8.8

CVSS4.0

CVE-2026-33413 - etcd: Authorization bypasses in multiple APIs

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, unauthorized users may bypass authentication or authorization checks and call certain etcd functions in clusters that expose the gRPC API to untrusted or partially trusted client…

πŸ“… Published: March 26, 2026, 1:36 p.m. πŸ”„ Last Modified: March 27, 2026, 9:26 a.m.

4.9

CVSS3.1

CVE-2026-2389 - Complianz – GDPR/CCPA Cookie Consent <= 7.4.4.2 - Authenticated (Contributor+) Stored Cross-Site Sc…

The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 7.4.4.2. This is due to the `revert_divs_to_summary` function replacing `&#8221;` HTML entities with literal double-quote characters (`"`) in post content…

πŸ“… Published: March 26, 2026, 1:26 p.m. πŸ”„ Last Modified: April 24, 2026, 4:35 p.m.

4.3

CVSS3.1

CVE-2026-1032 - Conditional Menus <= 1.2.6 - Cross-Site Request Forgery to Menu Options Update

The Conditional Menus plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.6. This is due to missing nonce validation on the 'save_options' function. This makes it possible for unauthenticated attackers to modify conditional menu assignments via…

πŸ“… Published: March 26, 2026, 1:26 p.m. πŸ”„ Last Modified: April 24, 2026, 4:35 p.m.

7.2

CVSS3.1

CVE-2026-2231 - Fluent Booking <= 2.0.01 - Unauthenticated Stored Cross-Site Scripting via Multiple Parameters

The Fluent Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions up to, and including, 2.0.01 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts …

πŸ“… Published: March 26, 2026, 1:26 p.m. πŸ”„ Last Modified: April 24, 2026, 4:35 p.m.

7.5

CVSS3.1

CVE-2026-2511 - JS Help Desk – AI-Powered Support & Ticketing System <= 3.0.4 - Unauthenticated SQL Injection via '…

The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the `multiformid` parameter in the `storeTickets()` function in all versions up to, and including, 3.0.4. This is due to the user-supplied `multiformid` value being passed to `esc_sql()`…

πŸ“… Published: March 26, 2026, 1:26 p.m. πŸ”„ Last Modified: April 24, 2026, 4:35 p.m.

8.6

CVSS4.0

CVE-2019-25650 - River Past CamDo 3.7.6 Structured Exception Handler Buffer Overflow

River Past CamDo 3.7.6 contains a structured exception handler (SEH) buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the Lame_enc.dll name field. Attackers can craft a payload with a 280-byte buffer, NSEH jump instruction, and S…

πŸ“… Published: March 26, 2026, 1:24 p.m. πŸ”„ Last Modified: March 27, 2026, 9:26 a.m.

6.8

CVSS4.0

CVE-2019-25649 - River Past Audio Converter 7.7.16 Local Buffer Overflow DoS

River Past Audio Converter 7.7.16 contains a local buffer overflow vulnerability in the activation code field that allows local attackers to crash the application by supplying an oversized input string. Attackers can paste a large payload of repeated characters into the 'E-Mail and Activation Code'…

πŸ“… Published: March 26, 2026, 1:24 p.m. πŸ”„ Last Modified: March 27, 2026, 9:26 a.m.

6.9

CVSS4.0

CVE-2019-25648 - MyVideoConverter Pro 3.14 Denial of Service Buffer Overflow

MyVideoConverter Pro 3.14 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying an excessively long string to the registration code input field. Attackers can paste a malicious payload containing 10000 bytes into the 'Copy and Paste Registration …

πŸ“… Published: March 26, 2026, 1:24 p.m. πŸ”„ Last Modified: March 27, 2026, 9:26 a.m.

8.6

CVSS4.0

CVE-2018-25219 - PassFab Excel Password Recovery 8.3.1 SEH Buffer Overflow

PassFab Excel Password Recovery 8.3.1 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload in the registration code field. Attackers can craft a buffer overflow payload with a pop-pop-ret gadget…

πŸ“… Published: March 26, 2026, 1:24 p.m. πŸ”„ Last Modified: March 31, 2026, 8:09 p.m.

8.6

CVSS4.0

CVE-2018-25218 - PassFab RAR Password Recovery 9.3.2 SEH Buffer Overflow

PassFab RAR Password Recovery 9.3.2 contains a structured exception handler (SEH) buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload. Attackers can craft a payload with a buffer overflow, NSEH jump, and shellcode, then paste it into …

πŸ“… Published: March 26, 2026, 1:24 p.m. πŸ”„ Last Modified: March 31, 2026, 8:09 p.m.
Total resulsts: 349182
Page 858 of 34,919
Β« previous page Β» next page
Filters