7.2

CVSS3.1

CVE-2026-3328 - Frontend Admin by DynamiApps <= 3.28.31 - Authenticated (Editor+) PHP Object Injection via 'post_coโ€ฆ

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to PHP Object Injection via deserialization of the 'post_content' of admin_form posts in all versions up to, and including, 3.28.31. This is due to the use of WordPress's `maybe_unserialize()` function without class restrictions onโ€ฆ

๐Ÿ“… Published: March 26, 2026, 2:25 a.m. ๐Ÿ”„ Last Modified: April 24, 2026, 4:35 p.m.

9.8

CVSS3.1

CVE-2014-125112 - Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution

Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution. Plack::Middleware::Session::Cookie versions through 0.21 has a security vulnerability where it allows an attacker to execute arbitrary code on the server during deserialization of the cookie data, when โ€ฆ

๐Ÿ“… Published: March 26, 2026, 2:04 a.m. ๐Ÿ”„ Last Modified: May 6, 2026, 2:50 p.m.

8.5

CVSS4.0

CVE-2025-15101 -

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Web management interface of certain ASUS router models. This vulnerability potentially allows actions to be performed with the existing privileges of an authenticated user on the affected device, including the ability to eโ€ฆ

๐Ÿ“… Published: March 26, 2026, 2:01 a.m. ๐Ÿ”„ Last Modified: March 27, 2026, 9:28 a.m.

5.3

CVSS4.0

CVE-2026-4836 - code-projects Accounting System delete.php sql injection

A vulnerability was detected in code-projects Accounting System 1.0. The affected element is an unknown function of the file /my_account/delete.php. Performing a manipulation of the argument cos_id results in sql injection. It is possible to initiate the attack remotely. The exploit is now public aโ€ฆ

๐Ÿ“… Published: March 26, 2026, 1:52 a.m. ๐Ÿ”„ Last Modified: April 24, 2026, 4:35 p.m.

5.1

CVSS4.0

CVE-2026-4835 - code-projects Accounting System Web Application add_costumer.php cross site scripting

A security vulnerability has been detected in code-projects Accounting System 1.0. Impacted is an unknown function of the file /my_account/add_costumer.php of the component Web Application Interface. Such manipulation of the argument costumer_name leads to cross site scripting. The attack may be peโ€ฆ

๐Ÿ“… Published: March 26, 2026, 1:52 a.m. ๐Ÿ”„ Last Modified: April 24, 2026, 4:35 p.m.

8.8

CVSS3.1

CVE-2026-4484 - Masteriyo LMS <= 2.1.6 - Missing Authorization to Authenticated (Student+) Privilege Escalation to โ€ฆ

The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6. This is due to the plugin allowing a user to update the user role through the 'InstructorsController::prepare_object_for_database' function. This makes it possible for authenticโ€ฆ

๐Ÿ“… Published: March 26, 2026, 1:25 a.m. ๐Ÿ”„ Last Modified: April 24, 2026, 4:35 p.m.

4.8

CVSS4.0

CVE-2026-4833 - Orc discount Markdown markdown.c compile recursion

A weakness has been identified in Orc discount up to 3.0.1.2. This issue affects the function compile of the file markdown.c of the component Markdown Handler. This manipulation causes uncontrolled recursion. The attack is restricted to local execution. The exploit has been made available to the puโ€ฆ

๐Ÿ“… Published: March 26, 2026, 1:02 a.m. ๐Ÿ”„ Last Modified: April 24, 2026, 4:35 p.m.

6.3

CVSS4.0

CVE-2026-4831 - kalcaddle kodbox Password-protected Share auth.class.php can improper authentication

A security flaw has been discovered in kalcaddle kodbox 1.64. Impacted is the function can of the file /workspace/source-code/app/controller/explorer/auth.class.php of the component Password-protected Share Handler. Performing a manipulation results in improper authentication. The attack is possiblโ€ฆ

๐Ÿ“… Published: March 26, 2026, 1:02 a.m. ๐Ÿ”„ Last Modified: April 24, 2026, 4:35 p.m.

7.5

CVSS3.1

CVE-2026-33285 - LiquidJS: memoryLimit Bypass through Negative Range Values Leads to Process Crash

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.1, LiquidJS's `memoryLimit` security mechanism can be completely bypassed by using reverse range expressions (e.g., `(100000000..1)`), allowing an attacker to allocate unlimited memory. Combinโ€ฆ

๐Ÿ“… Published: March 26, 2026, 12:34 a.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:57 p.m.

7.5

CVSS3.1

CVE-2026-33287 - LiquidJS has Exponential Memory Amplification through its replace_first Filter $& Pattern

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.1, the `replace_first` filter in LiquidJS uses JavaScript's `String.prototype.replace()` which interprets `$&` as a back reference to the matched substring. The filter only charges `memoryLimiโ€ฆ

๐Ÿ“… Published: March 26, 2026, 12:33 a.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:57 p.m.
Total resulsts: 349182
Page 868 of 34,919
ยซ previous page ยป next page
Filters