CVE Feed

    Dashboard / CVE

    8.2
    High

    CVE-2026-4828

    Last Modified: 7 Apr 2026

    Improper authentication in the OAuth login functionality in Devolutions Server 2026.1.11 and earlier allows a remote attacker with valid credentials to bypass multi-factor authentication via a crafted login request.

    Published: 1 Apr 2026
    5.4
    Medium

    CVE-2026-4829

    Last Modified: 7 Apr 2026

    Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an authenticated user to authenticate as other users, including administrators, via reuse of a session code from an external authentication flow.

    Published: 1 Apr 2026
    6.4
    Medium

    CVE-2025-13535

    Last Modified: 24 Apr 2026

    The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Scripting vulnerabilities in all versions up to, and including, 51.1.38. This is due to insufficient input sanitization and output escaping across multiple widgets and features. The plugin uses esc_attr() and esc_url() within JavaScript inline event handlers (onclick attributes), which allows HTML entities to be decoded by the DOM, enabling attackers to break out of the JavaScript context. Additionally, several JavaScript files use unsafe DOM manipulation methods (template literals, .html(), and window.location.href with unvalidated URLs) with user-controlled data. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts via Elementor widget settings that execute when a user accesses the injected page or when an administrator previews the page in Elementor's editor. The vulnerability was partially patched in version 5.1.51.

    Published: 1 Apr 2026
    5.6
    Medium

    CVE-2026-5271

    Last Modified: 8 Apr 2026

    pymanager included the current working directory in sys.path meaning modules could be shadowed by modules in the current working directory. As a result, if a user executes a pymanager-generated command (e.g., pip, pytest) from an attacker-controlled directory, a malicious module in that directory can be imported and executed instead of the intended package.

    Published: 1 Apr 2026
    8.6
    High

    CVE-2026-34430

    Last Modified: 14 Aug 2026

    ByteDance DeerFlow versions prior to commit 92c7a20 contain a sandbox escape vulnerability in bash tool handling that allows attackers to execute arbitrary commands on the host system by bypassing regex-based validation using shell features such as directory changes and relative paths. Attackers can exploit the incomplete shell semantics modeling to read and modify files outside the sandbox boundary and achieve arbitrary command execution through subprocess invocation with shell interpretation enabled.

    Published: 1 Apr 2026
    6.9
    Medium

    CVE-2026-34999

    Last Modified: 8 Apr 2026

    OpenViking versions 0.2.5 prior to 0.2.14 contain a missing authentication vulnerability in the bot proxy router that allows remote unauthenticated attackers to access protected bot proxy functionality by sending requests to the POST /bot/v1/chat and POST /bot/v1/chat/stream endpoints. Attackers can bypass authentication checks and interact directly with the upstream bot backend through the OpenViking proxy without providing valid credentials.

    Published: 1 Apr 2026
    7.3
    High

    CVE-2026-3877

    Last Modified: 3 Apr 2026

    A reflected cross-site scripting (XSS) vulnerability in the dashboard search functionality of the VertiGIS FM solution allows attackers to craft a malicious URL, that if visited by an authenticated victim, will execute arbitrary JavaScript in the victim's context. Such a URL could be delivered through various means, for instance, by sending a link or by tricking victims to visit a page crafted by the attacker.

    Published: 1 Apr 2026
    7.4
    High

    CVE-2026-0522

    Last Modified: 8 Apr 2026

    A local file inclusion vulnerability in the upload/download flow of the VertiGIS FM application allows authenticated attackers to read arbitrary files from the server by manipulating a file's path during its upload. When the file is subsequently downloaded, the file in the attacker controlled path is returned. Due to the application's ASP.NET architecture, this could potentially lead to remote code execution when the "web.config" file is obtained. Furthermore, the application resolves UNC paths which may enable NTLM-relaying attacks. This issue affects VertiGIS FM: 10.5.00119 (0d29d428).

    Published: 1 Apr 2026
    9.3
    Critical

    CVE-2026-29014

    Last Modified: 14 Jul 2026

    MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code. Attackers can exploit insufficient input neutralization in the execution path to achieve remote code execution and gain full control over the affected server.

    Published: 1 Apr 2026
    7.3
    High

    CVE-2026-22768

    Last Modified: 3 Apr 2026

    Dell AppSync, version(s) 4.6.0, contain(s) an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

    Published: 1 Apr 2026
    7.3
    High

    CVE-2026-22767

    Last Modified: 3 Apr 2026

    Dell AppSync, version(s) 4.6.0, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.

    Published: 1 Apr 2026
    7.5
    High

    CVE-2026-35092

    Last Modified: 26 May 2026

    A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause the service to crash, leading to a denial of service. This vulnerability specifically affects Corosync deployments configured to use totemudp/totemudpu mode.

    Published: 1 Apr 2026
    8.2
    High

    CVE-2026-35091

    Last Modified: 26 May 2026

    A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol (UDP) packet. This can lead to an out-of-bounds read, causing a denial of service (DoS) and potentially disclosing limited memory contents

    Published: 1 Apr 2026
    6.4
    Medium

    CVE-2026-25601

    Last Modified: 8 Apr 2026

    A vulnerability was identified in MEPIS RM, an industrial software product developed by Metronik. The application contained a hardcoded cryptographic key within the Mx.Web.ComponentModel.dll component. When the option to store domain passwords was enabled, this key was used to encrypt user passwords before storing them in the application’s database. An attacker with sufficient privileges to access the database could extract the encrypted passwords, decrypt them using the embedded key, and gain unauthorized access to the associated ICS/OT environment.

    Published: 1 Apr 2026
    Unknown

    CVE-2026-5307

    Last Modified: 14 Apr 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 1 Apr 2026
    5.3
    Medium

    CVE-2026-24096

    Last Modified: 8 Apr 2026

    Insufficient permission validation on multiple REST API Quick Setup endpoints in Checkmk 2.5.0 (beta) before version 2.5.0b2 and 2.4.0 before version 2.4.0p25 allows low-privileged users to perform unauthorized actions or obtain sensitive information

    Published: 1 Apr 2026
    6.9
    Medium

    CVE-2026-0932

    Last Modified: 3 Apr 2026

    Blind server-side request forgery (SSRF) vulnerability in legacy connection methods of document co-authoring features in M-Files Server before 26.3 allow an unauthenticated attacker to cause the server to send HTTP GET requests to arbitrary URLs.

    Published: 1 Apr 2026
    2.1
    Low

    CVE-2026-1879

    Last Modified: 24 Apr 2026

    A vulnerability was detected in Harvard University IQSS Dataverse up to 6.8. This affects an unknown function of the file /ThemeAndWidgets.xhtml of the component Theme Customization. Performing a manipulation of the argument uploadLogo results in unrestricted upload. Remote exploitation of the attack is possible. The exploit is now public and may be used. Upgrading to version 6.10 mitigates this issue. You should upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

    Published: 1 Apr 2026
    5.3
    Medium

    CVE-2024-53828

    Last Modified: 13 Apr 2026

    Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a vulnerability where an attacker sending a large volume of specially crafted messages may cause service degradation.

    Published: 1 Apr 2026
    6.9
    Medium

    CVE-2026-21630

    Last Modified: 10 Apr 2026

    Improperly built order clauses lead to a SQL injection vulnerability in the articles webservice endpoint.

    Published: 1 Apr 2026
    8.6
    High

    CVE-2026-23898

    Last Modified: 10 Apr 2026

    Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism.

    Published: 1 Apr 2026
    6.3
    Medium

    CVE-2026-21629

    Last Modified: 10 Apr 2026

    The ajax component was excluded from the default logged-in-user check in the administrative area. This behavior was potentially unexpected by 3rd party developers.

    Published: 1 Apr 2026
    8.6
    High

    CVE-2026-23899

    Last Modified: 10 Apr 2026

    An improper access check allows unauthorized access to webservice endpoints.

    Published: 1 Apr 2026
    5.9
    Medium

    CVE-2026-21631

    Last Modified: 10 Apr 2026

    Lack of output escaping leads to a XSS vector in the multilingual associations component.

    Published: 1 Apr 2026
    5.9
    Medium

    CVE-2026-21632

    Last Modified: 10 Apr 2026

    Lack of output escaping for article titles leads to XSS vectors in various locations.

    Published: 1 Apr 2026
    6.5
    Medium

    CVE-2026-34889

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Ultimate Addons for WPBakery Page Builder allows DOM-Based XSS.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a before 3.21.4.

    Published: 1 Apr 2026
    5.5
    Medium

    CVE-2026-5261

    Last Modified: 24 Apr 2026

    A vulnerability was identified in Shandong Hoteam InforCenter PLM up to 8.3.8. The impacted element is the function uploadFileToIIS of the file /Base/BaseHandler.ashx. The manipulation of the argument File leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 1 Apr 2026
    10
    Critical

    CVE-2026-4370

    Last Modified: 8 Apr 2026

    A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the internal Dqlite database cluster fails to perform proper TLS client and server authentication. Specifically, the Juju controller's database endpoint does not validate client certificates when a new node attempts to join the cluster. An unauthenticated attacker with network reachability to the Juju controller's Dqlite port can exploit this flaw to join the database cluster. Once joined, the attacker gains full read and write access to the underlying database, allowing for total data compromise.

    Published: 1 Apr 2026
    4.4
    Medium

    CVE-2026-28265

    Last Modified: 3 Apr 2026

    PowerStore, contains a Path Traversal vulnerability in the Service user. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modification of arbitrary system files.

    Published: 1 Apr 2026
    2.1
    Low

    CVE-2026-5259

    Last Modified: 24 Apr 2026

    A vulnerability was determined in AutohomeCorp frostmourne up to 1.0. The affected element is an unknown function of the file frostmourne-monitor/src/main/java/com/autohome/frostmourne/monitor/controller/AlarmController.java of the component Alarm Preview. Executing a manipulation can lead to server-side request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.

    Published: 1 Apr 2026
    4.7
    Medium

    CVE-2026-27101

    Last Modified: 3 Apr 2026

    Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application version(s) 5.28.00.xx to 5.32.00.xx, contain(s) an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A high privileged attacker within the management network could potentially exploit this vulnerability, leading to remote execution.

    Published: 1 Apr 2026
    5.5
    Medium

    CVE-2026-5258

    Last Modified: 24 Apr 2026

    A vulnerability was found in Sanster IOPaint 1.5.3. Impacted is the function _get_file of the file iopaint/file_manager/file_manager.py of the component File Manager. Performing a manipulation of the argument filename results in path traversal. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 1 Apr 2026
    7.5
    High

    CVE-2026-4748

    Last Modified: 3 Apr 2026

    A regression in the way hashes were calculated caused rules containing the address range syntax (x.x.x.x - y.y.y.y) that only differ in the address range(s) involved to be silently dropped as duplicates. Only the first of such rules is actually loaded into pf. Ranges expressed using the address[/mask-bits] syntax were not affected. Some keywords representing actions taken on a packet-matching rule, such as 'log', 'return tll', or 'dnpipe', may suffer from the same issue. It is unlikely that users have such configurations, as these rules would always be redundant. Affected rules are silently ignored, which can lead to unexpected behaviour including over- and underblocking.

    Published: 1 Apr 2026
    5.5
    Medium

    CVE-2026-5257

    Last Modified: 3 Apr 2026

    A vulnerability has been found in code-projects Simple Laundry System 1.0. This issue affects some unknown processing of the file /delstaffinfo.php of the component Parameter Handler. Such manipulation of the argument userid leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

    Published: 1 Apr 2026
    5.5
    Medium

    CVE-2026-5256

    Last Modified: 3 Apr 2026

    A flaw has been found in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /modify.php of the component Parameter Handler. This manipulation of the argument firstName causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.

    Published: 1 Apr 2026
    5.3
    Medium

    CVE-2026-2696

    Last Modified: 15 Apr 2026

    The Export All URLs WordPress plugin before 5.1 generates CSV filenames containing posts URLS (including private posts) in a predictable pattern using a random 6-digit number. These files are stored in the publicly accessible wp-content/uploads/ directory. As a result, any unauthenticated user can brute-force the filenames to gain access to sensitive data contained within the exported files.

    Published: 1 Apr 2026
    9.1
    Critical

    CVE-2025-15484

    Last Modified: 15 Apr 2026

    The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant full access to all unauthenticated requests, enabling complete read/write access to store resources like products, coupons, and customers.

    Published: 1 Apr 2026
    2.1
    Low

    CVE-2026-5255

    Last Modified: 7 Apr 2026

    A vulnerability was detected in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /delstaffinfo.php of the component Parameter Handler. The manipulation of the argument userid results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used.

    Published: 1 Apr 2026
    8.8
    High

    CVE-2026-5292

    Last Modified: 2 Apr 2026

    Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)

    Published: 1 Apr 2026
    9.6
    Critical

    CVE-2026-5290

    Last Modified: 2 Apr 2026

    Use after free in Compositing in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Apr 2026
    9.6
    Critical

    CVE-2026-5289

    Last Modified: 2 Apr 2026

    Use after free in Navigation in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Apr 2026
    9.6
    Critical

    CVE-2026-5288

    Last Modified: 2 Apr 2026

    Use after free in WebView in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Apr 2026
    2
    Low

    CVE-2026-5254

    Last Modified: 24 Apr 2026

    A security vulnerability has been detected in welovemedia FFmate up to 2.0.15. Affected by this issue is some unknown functionality of the file /ui/app/components/AppJsonTreeView.vue of the component Webhook Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 1 Apr 2026
    2
    Low

    CVE-2026-5253

    Last Modified: 24 Apr 2026

    A weakness has been identified in bufanyun HotGo 1.0/2.0. Affected by this vulnerability is an unknown functionality of the file /web/src/layout/components/Header/MessageList.vue of the component editNotice Endpoint. Executing a manipulation can lead to cross site scripting. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 1 Apr 2026
    2
    Low

    CVE-2026-5252

    Last Modified: 24 Apr 2026

    A security flaw has been discovered in z-9527 admin 1.0/2.0. Affected is an unknown function of the file /server/routes/message.js of the component Message Create Endpoint. Performing a manipulation results in cross site scripting. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 1 Apr 2026
    2.1
    Low

    CVE-2026-5251

    Last Modified: 24 Apr 2026

    A vulnerability was identified in z-9527 admin 1.0/2.0. This impacts an unknown function of the file /server/routes/user.js of the component User Update Endpoint. Such manipulation of the argument isAdmin with the input 1 leads to dynamically-determined object attributes. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 1 Apr 2026
    4.7
    Medium

    CVE-2026-3774

    Last Modified: 10 Apr 2026

    The application allows PDF JavaScript and document/print actions (such as WillPrint/DidPrint) to update form fields, annotations, or optional content groups (OCGs) immediately before or after redaction, encryption, or printing. These script‑driven updates are not fully covered by the existing redaction, encryption, and printing logic, which, under specific document structures and user workflows, may cause a small amount of sensitive content to remain unremoved or unencrypted as expected, or result in printed output that slightly differs from what was reviewed on screen.

    Published: 1 Apr 2026
    7.8
    High

    CVE-2026-3775

    Last Modified: 15 Apr 2026

    The application's update service, when checking for updates, loads certain system libraries from a search path that includes directories writable by low‑privileged users and is not strictly restricted to trusted system locations. Because these libraries may be resolved and loaded from user‑writable locations, a local attacker can place a malicious library there and have it loaded with SYSTEM privileges, resulting in local privilege escalation and arbitrary code execution.

    Published: 1 Apr 2026
    5.5
    Medium

    CVE-2026-3776

    Last Modified: 15 Apr 2026

    The application does not validate the presence of required appearance (AP) data before accessing stamp annotation resources. When a PDF contains a stamp annotation missing its AP entry, the code continues to dereference the associated object without a prior null or validity check, which allows a crafted document to trigger a null pointer dereference and crash the application, resulting in denial of service.

    Published: 1 Apr 2026
    7.3
    High

    CVE-2026-3780

    Last Modified: 28 Apr 2026

    The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted search paths that can include user-writable directories, allowing a local attacker to place malicious binaries with the same names and have them loaded or executed instead of the legitimate system files, resulting in local privilege escalation.

    Published: 1 Apr 2026