8.8

CVSS3.1

CVE-2026-4674 - chromium-browser: Out of bounds read in CSS

Out of bounds read in CSS in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: March 23, 2026, midnight πŸ”„ Last Modified: March 25, 2026, 8:40 p.m.

8.8

CVSS3.1

CVE-2026-4677 - chromium-browser: Out of bounds read in WebAudio

Inappropriate implementation in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: March 23, 2026, midnight πŸ”„ Last Modified: March 25, 2026, 8:40 p.m.

5.1

CVSS4.0

CVE-2026-4564 - yangzongzhuan RuoYi Quartz Job job code injection

A security vulnerability has been detected in yangzongzhuan RuoYi up to 4.8.2. This issue affects some unknown processing of the file /monitor/job/ of the component Quartz Job Handler. Such manipulation of the argument invokeTarget leads to code injection. It is possible to launch the attack remote…

πŸ“… Published: March 22, 2026, 11:51 p.m. πŸ”„ Last Modified: April 24, 2026, 4:32 p.m.

5.3

CVSS4.0

CVE-2026-4563 - MacCMS Member Order Detail User.php order_info authorization

A weakness has been identified in MacCMS up to 2025.1000.4052. This vulnerability affects the function order_info of the file application/index/controller/User.php of the component Member Order Detail Interface. This manipulation of the argument order_id causes authorization bypass. It is possible …

πŸ“… Published: March 22, 2026, 11:51 p.m. πŸ”„ Last Modified: April 24, 2026, 4:32 p.m.

7.5

CVSS3.1

CVE-2026-2580 - WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.9.1 - Una…

The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to time-based SQL Injection via the β€˜orderby’ parameter in all versions up to, and including, 4.9.1 due to insufficient escaping on the user supplied parameter and lack of suf…

πŸ“… Published: March 22, 2026, 11:24 p.m. πŸ”„ Last Modified: April 24, 2026, 4:32 p.m.

6.9

CVSS4.0

CVE-2026-4562 - MacCMS Timming API Endpoint Timming.php weak authentication

A security flaw has been discovered in MacCMS 2025.1000.4052. This affects an unknown part of the file application/api/controller/Timming.php of the component Timming API Endpoint. The manipulation results in missing authentication. The attack may be performed from remote. The exploit has been rele…

πŸ“… Published: March 22, 2026, 11:09 p.m. πŸ”„ Last Modified: April 24, 2026, 4:32 p.m.

8.7

CVSS4.0

CVE-2026-4558 - Linksys MR9600 SmartConnect.lua smartConnectConfigure os command injection

A flaw has been found in Linksys MR9600 2.0.6.206937. Affected is the function smartConnectConfigure of the file SmartConnect.lua. Executing a manipulation of the argument configApSsid/configApPassphrase/srpLogin/srpPassword can lead to os command injection. The attack may be launched remotely. The…

πŸ“… Published: March 22, 2026, 5:29 p.m. πŸ”„ Last Modified: April 30, 2026, 4:34 p.m.

5.3

CVSS4.0

CVE-2026-4557 - code-projects Exam Form Submission update_s1.php cross site scripting

A vulnerability was detected in code-projects Exam Form Submission 1.0. This impacts an unknown function of the file /admin/update_s1.php. Performing a manipulation of the argument sname results in cross site scripting. The attack may be initiated remotely. The exploit is now public and may be used.

πŸ“… Published: March 22, 2026, 5:29 p.m. πŸ”„ Last Modified: April 24, 2026, 4:32 p.m.

2.1

CVSS4.0

CVE-2026-33296 - AVideo has an Open Redirect via Unvalidated redirectUri in userLogin.php

WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains an open redirect vulnerability in the login flow where a user-supplied redirectUri parameter is reflected directly into a JavaScript `document.location` assignment without JavaScript-safe encoding. After a use…

πŸ“… Published: March 22, 2026, 5:03 p.m. πŸ”„ Last Modified: March 25, 2026, 2:50 p.m.

8.2

CVSS4.0

CVE-2026-33295 - AVideo Vulnerable to Stored XSS via Unescaped Video Title in CDN downloadButtons.php

WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains a stored cross-site scripting vulnerability in the CDN plugin's download buttons component. The `clean_title` field of a video record is interpolated directly into a JavaScript string literal without any escap…

πŸ“… Published: March 22, 2026, 5 p.m. πŸ”„ Last Modified: March 25, 2026, 2:50 p.m.
Total resulsts: 349182
Page 980 of 34,919
Β« previous page Β» next page
Filters