7.2

CVSS3.1

CVE-2026-2568 - WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.5 - Unauthenti…

The WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission data in all versions up to, and including, 1.1.5 due to insufficient input sanitization and output escaping. This makes it possible…

📅 Published: March 3, 2026, 9:24 a.m. 🔄 Last Modified: April 22, 2026, 9:26 p.m.

9.8

CVSS3.1

CVE-2026-22886 - Default Credentials Persist in Eclipse OpenMQ TCP Management Service Allowing Remote Administration

OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a default administrative account (admin/ admin) and does not enforce a mandatory password change on first use. After the first successful login, the server continues t…

📅 Published: March 3, 2026, 9:18 a.m. 🔄 Last Modified: April 16, 2026, 2:15 p.m.

8.7

CVSS4.0

CVE-2026-1876 - Denial-of-Service (DoS) vulnerability in Ethernet function of MELSEC iQ-F Series Ethernet module

Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP all versions allows a remote attacker to cause a denial-of-service (DoS) condition on the products by continuously sending UDP packets to the products. A…

📅 Published: March 3, 2026, 7:03 a.m. 🔄 Last Modified: April 30, 2026, 8:40 p.m.

8.7

CVSS4.0

CVE-2026-1875 - Denial-of-Service (DoS) vulnerability in Ethernet function of MELSEC iQ-F Series EtherNet/IP module

Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-EIP EtherNet/IP Module FX5-EIP versions 1.000 and prior allows a remote attacker to cause a denial-of-service (DoS) condition on the products by continuously sending UDP packets to the prod…

📅 Published: March 3, 2026, 6:54 a.m. 🔄 Last Modified: April 24, 2026, 8:16 a.m.

8.7

CVSS4.0

CVE-2026-1874 - Denial-of-Service (DoS) vulnerability in Ethernet function of MELSEC iQ-F Series EtherNet/IP module…

Always-Incorrect Control Flow Implementation vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP versions 1.106 and prior and Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-EIP EtherNet/IP Module FX5-EIP versions 1.000 and prior allows…

📅 Published: March 3, 2026, 6:46 a.m. 🔄 Last Modified: May 4, 2026, 2:27 p.m.

8.7

CVSS4.0

CVE-2025-12345 - LLM-Claw Agent Deployment initiate.c agent_deploy_init buffer overflow

A security vulnerability has been detected in LLM-Claw 0.1.0/0.1.1/0.1.1a/0.1.1a-p1. The affected element is the function agent_deploy_init of the file /agents/deploy/initiate.c of the component Agent Deployment. Such manipulation leads to buffer overflow. It is possible to launch the attack remote…

📅 Published: March 3, 2026, 6:32 a.m. 🔄 Last Modified: April 22, 2026, 9:26 p.m.

5.7

CVSS4.0

CVE-2025-15595 - Privilege escalation via dll hijacking in Inno Setup

Privilege escalation via dll hijacking in Inno Setup 6.2.1 and ealier versions.

📅 Published: March 3, 2026, 6:13 a.m. 🔄 Last Modified: March 13, 2026, 5:55 p.m.

5.1

CVSS4.0

CVE-2026-3455 - mailparser Cross‑Site Scripting via textToHtml URL Sanitization

Versions of the package mailparser before 3.9.3 are vulnerable to Cross-site Scripting (XSS) via the textToHtml() function due to the improper sanitisation of URLs in the email content. An attacker can execute arbitrary scripts in victim browsers by adding extra quote " to the URL with embedded ma…

📅 Published: March 3, 2026, 5 a.m. 🔄 Last Modified: April 17, 2026, 1:30 p.m.

4.8

CVSS4.0

CVE-2026-3449 - @tootallnate/once: @tootallnate/once: Denial of Service due to incorrect control flow scoping with …

Versions of the package @tootallnate/once before 3.0.1 are vulnerable to Incorrect Control Flow Scoping in promise resolving when AbortSignal option is used. The Promise remains in a permanently pending state after the signal is aborted, causing any await or .then() usage to hang indefinitely. This…

📅 Published: March 3, 2026, 5 a.m. 🔄 Last Modified: April 17, 2026, 1:30 p.m.

9.8

CVSS3.1

CVE-2026-1492 - User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership Regis…

The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including, 5.1.2. This is due to the plugin accepting a user…

📅 Published: March 3, 2026, 4:33 a.m. 🔄 Last Modified: April 22, 2026, 9:26 p.m.
Total resulsts: 348435
Page 1289 of 34,844
« previous page » next page
Filters