6.9

CVSS4.0

CVE-2026-32326 - Unauthorized Access to Sharp 5G Routers via Unauthenticated Web APIs

SHARP routers do not perform authentication for some web APIs. The device information may be retrieved without authentication. If the administrative password of the device is left as the initial one, the device may be taken over.

πŸ“… Published: March 25, 2026, 7:38 a.m. πŸ”„ Last Modified: March 25, 2026, 9:15 p.m.

5.3

CVSS3.1

CVE-2026-2343 - PeproDev Ultimate Invoice <= 2.2.5 - Unauthenticated Invoice Archive Download

The PeproDev Ultimate Invoice WordPress plugin through 2.2.5 has a bulk download invoices action that generates ZIP archives containing exported invoice PDFs. The ZIP files are named predictably making it possible to brute force and retreive PII.

πŸ“… Published: March 25, 2026, 6 a.m. πŸ”„ Last Modified: April 15, 2026, 3:05 p.m.

8.4

CVSS4.0

CVE-2026-26306 - Insecure DLL Loading in OM Workspace (Windows Edition) Installer Allows Arbitrary Code Execution

The installer for OM Workspace (Windows Edition) Ver 2.4 and earlier insecurely loads Dynamic Link Libraries (DLLs), which could allow an attacker to execute arbitrary code with the privileges of the user invoking the installer.

πŸ“… Published: March 25, 2026, 5:44 a.m. πŸ”„ Last Modified: March 25, 2026, 9:15 p.m.

8.4

CVSS4.0

CVE-2026-33253 - Unquoted Service Path Allows SYSTEM Privilege Escalation in SANYO DENKI SANUPS Software

SANUPS SOFTWARE provided by SANYO DENKI CO., LTD. registers Windows services with unquoted file paths. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.

πŸ“… Published: March 25, 2026, 5:11 a.m. πŸ”„ Last Modified: March 25, 2026, 9:15 p.m.

8.2

CVSS3.1

CVE-2026-2072 - Cross-Site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor and Hitachi Ops Cent…

Cross-Site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Analytics probe component), Hitachi Ops Center Analyzer.This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.5-00.

πŸ“… Published: March 25, 2026, 2:15 a.m. πŸ”„ Last Modified: March 25, 2026, 9:15 p.m.

4.3

CVSS3.1

CVE-2026-1166 - Open Redirect Vulnerability in Hitachi Ops Center Administrator

Open Redirect vulnerability in Hitachi Ops Center Administrator.This issue affects Hitachi Ops Center Administrator: from 10.2.0 before 11.0.8.

πŸ“… Published: March 25, 2026, 2:07 a.m. πŸ”„ Last Modified: March 25, 2026, 9:15 p.m.

6.4

CVSS3.1

CVE-2026-4766 - Easy Image Gallery <= 1.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery …

The Easy Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Gallery shortcode post meta field in all versions up to, and including, 1.5.3. This is due to insufficient input sanitization and output escaping on user-supplied gallery shortcode values. This makes it…

πŸ“… Published: March 25, 2026, 1:25 a.m. πŸ”„ Last Modified: April 24, 2026, 4:32 p.m.

6.9

CVSS4.0

CVE-2026-4784 - code-projects Simple Laundry System Parameter checkcheckout.php sql injection

A vulnerability was found in code-projects Simple Laundry System 1.0. This affects an unknown function of the file /checkcheckout.php of the component Parameter Handler. The manipulation of the argument serviceId results in sql injection. It is possible to launch the attack remotely. The exploit ha…

πŸ“… Published: March 25, 2026, 1:09 a.m. πŸ”„ Last Modified: April 3, 2026, 9:18 p.m.

3.3

CVSS3.1

CVE-2026-28864 - Local Keychain Access Exploit in Apple Operating Systems

This issue was addressed with improved permissions checking. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. A local attacker may gain access to user's Keychain items.

πŸ“… Published: March 25, 2026, 12:35 a.m. πŸ”„ Last Modified: April 2, 2026, 6:27 p.m.

4.3

CVSS3.1

CVE-2026-20691 - webkitgtk: A maliciously crafted webpage may be able to fingerprint the user

An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. A maliciously crafted webpage may be able to fingerprint the user.

πŸ“… Published: March 25, 2026, 12:35 a.m. πŸ”„ Last Modified: April 2, 2026, 6:27 p.m.
Total resulsts: 349182
Page 910 of 34,919
Β« previous page Β» next page
Filters