8.8

CVSS3.1

CVE-2026-34197 - Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE…

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations …

📅 Published: April 7, 2026, 7:50 a.m. 🔄 Last Modified: April 21, 2026, 11:30 p.m.

5.3

CVSS3.1

CVE-2026-3177 - Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More <= 1.8.9.7…

The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to, and including, 1.8.9.7. This is due to missing cryptographic verification of incoming Stripe webhook e…

📅 Published: April 7, 2026, 7:40 a.m. 🔄 Last Modified: April 8, 2026, 7:49 p.m.

8.8

CVSS3.1

CVE-2026-5465 - Amelia <= 2.1.3 - Insecure Direct Object Reference to Authenticated (Employee+) Privilege Escalatio…

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.3. This is due to the `UpdateProviderCommandHandler` failing to validate changes to the `externalId` field when a Provider (Empl…

📅 Published: April 7, 2026, 6:43 a.m. 🔄 Last Modified: April 9, 2026, 8:24 a.m.

9.8

CVSS3.0

CVE-2026-1114 - Improper Access Control via Weak JWT Token in parisneo/lollms

In parisneo/lollms version 2.1.0, the application's session management is vulnerable to improper access control due to the use of a weak secret key for signing JSON Web Tokens (JWT). This vulnerability allows an attacker to perform an offline brute-force attack to recover the secret key. Once the s…

📅 Published: April 7, 2026, 6:19 a.m. 🔄 Last Modified: April 28, 2026, midnight

6.5

CVSS3.1

CVE-2026-4079 - SQL Chart Builder < 2.3.8 - Unauthenticated SQL Injection

The SQL Chart Builder WordPress plugin before 2.3.8 does not properly escape user input as it is concatened to SQL queries, making it possible for attackers to conduct SQL Injection attacks against the dynamic filter functionality.

📅 Published: April 7, 2026, 6 a.m. 🔄 Last Modified: April 10, 2026, 9:41 a.m.

6.5

CVSS3.1

CVE-2026-1900 - Link Whisper Free < 0.9.1 - Unauthenticated Settings and User Meta Update

The Link Whisper Free WordPress plugin before 0.9.1 has a publicly accessible REST endpoint that allows unauthenticated settings updates.

📅 Published: April 7, 2026, 6 a.m. 🔄 Last Modified: April 15, 2026, 4:30 p.m.

5.4

CVSS3.1

CVE-2025-15611 - Popup Box AYS Pro < 5.5.0 - Admin+ Stored Cross-Site Scripting (XSS) via CSRF

The Popup Box WordPress plugin before 5.5.0 does not properly validate nonces in the add_or_edit_popupbox() function before saving popup data, allowing unauthenticated attackers to perform Cross-Site Request Forgery attacks. When an authenticated admin visits a malicious page, the attacker can cre…

📅 Published: April 7, 2026, 6 a.m. 🔄 Last Modified: April 10, 2026, 9:41 a.m.

5.5

CVSS3.1

CVE-2025-65116 - Buffer Overflow Vulnerability in JP1/IT Desktop Management 2 and JP1/NETM/DM

Buffer Overflow Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows, Job Management Partner 1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management - Manager on Windows, Job Management Partner 1/IT Desktop…

📅 Published: April 7, 2026, 5:43 a.m. 🔄 Last Modified: April 28, 2026, 4:50 p.m.

7.8

CVSS3.1

CVE-2026-1839 - Arbitrary Code Execution via Unsafe torch.load() in Trainer Checkpoint Loading in huggingface/trans…

A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_state()` method in `src/transformers/trainer.py` at line 3059 calls `torch.load()` without the `weights_only=True` parameter. This issue affects all vers…

📅 Published: April 7, 2026, 5:22 a.m. 🔄 Last Modified: April 28, 2026, 4:39 p.m.

8.8

CVSS3.1

CVE-2025-65115 - Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 and JP1/NETM/DM

Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows, Job Management Partner 1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management - Manager on Windows, Job Management Partner 1/IT D…

📅 Published: April 7, 2026, 5:19 a.m. 🔄 Last Modified: April 28, 2026, 5 p.m.
Total resulsts: 349182
Page 642 of 34,919
« previous page » next page
Filters