8.8

CVSS3.1

CVE-2026-40466 - Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Possible bypass of CVE-2026-34197 via…

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated attacker may bypass the fix in CVE-2026-34197 by adding a connector using an HTTP Discovery transport via BrokerVie…

📅 Published: April 24, 2026, 10:15 a.m. 🔄 Last Modified: April 27, 2026, 12:23 p.m.

8.5

CVSS4.0

CVE-2026-6272 - Unrestricted Signal Provider registration enables unauthorized data injection in Eclipse KUKSA Data…

A client holding only a read JWT scope can still register itself as a signal provider through the production kuksa.val.v2 OpenProviderStream API by sending ProvideSignalRequest. 1. Obtain any valid token with only read scope. 2. Connect to the normal production gRPC API (kuksa.val.v2). 3. Open Ope…

📅 Published: April 24, 2026, 8:28 a.m. 🔄 Last Modified: April 28, 2026, 2:30 p.m.

7.5

CVSS3.1

CVE-2026-21728 - Tempo query limit results in unbounded memory allocation

Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18).

📅 Published: April 24, 2026, 8 a.m. 🔄 Last Modified: April 28, 2026, 1:30 a.m.

5.3

CVSS3.1

CVE-2026-3569 - Liaison Site Prober <= 1.2.1 - Missing Authorization to Unauthenticated Information Exposure in '/l…

The Liaison Site Prober plugin for WordPress is vulnerable to Information Exposure in all versions up to and including 1.2.1 via the /wp-json/site-prober/v1/logs REST API endpoint. The permissions_read() permission callback unconditionally returns true (via __return_true()) instead of checking for …

📅 Published: April 24, 2026, 7:45 a.m. 🔄 Last Modified: April 28, 2026, 9:18 a.m.

6.4

CVSS3.1

CVE-2026-4078 - ITERAS <= 1.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

The ITERAS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes (iteras-ordering, iteras-signup, iteras-paywall-login, iteras-selfservice) in all versions up to and including 1.8.2. This is due to insufficient input sanitization and output escaping in the combin…

📅 Published: April 24, 2026, 7:45 a.m. 🔄 Last Modified: April 28, 2026, 9:18 a.m.

4.3

CVSS3.1

CVE-2026-3565 - Taqnix <= 1.0.3 - Cross-Site Request Forgery to Account Deletion via 'taqnix_delete_my_account' AJA…

The Taqnix plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to a missing nonce verification in the taqnix_delete_my_account() function, where the check_ajax_referer() call is explicitly commented out on line 883. This makes it…

📅 Published: April 24, 2026, 7:45 a.m. 🔄 Last Modified: April 28, 2026, 9:18 a.m.

4.3

CVSS3.1

CVE-2025-11762 - HubSpot All-In-One Marketing - Forms, Popups, Live Chat <= 11.3.32 - Missing Authorization to Authe…

The HubSpot All-In-One Marketing - Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.32 via the leadin/public/admin/class-adminconstants.php file. This makes it possible for authenticated attackers, with Contribu…

📅 Published: April 24, 2026, 7:45 a.m. 🔄 Last Modified: April 28, 2026, 9:18 a.m.

9.8

CVSS3.1

CVE-2026-1951 - No checking of the length of the buffer with the directory name in AS320T

Delta Electronics AS320T has no checking of the length of the buffer with the directory name vulnerability.

📅 Published: April 24, 2026, 6:13 a.m. 🔄 Last Modified: April 24, 2026, 2:39 p.m.

9.8

CVSS3.1

CVE-2026-1952 - Denial of service via the undocumented subfunction in AS320T

Delta Electronics AS320T has denial of service via the undocumented subfunction vulnerability.

📅 Published: April 24, 2026, 6:08 a.m. 🔄 Last Modified: April 24, 2026, 3:26 p.m.

9.8

CVSS3.1

CVE-2026-1950 - No checking of the length of the buffer with the file name in AS320T

Delta Electronics AS320T has No checking of the length of the buffer with the file name vulnerability.

📅 Published: April 24, 2026, 5:56 a.m. 🔄 Last Modified: April 24, 2026, 3:27 p.m.
Total resulsts: 347269
Page 84 of 34,727
« previous page » next page
Filters