoint <= 5.5.0 - Unauthenticated Stored Cross-Site Scripting via 'first_name' Parameter

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

📅 Published: May 6, 2026, 6:47 a.m. 🔄 Last Modified: May 8, 2026, 12:25 p.m.

7.2

CVSS3.1

CVE-2026-7332 - LatePoint <= 5.5.0 - Unauthenticated Stored Cross-Site Scripting via 'booking_form_page_url' Parame…

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking_form_page_url' parameter in all versions up to, and including, 5.5.0 due to insufficient input sanitization and output escaping. This makes it possi…

📅 Published: May 6, 2026, 6:47 a.m. 🔄 Last Modified: May 6, 2026, 8:30 a.m.

6.4

CVSS3.1

CVE-2026-7457 - LatePoint <= 5.5.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Customer Cabinet P…

The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to and including 5.5.0. This is due to insufficient input sanitization on the customer cabinet profile update endpoint — where raw POST parameters (first_name, last_name, phone, notes) bypass sanitiza…

📅 Published: May 6, 2026, 6:47 a.m. 🔄 Last Modified: May 6, 2026, 6:47 a.m.

6.4

CVSS3.1

CVE-2026-6672 - Affiliate Program Suite <= 1.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via sli…

The Affiliate Program Suite — SliceWP Affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in all versions up to, and including, 1.2.7. This is due to insufficient input sanitization and output escaping on user-supplied attributes in the 'slicewp_aff…

📅 Published: May 6, 2026, 6:47 a.m. 🔄 Last Modified: May 6, 2026, 6:47 a.m.

4.9

CVSS3.1

CVE-2026-6344 - Fluent Forms <= 6.2.1 - Authenticated (Administrator+) Arbitrary File Read via Path Traversal in Em…

The Fluent Forms plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 6.2.1. This is due to insufficient path validation in the getAttachments() method of EmailNotificationActions, which resolves attacker-supplied file-upload URLs into filesystem paths without v…

📅 Published: May 6, 2026, 6:47 a.m. 🔄 Last Modified: May 6, 2026, 6:47 a.m.

4.7

CVSS3.1

CVE-2026-35253 - Oracle Macaron Tool 0.22.0 Host Address Validation Vulnerability

Vulnerability in the Oracle Macoron Tool product of Oracle Open Source Projects. The supported versions that is affected is v0.22.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Macaron Tool. Successful attacks of this vulnerabil…

📅 Published: May 6, 2026, 6:22 a.m. 🔄 Last Modified: May 6, 2026, 10 p.m.
Total resulsts: 349182
Page 81 of 34,919
« previous page » next page
Filters