8.5

CVSS4.0

CVE-2026-32680 - Privilege Escalation via Unsecured Installation Folder in RATOC RAID Monitoring Manager for Windows

The installer of RATOC RAID Monitoring Manager for Windows allows to customize the installation folder. If the installation folder is customized to some non-default one, the folder may be left with un-secure ACLs and non-administrative users can alter contents of that folder. It may allow a non-adm…

πŸ“… Published: March 26, 2026, 6:55 a.m. πŸ”„ Last Modified: March 26, 2026, 3:13 p.m.

8.4

CVSS4.0

CVE-2026-28760 - Administrator Privilege DLL Loading Vulnerability in RATOC RAID Monitoring Manager Installer

The installer of RATOC RAID Monitoring Manager for Windows searches the current directory to load certain DLLs. If a user is directed to place a crafted DLL with the installer, an arbitrary code may be executed with the administrator privilege.

πŸ“… Published: March 26, 2026, 6:54 a.m. πŸ”„ Last Modified: March 26, 2026, 3:13 p.m.

5.3

CVSS4.0

CVE-2026-4847 - dameng100 muucmf list.html cross site scripting

A vulnerability was found in dameng100 muucmf 1.9.5.20260309. The impacted element is an unknown function of the file /admin/config/list.html. Performing a manipulation of the argument Name results in cross site scripting. The attack can be initiated remotely. The exploit has been made public and c…

πŸ“… Published: March 26, 2026, 6:23 a.m. πŸ”„ Last Modified: April 24, 2026, 4:35 p.m.

8.8

CVSS3.1

CVE-2026-4747 - Remote code execution via RPCSEC_GSS packet validation

Each RPCSEC_GSS data packet is validated by a routine which checks a signature in the packet. This routine copies a portion of the packet into a stack buffer, but fails to ensure that the buffer is sufficiently large, and a malicious client can trigger a stack overflow. Notably, this does not req…

πŸ“… Published: March 26, 2026, 6:21 a.m. πŸ”„ Last Modified: April 20, 2026, 1:47 p.m.

7.5

CVSS3.1

CVE-2026-4652 - Remote denial of service via null pointer dereference

On a system exposing an NVMe/TCP target, a remote client can trigger a kernel panic by sending a CONNECT command for an I/O queue with a bogus or stale CNTLID. An attacker with network access to the NVMe/TCP target can trigger an unauthenticated Denial of Service condition on the affected machine.

πŸ“… Published: March 26, 2026, 6:15 a.m. πŸ”„ Last Modified: March 27, 2026, 9:28 a.m.

7.5

CVSS3.1

CVE-2026-4247 - TCP: remotely exploitable DoS vector (mbuf leak)

When a challenge ACK is to be sent tcp_respond() constructs and sends the challenge ACK and consumes the mbuf that is passed in. When no challenge ACK should be sent the function returns and leaks the mbuf. If an attacker is either on path with an established TCP connection, or can themselves est…

πŸ“… Published: March 26, 2026, 6:09 a.m. πŸ”„ Last Modified: March 27, 2026, 9:28 a.m.

5.3

CVSS3.1

CVE-2026-1890 - LeadConnector < 3.0.22 - Unauthenticated Rest Call

The LeadConnector WordPress plugin before 3.0.22 does not have authorization in a REST route, allowing unauthenticated users to call it and overwrite existing data

πŸ“… Published: March 26, 2026, 6 a.m. πŸ”„ Last Modified: April 15, 2026, 3:05 p.m.

4.8

CVSS3.1

CVE-2026-1430 - WP Lightbox 2 < 3.0.7 - Admin+ Stored XSS

The WP Lightbox 2 WordPress plugin before 3.0.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

πŸ“… Published: March 26, 2026, 6 a.m. πŸ”„ Last Modified: April 15, 2026, 3:05 p.m.

6.5

CVSS3.1

CVE-2025-15488 - Responsive Plus < 3.4.3 - Unauthenticated Arbitrary Shortcode Execution

The Responsive Plus WordPress plugin before 3.4.3 is vulnerable to arbitrary shortcode execution due to the software allowing unauthenticated users to execute the update_responsive_woo_free_shipping_left_shortcode AJAX action that does not properly validate the content_rech_data parameter before p…

πŸ“… Published: March 26, 2026, 6 a.m. πŸ”„ Last Modified: April 15, 2026, 3:05 p.m.

6.8

CVSS3.1

CVE-2025-15433 - Shared Files < 1.7.58 - Contributor+ Arbitrary File Download

The Shared Files WordPress plugin before 1.7.58 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector

πŸ“… Published: March 26, 2026, 6 a.m. πŸ”„ Last Modified: April 15, 2026, 3:05 p.m.
Total resulsts: 349182
Page 865 of 34,919
Β« previous page Β» next page
Filters