6.4

CVSS3.1

CVE-2026-3005 - List category posts <= 0.94.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'catlist' S…

The List category posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catlist' shortcode in all versions up to, and including, 0.94.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticate…

πŸ“… Published: April 9, 2026, 12:28 p.m. πŸ”„ Last Modified: April 24, 2026, 6:02 p.m.

9.1

CVSS3.1

CVE-2025-57735 - Apache Airflow: Airflow Logout Not Invalidating JWT

When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was intercepted. In Airflow 3.2 we implemented the mechanism that implements token invalidation at logout. Users who are concerned about the logout scenario a…

πŸ“… Published: April 9, 2026, 11:12 a.m. πŸ”„ Last Modified: April 17, 2026, 1:03 p.m.

0.0

CVE-2026-5968 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“… Published: April 9, 2026, 11:07 a.m. πŸ”„ Last Modified: April 16, 2026, 12:36 p.m.

7.2

CVSS3.1

CVE-2024-1490 - Wago: Vulnerability in WBM through Open VPN

An authenticated remote attacker with high privileges can exploit the OpenVPN configuration via the web-based management interface of a WAGO PLC. If user-defined scripts are permitted, OpenVPN may allow the execution of arbitrary shell commands enabling the attacker to run arbitrary commands on the…

πŸ“… Published: April 9, 2026, 10:52 a.m. πŸ”„ Last Modified: April 13, 2026, 3:02 p.m.

3.7

CVSS3.1

CVE-2026-24661 - Unbounded Request Body Read in MS Teams Plugin {{/changes}} Webhook Endpoint

Mattermost Plugins versions <=2.1.3.0 fail to limit the request body size on the {{/changes}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-00611

πŸ“… Published: April 9, 2026, 10:12 a.m. πŸ”„ Last Modified: April 17, 2026, 8:31 p.m.

3.7

CVSS3.1

CVE-2026-21388 - Unbounded Request Body Read in MS Teams Plugin {{/lifecycle}} Webhook Endpoint

Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-00610

πŸ“… Published: April 9, 2026, 10:09 a.m. πŸ”„ Last Modified: April 25, 2026, 6:02 p.m.

8.7

CVSS4.0

CVE-2026-34185 - SQL Injection in Hydrosystem Control System

Hydrosystem Control System is vulnerable to SQL Injection across most scripts and input parameters. Because no protections are in place, an authenticated attacker can inject arbitrary SQL commands, potentially gaining full control over the database.This issue was fixed in Hydrosystem Control System…

πŸ“… Published: April 9, 2026, 9:41 a.m. πŸ”„ Last Modified: April 20, 2026, 5:05 p.m.

8.8

CVSS4.0

CVE-2026-34184 - Missing Authorization in Hydrosystem Control System

Hydrosystem Control System does not enforce authorization for some directories. This allows an unauthorized attacker to read all files in these directories and even execute some of them. Critically the attacker could run PHP scripts directly on the connected database.This issue was fixed inΒ Hydrosy…

πŸ“… Published: April 9, 2026, 9:41 a.m. πŸ”„ Last Modified: April 20, 2026, 5:06 p.m.

6.9

CVSS4.0

CVE-2026-4901 - Insertion of Sesitive Information into Log File in Hydrosystem Control System

Hydrosystem Control System saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker to obtain further authorized access into the system. Combined with vulnerability CVE-2026-34184, these sensitive information could be accessed by an unauthorized use…

πŸ“… Published: April 9, 2026, 9:40 a.m. πŸ”„ Last Modified: April 20, 2026, 5:05 p.m.

7.5

CVSS3.1

CVE-2025-62188 - Apache DolphinScheduler: Users can access sensitive information through the actuator endpoint.

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler. This vulnerability may allow unauthorized actors to access sensitive information, including database credentials. This issue affects Apache DolphinScheduler versions 3.1.*. Users are …

πŸ“… Published: April 9, 2026, 9:27 a.m. πŸ”„ Last Modified: April 17, 2026, 12:57 p.m.
Total resulsts: 346671
Page 319 of 34,668
Β« previous page Β» next page
Filters