6.4

CVSS3.1

CVE-2026-1210 - Happy Addons for Elementor <= 3.20.7 - Authenticated (Contributor+) Stored Cross-Site Scripting viaโ€ฆ

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_elementor_data' meta field in all versions up to, and including, 3.20.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Conโ€ฆ

๐Ÿ“… Published: Feb. 3, 2026, 6:38 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2026-1065 - Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via SVG file

The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.15.35. This is due to the plugin's default file upload allowlist including SVG files combined with weak substring-based extension validation. This makes it possible for โ€ฆ

๐Ÿ“… Published: Feb. 3, 2026, 6:38 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2026-0617 - LatePoint โ€“ Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Unauthenticated Stored Cโ€ฆ

The LatePoint โ€“ Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer profile fields in all versions up to, and including, 5.2.5 due to insufficient input sanitization and output escaping. This makes it possible for unโ€ฆ

๐Ÿ“… Published: Feb. 3, 2026, 6:38 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 9:45 p.m.

4.6

CVSS4.0

CVE-2025-58381 - Directory transversal vulnerability in Brocade Fabric OS before 9.2.1c2 and 9.2.2 through 9.2.2a usโ€ฆ

A vulnerability in Brocade Fabric OS before 9.2.1c2 could allow an authenticated attacker with admin privileges using the shell commands โ€œsource, ping6, sleep, disown, wait to modify the path variables and move upwards in the directory structure or to traverse to different directories.

๐Ÿ“… Published: Feb. 3, 2026, 5:40 a.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 8:53 p.m.

5.3

CVSS3.1

CVE-2026-0950 - Spectra Gutenberg Blocks <= 2.19.17 - Unauthenticated Information Disclosure in Sensitive Data

The Spectra Gutenberg Blocks โ€“ Website Builder for the Block Editor plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 2.19.17. This is due to the plugin failing to check `post_password_required()` before rendering post excerpts in the `render_excerptโ€ฆ

๐Ÿ“… Published: Feb. 3, 2026, 5:30 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-14274 - Unlimited Elements for Elementor <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Scriptinโ€ฆ

The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Border Hero widget's Button Link field in versions up to 2.0.1. This is due to insufficient input sanitization and output escaping on user-supplied URLs. This makes it possible for authentโ€ฆ

๐Ÿ“… Published: Feb. 3, 2026, 5:30 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.4

CVSS4.0

CVE-2026-24694 - Installer Loads Untrusted DLLs Leading to Arbitrary Code Execution in Roland Cloud Manager

The installer for Roland Cloud Manager ver.3.1.19 and prior insecurely loads Dynamic Link Libraries (DLLs), which could allow an attacker to execute arbitrary code with the privileges of the application.

๐Ÿ“… Published: Feb. 3, 2026, 5:27 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 12:30 a.m.

8.5

CVSS4.0

CVE-2025-9711 - Privilege escalation in Brocade Fabric OS before 9.2.1c3, and 9.2.2 though 9.2.2b

A vulnerability in Brocade Fabric OS before 9.2.1c3 could allow elevating the privileges of the local authenticated user to โ€œrootโ€ using the export option of seccertmgmt and seccryptocfg commands.

๐Ÿ“… Published: Feb. 3, 2026, 5:19 a.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 3:04 p.m.

4.6

CVSS4.0

CVE-2025-58380 - Directory transversal vulnerability in Brocade Fabric OS before 9.2.1 using grep command

A vulnerability in Brocade Fabric OS before 9.2.1 could allow an authenticated attacker with admin privileges using the shell command โ€œgrepโ€ to modify the path variables and move upwards in the directory structure or to traverse to different directories.

๐Ÿ“… Published: Feb. 3, 2026, 5:05 a.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 8:52 p.m.

8.2

CVSS4.0

CVE-2026-0383 - Information disclosure in Brocade Fabric OS before 9.2.1c2, 9.2.2 through 9.2.2a and 10.0.0

A vulnerability in Brocade Fabric OS could allow an authenticated, local attacker with privileges to access the Bash shell to access insecurely stored file contents including the history command.

๐Ÿ“… Published: Feb. 3, 2026, 3:55 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 2:30 p.m.
Total resulsts: 349182
Page 1843 of 34,919
ยซ previous page ยป next page
Filters