5.3

CVSS4.0

CVE-2026-40179 - Prometheus: Stored XSS via metric names and label values in web UI tooltips and metrics explorer

Prometheus is an open-source monitoring system and time series database. Versions 3.0 through 3.5.1 and 3.6.0 through 3.11.1 have stored cross-site scripting vulnerabilities in multiple components of the Prometheus web UI where metric names and label values are injected into innerHTML without escap…

📅 Published: April 15, 2026, 10:26 p.m. 🔄 Last Modified: April 22, 2026, 8:04 p.m.

4.3

CVSS3.1

CVE-2026-4949 - ProfilePress <= 4.16.12 - Missing Authorization to Authenticated (Subscriber+) Inactive Membership …

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.16.12. This is due to the 'process_checkout' function not properly enforcing …

📅 Published: April 15, 2026, 10:26 p.m. 🔄 Last Modified: April 16, 2026, 2:19 p.m.

4.8

CVSS4.0

CVE-2026-1711 - Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerabi…

Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interface component. Requires a high privileged user with a developer role.

📅 Published: April 15, 2026, 9:32 p.m. 🔄 Last Modified: April 23, 2026, 8:01 p.m.

5.1

CVSS4.0

CVE-2026-1564 - Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a us…

Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface component. Requires a high privileged user with a developer role.

📅 Published: April 15, 2026, 9:31 p.m. 🔄 Last Modified: April 23, 2026, 8:02 p.m.

6.1

CVSS4.0

CVE-2026-40500 - ProcessWire CMS SSRF via Add Module From URL

ProcessWire CMS version 3.0.255 and prior contain a server-side request forgery vulnerability in the admin panel's 'Add Module From URL' feature that allows authenticated administrators to supply arbitrary URLs to the module download parameter, causing the server to issue outbound HTTP requests to …

📅 Published: April 15, 2026, 9:25 p.m. 🔄 Last Modified: April 17, 2026, 3:38 p.m.

8.8

CVSS3.1

CVE-2026-40261 - Composer has Command Injection via Malicious Perforce Reference

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $sourceReference parameter to a shell command without proper escaping, and additionally in the Perforce::ge…

📅 Published: April 15, 2026, 8:56 p.m. 🔄 Last Modified: April 25, 2026, 6:12 p.m.

7.8

CVSS3.1

CVE-2026-40176 - Composer is vulnerable to Command Injection via Malicious Perforce Repository

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::generateP4Command() method, which constructs shell commands by interpolating user-supplied Perforce connection parameters (port, user, client) witho…

📅 Published: April 15, 2026, 8:47 p.m. 🔄 Last Modified: April 25, 2026, 6:24 p.m.

8.5

CVSS4.0

CVE-2026-22676 - Barracuda RMM < 2025.2.2 Privilege Escalation via Insecure Directory Permissions

Barracuda RMM versions prior to 2025.2.2 contain a privilege escalation vulnerability that allows local attackers to gain SYSTEM-level privileges by exploiting overly permissive filesystem ACLs on the C:\Windows\Automation directory. Attackers can modify existing automation content or place attacke…

📅 Published: April 15, 2026, 8:45 p.m. 🔄 Last Modified: April 17, 2026, 3:38 p.m.

9.4

CVSS3.1

CVE-2026-40173 - Dgraph: Unauthenticated pprof endpoint leaks admin auth token

Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential disclosure vulnerability where the /debug/pprof/cmdline endpoint is registered on the default mux and reachable without authentication, exposing the full process command line inclu…

📅 Published: April 15, 2026, 8:40 p.m. 🔄 Last Modified: April 25, 2026, 6:27 p.m.

6.1

CVSS3.1

CVE-2026-40186 - ApostropheCMS: sanitize-html allowedTags Bypass via Entity-Decoded Text in nonTextTags Elements

ApostropheCMS is an open-source Node.js content management system. A regression introduced in commit 49d0bb7, included in versions 2.17.1 of the ApostropheCMS-maintained sanitize-html package bypasses allowedTags enforcement for text inside nonTextTagsArray elements (textarea and option). Apostroph…

📅 Published: April 15, 2026, 8:15 p.m. 🔄 Last Modified: April 25, 2026, 6:15 p.m.
Total resulsts: 349182
Page 434 of 34,919
« previous page » next page
Filters