6.5

CVSS3.1

CVE-2026-2412 - Quiz and Survey Master (QSM) <= 10.3.5 - Authenticated (Contributor+) SQL Injection via 'merged_que…

The Quiz and Survey Master (QSM) plugin for WordPress is vulnerable to SQL Injection via the 'merged_question' parameter in all versions up to, and including, 10.3.5. This is due to insufficient sanitization of user-supplied input before being used in a SQL query. The sanitize_text_field() function…

📅 Published: March 23, 2026, 10:25 p.m. 🔄 Last Modified: March 25, 2026, 8:36 p.m.

4.3

CVSS3.1

CVE-2026-4066 - Smart Custom Fields <= 5.0.6 - Missing Authorization to Authenticated (Contributor+) Sensitive Info…

The Smart Custom Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relational_posts_search() function in all versions up to, and including, 5.0.6. This makes it possible for authenticated attackers, with Contributor-level access and ab…

📅 Published: March 23, 2026, 10:25 p.m. 🔄 Last Modified: March 24, 2026, 10:30 a.m.

6.9

CVSS4.0

CVE-2026-4612 - itsourcecode Free Hotel Reservation System Parameter index.php sql injection

A vulnerability has been found in itsourcecode Free Hotel Reservation System 1.0. This affects an unknown part of the file /hotel/admin/mod_users/index.php?view=edit&id=8 of the component Parameter Handler. The manipulation of the argument account_id leads to sql injection. Remote exploitation of t…

📅 Published: March 23, 2026, 9:57 p.m. 🔄 Last Modified: March 24, 2026, 10:30 a.m.

9.3

CVSS4.0

CVE-2026-4681 - Critical Remote Code Execution vulnerability reported in Windchill

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. This issue affects Windchill PDMLink: 11.0 M030, 11.1 M020, 11.2.1.0, 12.0.2.0, 12.1.2.0, 13.0.2.0, 13.1.0.0, 1…

📅 Published: March 23, 2026, 9:48 p.m. 🔄 Last Modified: March 24, 2026, 10:30 a.m.

9.4

CVSS4.0

CVE-2026-33634 - Trivy ecosystem supply chain briefly compromised

Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all 7 tags in `aquasecurity/setup-trivy` with malicio…

📅 Published: March 23, 2026, 9:47 p.m. 🔄 Last Modified: March 27, 2026, 1:16 a.m.

8.1

CVSS3.1

CVE-2026-32300 - Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Ar…

Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Versions 1.41.1…

📅 Published: March 23, 2026, 9:40 p.m. 🔄 Last Modified: March 25, 2026, 8:36 p.m.

7.5

CVSS3.1

CVE-2026-32299 - Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieva…

Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Versions 1.41.1 and 2.…

📅 Published: March 23, 2026, 9:37 p.m. 🔄 Last Modified: March 25, 2026, 8:36 p.m.

6.8

CVSS3.1

CVE-2026-32279 - Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin

Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, a Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Versions 1.41.1 and…

📅 Published: March 23, 2026, 9:36 p.m. 🔄 Last Modified: March 25, 2026, 8:36 p.m.

8.8

CVSS4.0

CVE-2026-32913 - OpenClaw < 2026.3.7 - Custom Authorization Header Leakage via Cross-Origin Redirects

OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom authorization headers across cross-origin redirects. Attackers can trigger redirects to different origins to intercept sensitive headers like X-Api-Key and Private-Token intended…

📅 Published: March 23, 2026, 9:36 p.m. 🔄 Last Modified: March 25, 2026, 8:36 p.m.

0.0

CVE-2026-32912 -

This CVE ID has been rejected.

📅 Published: March 23, 2026, 9:36 p.m. 🔄 Last Modified: March 23, 2026, 11:17 p.m.
Total resulsts: 340915
Page 137 of 34,092
« previous page » next page
Filters