0.0

CVE-2026-6337 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

๐Ÿ“… Published: April 15, 2026, 9:19 a.m. ๐Ÿ”„ Last Modified: April 27, 2026, 2:14 p.m.

8.7

CVSS4.0

CVE-2026-3505 - Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.

Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules). This vulnerability is associated with program files AEADEncDataPacket.Java, BcAEADUtil.Java, JceAEADUtil.Java, OperatorHelper.Jโ€ฆ

๐Ÿ“… Published: April 15, 2026, 9:06 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 3:45 a.m.

6.3

CVSS4.0

CVE-2026-5588 - PKIX draft CompositeVerifier accepts empty signature sequence as valid.

Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of the Bouncy Castle Inc. BCPKIX-FIPS bcpkix on All (pkix modules), Legion of the Bouncy Castle Inc. BCPIX-LTS bcpkix on All (pkix modules). This vulneraโ€ฆ

๐Ÿ“… Published: April 15, 2026, 9:06 a.m. ๐Ÿ”„ Last Modified: May 8, 2026, 5:29 a.m.

8.9

CVSS4.0

CVE-2026-5598 - Non-constant time comparisons risk private key leakage in FrodoKEM.

Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue affects BC-JAVA: from 1.71 before 1.84.

๐Ÿ“… Published: April 15, 2026, 9:05 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 11:14 a.m.

5.5

CVSS4.0

CVE-2026-0636 - LDAP Injection Vulnerability in LDAPStoreHelper.java

Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules). This vulnerability is associated with program files LDAPStoreHelper. This issue affects BC-JAVA: from 1.74 before 1.84.

๐Ÿ“… Published: April 15, 2026, 8:59 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:38 p.m.

9.3

CVSS4.0

CVE-2025-14813 - GOSTCTR implementation unable to process more than 255 blocks correctly

Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules). This vulnerability is associated with program files G3413CTRBlockCipher. GOSTCTR implementation unable to process more than 255 blocks correctly. This issue afโ€ฆ

๐Ÿ“… Published: April 15, 2026, 8:56 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:38 p.m.

2.9

CVSS3.1

CVE-2025-52641 - Internal Filesystem Exploration vulnerability

HCL AION is affected by a vulnerability where certain system behaviours may allow exploration of internal filesystem structures. Exposure of such information may provide insights into the underlying environment, which could potentially aid in further targeted actions or limited information disclosuโ€ฆ

๐Ÿ“… Published: April 15, 2026, 8:47 a.m. ๐Ÿ”„ Last Modified: May 1, 2026, 12:37 p.m.

7.2

CVSS3.1

CVE-2026-3643 - Accessibly <= 3.0.3 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting via Widgโ€ฆ

The Accessibly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in all versions up to, and including, 3.0.3. The plugin registers REST API endpoints at `/otm-ac/v1/update-widget-options` and `/otm-ac/v1/update-app-config` with the `permission_callback` set to `__reโ€ฆ

๐Ÿ“… Published: April 15, 2026, 8:28 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 8:23 p.m.

6.4

CVSS3.1

CVE-2026-4011 - Power Charts <= 0.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcodeโ€ฆ

The Power Charts Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [pc] shortcode in all versions up to, and including, 0.1.0. This is due to insufficient input sanitization and output escaping on the 'id' shortcode attribute. Specifically, in the โ€ฆ

๐Ÿ“… Published: April 15, 2026, 8:28 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 8:23 p.m.

6.4

CVSS3.1

CVE-2026-3998 - WM JqMath <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'style' Shortcode Aโ€ฆ

The WM JqMath plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' shortcode attribute of the [jqmath] shortcode in all versions up to and including 1.3. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. The generaโ€ฆ

๐Ÿ“… Published: April 15, 2026, 8:28 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 8:23 p.m.
Total resulsts: 349182
Page 446 of 34,919
ยซ previous page ยป next page
Filters