6.4

CVSS3.1

CVE-2026-1252 - Events Listing Widget <= 1.3.4 - Authenticated (Author+) Stored Cross-Site Scripting via Event URL …

The Events Listing Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Event URL' parameter in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level acc…

πŸ“… Published: Feb. 6, 2026, 8:25 a.m. πŸ”„ Last Modified: April 15, 2026, 9:30 p.m.

4.3

CVSS3.1

CVE-2026-1785 - Code Snippets <= 3.9.4 - Cross-Site Request Forgery to Cloud Snippet Download/Update Actions

The Code Snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.9.4. This is due to missing nonce validation on the cloud snippet download and update actions in the Cloud_Search_List_Table class. This makes it possible for unauthenticated a…

πŸ“… Published: Feb. 6, 2026, 8:25 a.m. πŸ”„ Last Modified: April 8, 2026, 4:50 p.m.

8.8

CVSS3.1

CVE-2026-1499 - WP Duplicate <= 1.1.8 - Authenticated (Subscriber+) Arbitrary File Upload via 'process_add_site' AJ…

The WP Duplicate plugin for WordPress is vulnerable to Missing Authorization leading to Arbitrary File Upload in all versions up to and including 1.1.8. This is due to a missing capability check on the `process_add_site()` AJAX action combined with path traversal in the file upload functionality. T…

πŸ“… Published: Feb. 6, 2026, 8:25 a.m. πŸ”„ Last Modified: April 14, 2026, 3:12 p.m.

9.1

CVSS3.1

CVE-2026-21643 -

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

πŸ“… Published: Feb. 6, 2026, 8:24 a.m. πŸ”„ Last Modified: April 14, 2026, 2:21 p.m.

8.4

CVSS3.1

CVE-2026-24926 - Out‑of‑Bounds Write in HarmonyOS Camera Module

Out-of-bounds write vulnerability in the camera module. Impact: Successful exploitation of this vulnerability may affect availability.

πŸ“… Published: Feb. 6, 2026, 8:23 a.m. πŸ”„ Last Modified: April 17, 2026, 11 p.m.

7.3

CVSS3.1

CVE-2026-24925 - Heap-Based Buffer Overflow in Image Module

Heap-based buffer overflow vulnerability in the image module. Impact: Successful exploitation of this vulnerability may affect availability.

πŸ“… Published: Feb. 6, 2026, 8:22 a.m. πŸ”„ Last Modified: April 17, 2026, 11 p.m.

5.3

CVSS3.1

CVE-2026-2100 - P11-kit: p11-kit: null dereference via c_derivekey with specific null parameters

A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentiall…

πŸ“… Published: Feb. 6, 2026, 8:08 a.m. πŸ”„ Last Modified: April 15, 2026, 4:45 p.m.

2.3

CVSS4.0

CVE-2026-2010 - Sanluan PublicCMS Trade Payment TradePaymentService.java paid improper authorization

A vulnerability has been found in Sanluan PublicCMS up to 4.0.202506.d/5.202506.d/6.202506.d. Impacted is the function Paid of the file publiccms-parent/publiccms-trade/src/main/java/com/publiccms/logic/service/trade/TradePaymentService.java of the component Trade Payment Handler. The manipulation …

πŸ“… Published: Feb. 6, 2026, 8:02 a.m. πŸ”„ Last Modified: April 17, 2026, 11 p.m.

9.2

CVSS4.0

CVE-2026-21626 - Extension - stackideas.com - Information disclosure in post custom fields in EasyDiscuss 1.0.0-5.0.…

Access control settings for forum post custom fields are not applied to the JSON output type, leading to an ACL violation vector an information disclosure

πŸ“… Published: Feb. 6, 2026, 7:49 a.m. πŸ”„ Last Modified: April 18, 2026, 6:30 p.m.

5.3

CVSS4.0

CVE-2026-2009 - SourceCodester Gas Agency Management System createUser.php access control

A flaw has been found in SourceCodester Gas Agency Management System 1.0. This issue affects some unknown processing of the file /gasmark/php_action/createUser.php. Executing a manipulation can lead to improper access controls. It is possible to launch the attack remotely. The exploit has been publ…

πŸ“… Published: Feb. 6, 2026, 7:32 a.m. πŸ”„ Last Modified: April 18, 2026, 1:45 p.m.
Total resulsts: 345293
Page 1390 of 34,530
Β« previous page Β» next page
Filters