6.4

CVSS3.1

CVE-2026-7209 - Simple Link Directory <= 8.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Short…

The Simple Link Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `qcopd-directory` shortcode in all versions up to, and including, 8.9.2. This is due to insufficient input sanitization and output escaping on user supplied attributes such as `title_font_si…

πŸ“… Published: May 2, 2026, 3:36 a.m. πŸ”„ Last Modified: May 2, 2026, 3:36 a.m.

5.3

CVSS3.1

CVE-2026-7638 - App Builder <= 5.5.10 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary U…

The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to and including 5.6.0. This is due to missing authorization validation in the `upload_avatar()` function, which accepts an attacker-controlled…

πŸ“… Published: May 2, 2026, 3:36 a.m. πŸ”„ Last Modified: May 2, 2026, 3:36 a.m.

6.4

CVSS3.1

CVE-2026-6378 - Maxi Blocks <= 2.1.9 - Authenticated (Author+) Stored Cross-Site Scripting via Style Card REST API

The Maxi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `/wp-json/maxi-blocks/v1.0/style-card` REST API endpoint in all versions up to, and including, 2.1.9 due to insufficient input sanitization and output escaping of the `sc_styles` parameter. This makes it possi…

πŸ“… Published: May 2, 2026, 3:36 a.m. πŸ”„ Last Modified: May 2, 2026, 3:36 a.m.

5.3

CVSS4.0

CVE-2026-7602 - JeecgBoot FillRuleUtil edit improper authorization

A vulnerability was found in JeecgBoot up to 3.9.1. Affected by this vulnerability is an unknown functionality of the file /sys/fillRule/edit of the component FillRuleUtil Component. The manipulation of the argument ruleClass results in improper authorization. The attack may be performed from remot…

πŸ“… Published: May 2, 2026, 3:15 a.m. πŸ”„ Last Modified: May 2, 2026, 3:15 a.m.

5.3

CVSS4.0

CVE-2026-7601 - Open5GS AMF gmm-handler.c denial of service

A vulnerability has been found in Open5GS up to 2.7.6. Affected is an unknown function of the file src/amf/gmm-handler.c of the component AMF. The manipulation of the argument reg_type leads to denial of service. The attack is possible to be carried out remotely. Upgrading to version 2.7.7 is able …

πŸ“… Published: May 2, 2026, 2 a.m. πŸ”„ Last Modified: May 2, 2026, 2 a.m.

7.7

CVSS3.1

CVE-2026-43824 -

In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.

πŸ“… Published: May 2, 2026, 1:20 a.m. πŸ”„ Last Modified: May 2, 2026, 1:42 a.m.

5.3

CVSS4.0

CVE-2026-7600 - ArtMin96 yii2-mcp-server MCP index.ts yii_execute_command os command injection

A flaw has been found in ArtMin96 yii2-mcp-server 1.0.2. This impacts the function yii_command_help/yii_execute_command of the file src/index.ts of the component MCP Interface. Executing a manipulation can lead to os command injection. The attack can be executed remotely. The exploit has been publi…

πŸ“… Published: May 2, 2026, 12:15 a.m. πŸ”„ Last Modified: May 2, 2026, 12:15 a.m.

5.3

CVSS4.0

CVE-2026-7599 - Dayoooun hwpx-mcp MCP index.ts export_to_html path traversal

A vulnerability was detected in Dayoooun hwpx-mcp 0.2.0. This affects the function save_document/export_to_text/export_to_html of the file mcp-server/src/index.ts of the component MCP Interface. Performing a manipulation of the argument output_path results in path traversal. Remote exploitation of …

πŸ“… Published: May 1, 2026, 9:45 p.m. πŸ”„ Last Modified: May 1, 2026, 9:45 p.m.

6.9

CVSS4.0

CVE-2026-7598 - libssh2 userauth.c userauth_password integer overflow

A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow. The attack may be launched remotely. The name of the patch is…

πŸ“… Published: May 1, 2026, 9:30 p.m. πŸ”„ Last Modified: May 1, 2026, 9:30 p.m.

5.3

CVSS4.0

CVE-2026-7597 - mem0ai mem0 faiss.py pickle.dump deserialization

A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used.…

πŸ“… Published: May 1, 2026, 9:15 p.m. πŸ”„ Last Modified: May 1, 2026, 9:15 p.m.
Total resulsts: 347730
Page 10 of 34,773
Β« previous page Β» next page
Filters