4.3

CVSS3.1

CVE-2026-2306 - Ninja Tables <= 5.2.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Table Creatiโ€ฆ

The Ninja Tables โ€“ Easy Data Table Builder plugin for WordPress is vulnerable to unauthorized database table creation due to missing authorization checks on the `createFluentCartTable` function in all versions up to, and including, 5.2.6. This makes it possible for authenticated attackers, with Subโ€ฆ

๐Ÿ“… Published: May 6, 2026, 4:26 a.m. ๐Ÿ”„ Last Modified: May 6, 2026, 4:26 a.m.

6.5

CVSS3.1

CVE-2026-5753 - All-in-One WP Migration Unlimited Extension <= 2.83 - Missing Authorization to Authenticated (Subscโ€ฆ

The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.83. This is due to the 'Ai1wmve_Schedules_Controller::save' handler for 'admin_post_ai1wm_schedule_event_save' not verifying user capabilities before savinโ€ฆ

๐Ÿ“… Published: May 6, 2026, 3:27 a.m. ๐Ÿ”„ Last Modified: May 6, 2026, 3:27 a.m.

5.3

CVSS3.1

CVE-2026-3208 - Mercado Pago payments for WooCommerce <= 8.7.11 - Missing Authorization to Unauthenticated PIX Paymโ€ฆ

The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'mp_pix_image' WooCommerce API endpoint in all versions up to, and including, 8.7.11. This makes it possible for unauthenticated attackers to retrieveโ€ฆ

๐Ÿ“… Published: May 6, 2026, 3:27 a.m. ๐Ÿ”„ Last Modified: May 6, 2026, 3:27 a.m.

4.4

CVSS3.1

CVE-2026-7572 - Velociraptor EVTX Parser โ€” Process Crash via Crafted .evtx File

An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor before version 0.76.5 on Windows and Linux allows a local attacker to cause a Denial of Service (DoS) via a process crash by providing a specially crafted .evtx file to the parse_evtx โ€ฆ

๐Ÿ“… Published: May 6, 2026, 2:38 a.m. ๐Ÿ”„ Last Modified: May 6, 2026, 4:42 p.m.

5

CVSS3.1

CVE-2026-7573 - GetUserRoles API endpoint allows any authenticated user to enumerate ACL policies across all organiโ€ฆ

An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 allows any authenticated low-privilege user to retrieve the complete ACL policy (roles and permissions) for any user across all organizations by supplying targeted Name and Org parโ€ฆ

๐Ÿ“… Published: May 6, 2026, 2:15 a.m. ๐Ÿ”„ Last Modified: May 6, 2026, 4:17 p.m.

7.5

CVSS3.1

CVE-2025-71256 - Remote Denial of Service via Improper Input Validation in Unisoc NR Modem

In nr modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

๐Ÿ“… Published: May 6, 2026, 1:43 a.m. ๐Ÿ”„ Last Modified: May 6, 2026, 12:56 p.m.

7.5

CVSS3.1

CVE-2025-71255 - Remote Denial of Service via Improper Input Validation in Unisoc Modem IMS

In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

๐Ÿ“… Published: May 6, 2026, 1:43 a.m. ๐Ÿ”„ Last Modified: May 6, 2026, 12:55 p.m.

7.5

CVSS3.1

CVE-2025-71254 - Improper Input Validation in Modem IMS Leading to Remote Denial of Service

In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

๐Ÿ“… Published: May 6, 2026, 1:43 a.m. ๐Ÿ”„ Last Modified: May 6, 2026, 12:50 p.m.

7.5

CVSS3.1

CVE-2025-71253 - Improper Input Validation in Modem IMS Leading to Remote Denial of Service

In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

๐Ÿ“… Published: May 6, 2026, 1:43 a.m. ๐Ÿ”„ Last Modified: May 6, 2026, 3:24 p.m.

7.5

CVSS3.1

CVE-2025-71252 -

In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

๐Ÿ“… Published: May 6, 2026, 1:43 a.m. ๐Ÿ”„ Last Modified: May 6, 2026, 3:24 p.m.
Total resulsts: 349182
Page 82 of 34,919
ยซ previous page ยป next page
Filters