8

CVSS3.1

CVE-2026-4248 - Ultimate Member <= 2.11.2 - Authenticated (Contributor+) Sensitive Information Exposure to Account โ€ฆ

The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.2. This is due to the '{usermeta:password_reset_link}' template tag being processed within post content via the '[um_loggedin]' shortcode, which generates a valid passโ€ฆ

๐Ÿ“… Published: March 27, 2026, 10:26 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 4:36 p.m.

5.8

CVSS4.0

CVE-2026-33996 - LibJWT has NULL/bounds validation in JWK octet and RSA PSS parsing

LibJWT is a C JSON Web Token Library. Starting in version 3.0.0 and prior to version 3.3.0, the JWK parsing for RSA-PSS did not protect against a NULL value when expecting to parse JSON string values. A specially crafted JWK file could exploit this behavior by using integers in places where the codโ€ฆ

๐Ÿ“… Published: March 27, 2026, 10:21 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 7:55 a.m.

6.3

CVSS4.0

CVE-2026-33994 - Locutus Prototype Pollution due to incomplete fix for CVE-2026-25521

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Starting in version 2.0.39 and prior to version 3.0.25, a prototype pollution vulnerability exists in the `parse_str` function of the npm package locutus. An attacker can pollute `Object.prototype` by overโ€ฆ

๐Ÿ“… Published: March 27, 2026, 10:15 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 7:55 a.m.

6.9

CVSS4.0

CVE-2026-33993 - Locutus has Prototype Pollution via __proto__ Key Injection in unserialize()

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.25, the `unserialize()` function in `locutus/php/var/unserialize` assigns deserialized keys to plain objects via bracket notation without filtering the `__proto__` key. When a PHP seriโ€ฆ

๐Ÿ“… Published: March 27, 2026, 10:14 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 7:55 a.m.

9.3

CVSS4.0

CVE-2026-33992 - pyLoad: Server-Side Request Forgery via Download Link Submission Enables Cloud Metadata Exfiltration

pyLoad is a free and open-source download manager written in Python. Prior to version 0.5.0b3.dev97, PyLoad's download engine accepts arbitrary URLs without validation, enabling Server-Side Request Forgery (SSRF) attacks. An authenticated attacker can exploit this to access internal network serviceโ€ฆ

๐Ÿ“… Published: March 27, 2026, 10:12 p.m. ๐Ÿ”„ Last Modified: March 31, 2026, 8 p.m.

8.8

CVSS3.1

CVE-2026-33991 - WeGIA has SQL Injection in deletar_tag.php

WeGIA is a web manager for charitable institutions. Prior to version 3.6.7, the file `html/socio/sistema/deletar_tag.php` uses `extract($_REQUEST)` on line 14 and directly concatenates the `$id_tag` variable into SQL queries on lines 16-17 without prepared statements or sanitization. Version 3.6.7 โ€ฆ

๐Ÿ“… Published: March 27, 2026, 10:10 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 7:55 a.m.

5.3

CVSS3.1

CVE-2026-33936 - python-ecdsa: Denial of Service via improper DER length validation in crafted private keys

The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm) and ECDH (Elliptic Curve Diffie-Hellman). Prior to version 0.19.2, an issue in the lowโ€ฆ

๐Ÿ“… Published: March 27, 2026, 10:08 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 7:55 a.m.

5.3

CVSS4.0

CVE-2026-4992 - wandb OpenUI HTMLAnnotator server.py get_share HTML injection

A flaw has been found in wandb OpenUI up to 1.0. This affects the function create_share/get_share of the file backend/openui/server.py of the component HTMLAnnotator Component. Executing a manipulation of the argument ID can lead to HTML injection. The attack may be performed from remote. The exploโ€ฆ

๐Ÿ“… Published: March 27, 2026, 10:03 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 4:36 p.m.

5.1

CVSS4.0

CVE-2026-4991 - QDOCS Smart School Management System Admission Enquiry enquiry cross site scripting

A vulnerability was detected in QDOCS Smart School Management System up to 7.2. The impacted element is an unknown function of the file /admin/enquiry of the component Admission Enquiry Module. Performing a manipulation of the argument Note results in cross site scripting. The attack is possible toโ€ฆ

๐Ÿ“… Published: March 27, 2026, 10:03 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 4:36 p.m.

8.1

CVSS3.1

CVE-2026-33989 - @mobilenext/mobile-mcp alllows arbitrary file write via Path Traversal in mobile screen capture tooโ€ฆ

Mobile Next is an MCP server for mobile development and automation. Prior to version 0.0.49, the `@mobilenext/mobile-mcp` server contains a Path Traversal vulnerability in the `mobile_save_screenshot` and `mobile_start_screen_recording` tools. The `saveTo` and `output` parameters were passed directโ€ฆ

๐Ÿ“… Published: March 27, 2026, 10:03 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 7:55 a.m.
Total resulsts: 349182
Page 819 of 34,919
ยซ previous page ยป next page
Filters