6.1

CVSS3.1

CVE-2026-1404 - Ultimate Member <= 2.11.1 - Reflected Cross-Site Scripting via Filter Parameters

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the filter parameters (e.g., 'filter_first_name') in all versions up to, and including, 2.11.1 due to insuffici…

📅 Published: Feb. 18, 2026, 2:24 p.m. 🔄 Last Modified: April 15, 2026, 5:30 p.m.

8.8

CVSS3.1

CVE-2026-1426 - Advanced AJAX Product Filters <= 3.1.9.6 - Authenticated (Author+) PHP Object Injection via Live Co…

The Advanced AJAX Product Filters plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.9.6 via deserialization of untrusted input in the shortcode_check function within the Live Composer compatibility layer. This makes it possible for authenticated at…

📅 Published: Feb. 18, 2026, 2:24 p.m. 🔄 Last Modified: April 15, 2026, 8:30 p.m.

4.3

CVSS3.1

CVE-2026-27100 - org.jenkins-ci.main/jenkins-core: Jenkins: Information disclosure via unauthorized access to build …

Jenkins 2.550 and earlier, LTS 2.541.1 and earlier accepts Run Parameter values that refer to builds the user submitting the build does not have access to, allowing attackers with Item/Build and Item/Configure permission to obtain information about the existence of jobs, the existence of builds, an…

📅 Published: Feb. 18, 2026, 2:17 p.m. 🔄 Last Modified: April 17, 2026, 6:45 p.m.

8

CVSS3.1

CVE-2026-27099 - org.jenkins-ci.main/jenkins-core: Jenkins: Stored Cross-site Scripting (XSS) via unescaped user-pro…

Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-provided description of the "Mark temporarily offline" offline cause, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure or A…

📅 Published: Feb. 18, 2026, 2:17 p.m. 🔄 Last Modified: April 18, 2026, noon

9.3

CVSS4.0

CVE-2026-2329 - Grandstream GXP1600 VoIP Phones - Unauthenticated stack buffer overflow

An unauthenticated stack-based buffer overflow vulnerability exists in the HTTP API endpoint /cgi-bin/api.values.get. A remote attacker can leverage this vulnerability to achieve unauthenticated remote code execution (RCE) with root privileges on a target device. The vulnerability affects all six d…

📅 Published: Feb. 18, 2026, 2:08 p.m. 🔄 Last Modified: April 17, 2026, 6:45 p.m.

7.8

CVSS3.1

CVE-2025-60038 -

A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated file containing malicious serialized data. Exploitation requires user interaction, specifically opening a specially crafted file, which the…

📅 Published: Feb. 18, 2026, 2:03 p.m. 🔄 Last Modified: Feb. 24, 2026, 4:01 p.m.

7.8

CVSS3.1

CVE-2025-60037 -

A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated file containing malicious serialized data. Exploitation requires user interaction, specifically opening a specially crafted file, which the…

📅 Published: Feb. 18, 2026, 2:03 p.m. 🔄 Last Modified: Feb. 24, 2026, 4:02 p.m.

7.8

CVSS3.1

CVE-2025-60036 -

A vulnerability has been identified in the UA.Testclient utility, which is included in Rexroth IndraWorks. All versions prior to 15V24 are affected. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated file containing malicious serialized data. Exploi…

📅 Published: Feb. 18, 2026, 2:02 p.m. 🔄 Last Modified: Feb. 24, 2026, 4:02 p.m.

2

CVSS4.0

CVE-2026-2655 - ChaiScript chaiscript_defines.hpp operator use after free

A vulnerability was detected in ChaiScript up to 6.1.0. The impacted element is the function chaiscript::str_less::operator of the file include/chaiscript/chaiscript_defines.hpp. The manipulation results in use after free. The attack requires a local approach. The attack requires a high level of co…

📅 Published: Feb. 18, 2026, 2:02 p.m. 🔄 Last Modified: April 17, 2026, 6:45 p.m.

7.8

CVSS3.1

CVE-2025-60035 -

A vulnerability has been identified in the OPC.Testclient utility, which is included in Rexroth IndraWorks. All versions prior to 15V24 are affected. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated file containing malicious serialized data. Explo…

📅 Published: Feb. 18, 2026, 2:01 p.m. 🔄 Last Modified: Feb. 24, 2026, 4:01 p.m.
Total resulsts: 349182
Page 1590 of 34,919
« previous page » next page
Filters