9.3

CVSS4.0

CVE-2025-39666 - omd: Local privilege escalation when executing omd commands as root

Local privilege escalation in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Checkmk 2.5.0 (beta) before 2.5.0b3 allows a site user to escalate their privileges to root, by manipulating files in the site context that are processed when the `omd` administrativ…

📅 Published: April 7, 2026, 12:09 p.m. 🔄 Last Modified: April 14, 2026, 4:41 p.m.

8.5

CVSS4.0

CVE-2026-3466 - Cross-site scripting in dashlet title

Insufficient sanitization of dashboard dashlet title links in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Checkmk 2.5.0 (beta) before 2.5.0 allows an attacker with dashboard creation privileges to perform stored cross-site scripting (XSS) attacks by tricki…

📅 Published: April 7, 2026, 12:08 p.m. 🔄 Last Modified: April 22, 2026, 3:30 p.m.

8.7

CVSS4.0

CVE-2026-31842 - Tinyproxy HTTP request parsing desynchronization via case-sensitive Transfer-Encoding handling

Tinyproxy through 1.11.3 is vulnerable to HTTP request parsing desynchronization due to a case-sensitive comparison of the Transfer-Encoding header in src/reqs.c. The is_chunked_transfer() function uses strcmp() to compare the header value against "chunked", even though RFC 7230 specifies that tran…

📅 Published: April 7, 2026, 11:17 a.m. 🔄 Last Modified: April 29, 2026, 6:51 p.m.

5.1

CVSS4.0

CVE-2026-4420 - Stored XSS via Page Creating functionality in Bludit

Bludit is vulnerable to Stored Cross-Site Scripting (XSS) in its page creating functionality. An authenticated attacker with page creation privileges (such as Author, Editor, or Administrator) can embed a malicious JavaScript payload in the tags field of a newly created article. This payload will b…

📅 Published: April 7, 2026, 10:46 a.m. 🔄 Last Modified: April 20, 2026, 4:51 p.m.

5.4

CVSS3.1

CVE-2026-34903 - WordPress Ocean Extra plugin <= 2.5.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in OceanWP Ocean Extra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ocean Extra: from n/a through 2.5.3.

📅 Published: April 7, 2026, 8:57 a.m. 🔄 Last Modified: April 24, 2026, 6:08 p.m.

5.3

CVSS3.1

CVE-2026-34899 - WordPress LTL Freight Quotes – Worldwide Express Edition plugin <= 5.2.1 - Broken Access Control vu…

Missing Authorization vulnerability in Eniture technology LTL Freight Quotes – Worldwide Express Edition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LTL Freight Quotes – Worldwide Express Edition: from n/a through 5.2.1.

📅 Published: April 7, 2026, 8:31 a.m. 🔄 Last Modified: April 24, 2026, 6:08 p.m.

7.5

CVSS3.1

CVE-2026-34904 - WordPress Simple Social Media Share Buttons plugin <= 6.2.0 - Cross Site Request Forgery (CSRF) vul…

Cross-Site Request Forgery (CSRF) vulnerability in Analytify Simple Social Media Share Buttons allows Cross Site Request Forgery.This issue affects Simple Social Media Share Buttons: from n/a through 6.2.0.

📅 Published: April 7, 2026, 8:22 a.m. 🔄 Last Modified: April 24, 2026, 6:08 p.m.

7.5

CVSS3.1

CVE-2026-34896 - WordPress Under Construction, Coming Soon & Maintenance Mode plugin <= 2.1.1 - Cross Site Request F…

Cross-Site Request Forgery (CSRF) vulnerability in Analytify Under Construction, Coming Soon & Maintenance Mode allows Cross Site Request Forgery.This issue affects Under Construction, Coming Soon & Maintenance Mode: from n/a through 2.1.1.

📅 Published: April 7, 2026, 8:20 a.m. 🔄 Last Modified: April 24, 2026, 6:08 p.m.

4.3

CVSS3.1

CVE-2026-33227 - Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache Ac…

Improper validation and restriction of a classpath path name vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ. In two instances (when creating a Stomp consumer and also browsing messages in the Web console) an authentic…

📅 Published: April 7, 2026, 7:50 a.m. 🔄 Last Modified: April 20, 2026, 4:50 p.m.

6.3

CVSS4.0

CVE-2026-28810 - Predictable DNS Transaction IDs Enable Cache Poisoning in Built-in Resolver

Generation of Predictable Numbers or Identifiers vulnerability in Erlang/OTP kernel (inet_res, inet_db modules) allows DNS Cache Poisoning. The built-in DNS resolver (inet_res) uses a sequential, process-global 16-bit transaction ID for UDP queries and does not implement source port randomization.…

📅 Published: April 7, 2026, 7:50 a.m. 🔄 Last Modified: April 23, 2026, 3:18 p.m.
Total resulsts: 349182
Page 641 of 34,919
« previous page » next page
Filters