5.1

CVSS4.0

CVE-2026-1517 - iomad Company Admin Block sql injection

A vulnerability was identified in iomad up to 5.0. Affected is an unknown function of the component Company Admin Block. Such manipulation leads to sql injection. The attack can be executed remotely. It is best practice to apply a patch to resolve this issue.

📅 Published: Feb. 5, 2026, 12:02 p.m. 🔄 Last Modified: April 18, 2026, 6:30 p.m.

7.2

CVSS3.1

CVE-2026-23572 - Improper Access Control in TeamViewer clients

Improper access control in the TeamViewer Full and Host clients (Windows, macOS, Linux) prior version 15.74.5 allows an authenticated user to bypass additional access controls with “Allow after confirmation” configuration in a remote session. An exploit could result in unauthorized access prior to …

📅 Published: Feb. 5, 2026, 11:51 a.m. 🔄 Last Modified: April 17, 2026, 11:15 p.m.

2.4

CVSS4.0

CVE-2026-1966 - YugabyteDB Anywhere Exposes LDAP Credentials in Cleartext in Web UI

YugabyteDB Anywhere displays LDAP bind passwords configured via gflags in cleartext within the web UI. An authenticated user with access to the configuration view could obtain LDAP credentials, potentially enabling unauthorized access to external directory services.

📅 Published: Feb. 5, 2026, 11:38 a.m. 🔄 Last Modified: April 17, 2026, 11:15 p.m.

4.8

CVSS4.0

CVE-2026-23796 - Session Fixation in Quick.Cart

Quick.Cart allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID for a victim and later hijack the authenticated session. The vendor was notified early about this …

📅 Published: Feb. 5, 2026, 11:07 a.m. 🔄 Last Modified: April 17, 2026, 11:15 p.m.

6.9

CVSS4.0

CVE-2026-23797 - Plaintext password display in Quick.Cart

In Quick.Cart user passwords are stored in plaintext form. An attacker with high privileges can display users' password in user editing page. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.7 w…

📅 Published: Feb. 5, 2026, 11:07 a.m. 🔄 Last Modified: April 17, 2026, 11:15 p.m.

6.1

CVSS3.1

CVE-2026-1654 - Peter's Date Countdown <= 2.0.0 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF']

The Peter's Date Countdown plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to in…

📅 Published: Feb. 5, 2026, 9:13 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2026-1294 - All In One Image Viewer Block <= 1.0.2 - Unauthenticated Server-Side Request Forgery via image-prox…

The All In One Image Viewer Block plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.2 due to missing authorization and URL validation on the image-proxy REST API endpoint. This makes it possible for unauthenticated attackers to make web requ…

📅 Published: Feb. 5, 2026, 9:13 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2026-1271 - ProfileGrid <= 5.9.7.2 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary …

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.9.7.2 via the 'pm_upload_image' and 'pm_upload_cover_image' AJAX actions. This is due to the update_user_meta() function being calle…

📅 Published: Feb. 5, 2026, 9:13 a.m. 🔄 Last Modified: April 16, 2026, 1:15 a.m.

5.3

CVSS3.1

CVE-2025-14079 - ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.5 - Missing Authorization to Authenticat…

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.3.5. This is due to missing capability checks on the eh_crm_ticket_general function combined with a shared nonce that is exposed to low-privile…

📅 Published: Feb. 5, 2026, 9:13 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2026-25698 -

Not used

📅 Published: Feb. 5, 2026, 8:56 a.m. 🔄 Last Modified: Feb. 6, 2026, 3:55 a.m.
Total resulsts: 346555
Page 1527 of 34,656
« previous page » next page
Filters