9.8

CVSS3.1

CVE-2026-0740 - Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload

The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Controllers_Uploads::handle_upload' function in all versions up to, and including, 3.3.26. This makes it possible for unauthenticated attackers to uploaโ€ฆ

๐Ÿ“… Published: April 7, 2026, 4:25 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 7:50 p.m.

4.3

CVSS3.1

CVE-2026-20446 - Integer Overflow in Secure Boot Leading to Local Denial of Service

In sec boot, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service, if an attacker has physical access to the device, with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09963054; Issue ID: MSโ€ฆ

๐Ÿ“… Published: April 7, 2026, 3:25 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 7:50 p.m.

8.8

CVSS3.1

CVE-2026-20433 -

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. โ€ฆ

๐Ÿ“… Published: April 7, 2026, 3:25 a.m. ๐Ÿ”„ Last Modified: April 13, 2026, 2:27 p.m.

8

CVSS3.1

CVE-2026-20432 -

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. โ€ฆ

๐Ÿ“… Published: April 7, 2026, 3:25 a.m. ๐Ÿ”„ Last Modified: April 13, 2026, 2:27 p.m.

6.5

CVSS3.1

CVE-2026-20431 -

In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY0110โ€ฆ

๐Ÿ“… Published: April 7, 2026, 3:25 a.m. ๐Ÿ”„ Last Modified: April 13, 2026, 2:27 p.m.

5.3

CVSS4.0

CVE-2026-5719 - itsourcecode Construction Management System borrowedtool.php sql injection

A flaw has been found in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /borrowedtool.php. Executing a manipulation of the argument code can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be โ€ฆ

๐Ÿ“… Published: April 7, 2026, 2 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 7:50 p.m.

6.2

CVSS3.1

CVE-2025-13044 - Multiple Vulnerabilities in IBM Concert Software

IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.

๐Ÿ“… Published: April 7, 2026, 1:07 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 7:50 p.m.

6.5

CVSS3.1

CVE-2026-5876 - chromium-browser: Side-channel information leakage in Navigation

Side-channel information leakage in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

๐Ÿ“… Published: April 7, 2026, midnight ๐Ÿ”„ Last Modified: April 13, 2026, 5:40 p.m.

8.8

CVSS3.1

CVE-2026-5865 - chromium-browser: Type Confusion in V8

Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

๐Ÿ“… Published: April 7, 2026, midnight ๐Ÿ”„ Last Modified: April 13, 2026, 5:21 p.m.

6.6

CVSS3.1

CVE-2026-5892 - chromium-browser: Insufficient policy enforcement in PWAs

Insufficient policy enforcement in PWAs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to install a PWA without user consent via a crafted HTML page. (Chromium security severity: Medium)

๐Ÿ“… Published: April 7, 2026, midnight ๐Ÿ”„ Last Modified: April 14, 2026, 5:06 p.m.
Total resulsts: 349182
Page 643 of 34,919
ยซ previous page ยป next page
Filters