5.3

CVSS3.1

CVE-2026-2373 - Royal Addons for Elementor โ€“ Addons and Templates Kit for Elementor <= 1.7.1049 - Missing Authorizaโ€ฆ

The Royal Addons for Elementor โ€“ Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.1049 via the get_main_query_args() function due to insufficient restrictions on which posts can be included. This makes it posโ€ฆ

๐Ÿ“… Published: March 17, 2026, 3:36 a.m. ๐Ÿ”„ Last Modified: March 17, 2026, 3:36 a.m.

5.3

CVSS4.0

CVE-2026-4307 - frdel/agent0ai agent-zero files.py get_abs_path path traversal

A security flaw has been discovered in frdel/agent0ai agent-zero 0.9.7-10. The impacted element is the function get_abs_path of the file python/helpers/files.py. The manipulation results in path traversal. The attack can be executed remotely. The exploit has been released to the public and may be uโ€ฆ

๐Ÿ“… Published: March 17, 2026, 3:32 a.m. ๐Ÿ”„ Last Modified: March 17, 2026, 3:32 a.m.

8.3

CVSS3.1

CVE-2026-0708 - Libucl: libucl: denial of service via embedded null byte in ucl input

A flaw was found in libucl. A remote attacker could exploit this by providing a specially crafted Universal Configuration Language (UCL) input that contains a key with an embedded null byte. This can cause a segmentation fault (SEGV fault) in the `ucl_object_emit` function when parsing and emittingโ€ฆ

๐Ÿ“… Published: March 17, 2026, 2:28 a.m. ๐Ÿ”„ Last Modified: March 17, 2026, 2:20 p.m.

7.5

CVSS3.1

CVE-2026-2579 - WowStore โ€“ Store Builder & Product Blocks for WooCommerce <= 4.4.3 - Unauthenticated SQL Injection โ€ฆ

The WowStore โ€“ Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the โ€˜searchโ€™ parameter in all versions up to, and including, 4.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQLโ€ฆ

๐Ÿ“… Published: March 17, 2026, 1:24 a.m. ๐Ÿ”„ Last Modified: March 17, 2026, 1:24 a.m.

6.9

CVSS4.0

CVE-2026-4289 - Tiandy Easy7 Integrated Management Platform getRecByTemplateId sql injection

A security vulnerability has been detected in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This affects an unknown function of the file /rest/preSetTemplate/getRecByTemplateId. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploitโ€ฆ

๐Ÿ“… Published: March 17, 2026, 12:03 a.m. ๐Ÿ”„ Last Modified: March 17, 2026, 12:03 a.m.

6.9

CVSS4.0

CVE-2026-4288 - Tiandy Easy7 Integrated Management Platform Endpoint getDevDetailedInfo sql injection

A weakness has been identified in Tiandy Easy7 Integrated Management Platform 7.17.0. The impacted element is an unknown function of the file /rest/devStatus/getDevDetailedInfo of the component Endpoint. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launchโ€ฆ

๐Ÿ“… Published: March 17, 2026, 12:02 a.m. ๐Ÿ”„ Last Modified: March 17, 2026, 12:02 a.m.

0.0

CVE-2025-71239 - audit: add fchmodat2() to change attributes class

In the Linux kernel, the following vulnerability has been resolved: audit: add fchmodat2() to change attributes class fchmodat2(), introduced in version 6.6 is currently not in the change attribute class of audit. Calling fchmodat2() to change a file attribute in the same fashion than chmod() or โ€ฆ

๐Ÿ“… Published: March 17, 2026, midnight ๐Ÿ”„ Last Modified: March 18, 2026, 5:16 p.m.

8.1

CVSS3.1

CVE-2026-30707 -

An issue was discovered in SpeedExam Online Examination System (SaaS) after v.FEV2026. It allows Broken Access Control via the ReviewAnswerDetails ASP.NET PageMethod. Authenticated attackers can bypass client-side restrictions and invoke this method directly to retrieve the full answer key

๐Ÿ“… Published: March 17, 2026, midnight ๐Ÿ”„ Last Modified: March 18, 2026, 2:52 p.m.

0.0

CVE-2026-23241 - audit: add missing syscalls to read class

In the Linux kernel, the following vulnerability has been resolved: audit: add missing syscalls to read class The "at" variant of getxattr() and listxattr() are missing from the audit read class. Calling getxattrat() or listxattrat() on a file to read its extended attributes will bypass audit rulโ€ฆ

๐Ÿ“… Published: March 17, 2026, midnight ๐Ÿ”„ Last Modified: March 18, 2026, 12:13 p.m.

6.9

CVSS4.0

CVE-2026-4287 - Tiandy Easy7 Integrated Management Platform Endpoint queryResources sql injection

A security flaw has been discovered in Tiandy Easy7 Integrated Management Platform 7.17.0. The affected element is an unknown function of the file /rest/devStatus/queryResources of the component Endpoint. Performing a manipulation of the argument areaId results in sql injection. The attack can be iโ€ฆ

๐Ÿ“… Published: March 16, 2026, 11:33 p.m. ๐Ÿ”„ Last Modified: March 16, 2026, 11:33 p.m.
Total resulsts: 339298
Page 104 of 33,930
ยซ previous page ยป next page
Filters