5.3

CVSS4.0

CVE-2026-28769 - LFI in /IDC_Logging/checkifdone.cgi, "file" parameter Allowing for File Existence Enumeration On ID…

A path traversal vulnerability exists in the /IDC_Logging/checkifdone.cgi script in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver Web management portal version 101. An authenticated attacker can manipulate the `file` parameter to traverse directories and enumer…

📅 Published: March 4, 2026, 7:02 a.m. 🔄 Last Modified: April 16, 2026, 2 p.m.

5.4

CVSS3.1

CVE-2026-2732 - Enable Media Replace <= 4.1.7 - Improper Authorization to Authenticated (Author+) Arbitrary Attachm…

The Enable Media Replace plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'RemoveBackGroundViewController::load' function in all versions up to, and including, 4.1.7. This makes it possible for authenticated attackers, with Author-le…

📅 Published: March 4, 2026, 6:26 a.m. 🔄 Last Modified: April 22, 2026, 9:26 p.m.

6.5

CVSS3.1

CVE-2026-2363 - WP-Members Membership Plugin <= 3.5.5.1 - Authenticated (Contributor+) SQL Injection via 'order_by'…

The WP-Members Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'order_by' attribute of the [wpmem_user_membership_posts] shortcode in all versions up to, and including, 3.5.5.1. This is due to insufficient escaping on the user supplied parameter and lack of sufficient …

📅 Published: March 4, 2026, 6:26 a.m. 🔄 Last Modified: April 22, 2026, 9:26 p.m.

9.3

CVSS4.0

CVE-2026-27446 - Apache Artemis, Apache ActiveMQ Artemis: Auth bypass for Core downstream federation

Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to force a target broker to establish an outbound Core federation connection to an attacker-controlled rogue broker. This cou…

📅 Published: March 4, 2026, 6:06 a.m. 🔄 Last Modified: April 17, 2026, 1:15 p.m.

7.5

CVSS3.1

CVE-2026-2025 - Mail Mint < 1.19.5 - Unauthenticated Emails Disclosure

The Mail Mint WordPress plugin before 1.19.5 does not have authorization in one of its REST API endpoint, allowing unauthenticated users to call it and retrieve the email addresses of users on the blog

📅 Published: March 4, 2026, 6 a.m. 🔄 Last Modified: April 16, 2026, 2 p.m.

2.3

CVSS4.0

CVE-2026-2994 - Concrete CMS below 9.4.8 is vulnerable to CSRF by a Rogue Admin using the Anti-Spam Allowlist Group

Concrete CMS below version 9.4.8 is subject to CSRF by a Rogue Administrator using the Anti-Spam Allowlist Group Configuration via group_id parameter which can leads to a security bypass since changes are saved prior to checking the CSRF token. The Concrete CMS security team gave this vulnerability…

📅 Published: March 4, 2026, 2:18 a.m. 🔄 Last Modified: April 17, 2026, 1:15 p.m.

4.8

CVSS4.0

CVE-2026-3240 - Concrete CMS below 9.4.8 is vulnerable to Stored XSS via Legacy form

In Concrete CMS below version 9.4.8, a user with permission to edit a page with element Legacy form can perform a stored XSS attack towards high-privilege accounts via the Question field. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 4.8 with vector CVSS:4.0/AV:N/AC:L…

📅 Published: March 4, 2026, 2:15 a.m. 🔄 Last Modified: April 17, 2026, 1:30 p.m.

4.8

CVSS4.0

CVE-2026-3241 - Concrete CMS below version 9.4.8 is vulnerable to a stored cross-site scripting (XSS) in the "Legac…

In Concrete CMS below version 9.4.8, a stored cross-site scripting (XSS) vulnerability exists in the "Legacy Form" block. An authenticated user with permissions to create or edit forms (e.g., a rogue administrator) can inject a persistent JavaScript payload into the options of a multiple-choice que…

📅 Published: March 4, 2026, 2:12 a.m. 🔄 Last Modified: April 18, 2026, 10:15 a.m.

4.8

CVSS4.0

CVE-2026-3242 - Concrete CMS below 9.4.8 is vulnerable to Stored XSS in the Switch Language block

In Concrete CMS below version 9.4.8, a rogue administrator can add stored XSS via the Switch Language block.  The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 4.8 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N.  Thanks M3dium for reporting.

📅 Published: March 4, 2026, 2 a.m. 🔄 Last Modified: April 17, 2026, 1:30 p.m.

4.8

CVSS4.0

CVE-2026-3244 - Concrete CMS below version 9.4.8 is vulnerable to Stored XSS in Search Results via Page Names

In Concrete CMS below version 9.4.8, A stored cross-site scripting (XSS) vulnerability exists in the search block where page names and content are rendered without proper HTML encoding in search results. This allows authenticated, rogue administrators to inject malicious JavaScript through page nam…

📅 Published: March 4, 2026, 1:55 a.m. 🔄 Last Modified: April 18, 2026, 10:15 a.m.
Total resulsts: 348490
Page 1283 of 34,849
« previous page » next page
Filters