|
1301
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ive' shortcode in all versions up to, and including, 1.2.5.7 due to insuffic…
|
CWE-80
Basic XSS
|
CVE-2026-1834
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1302
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin Ibtana – WordPress Website Builder para WordPress es vulnerable a cross-site scripting almacenado a través del shortcode 'ive' del plugin en todas las versiones hasta la 1.2.5.7, inclusive,…
|
CWE-80
Basic XSS
|
CVE-2026-1834
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1303
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Auto Post Scheduler plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.84. This is due to missing nonce validation on the 'aps_options_page' …
|
CWE-79
Cross-site Scripting
|
CVE-2026-1877
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1304
|
6.1 |
MEDIUM
Network
|
-
|
-
|
El plugin Auto Post Scheduler para WordPress es vulnerable a la falsificación de petición en sitios cruzados en todas las versiones hasta e incluyendo la 1.84. Esto se debe a la falta de validación d…
|
CWE-79
Cross-site Scripting
|
CVE-2026-1877
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1305
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was found in SourceCodester Teacher Record System 1.0. Impacted is an unknown function of the file Teacher Record System of the component Parameter Handler. Performing a manipulation …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5182
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1306
|
7.3 |
HIGH
Network
|
-
|
-
|
Se encontró una vulnerabilidad en SourceCodester Teacher Record System 1.0. Afecta a una función desconocida del archivo Teacher Record System del componente Gestor de Parámetros. Realizar una manipu…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5182
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1307
|
5.3 |
MEDIUM
Local
|
-
|
-
|
A security flaw has been discovered in Nothings stb_image up to 2.30. This affects the function stbi__gif_load_next of the file stb_image.h of the component Multi-frame GIF File Handler. The manipula…
|
CWE-119 CWE-122
Incorrect Access of Indexable Resource ('Range Error') Heap-based Buffer Overflow
|
CVE-2026-5185
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1308
|
5.3 |
MEDIUM
Local
|
-
|
-
|
Una falla de seguridad ha sido descubierta en stb_image de Nothings hasta 2.30. Esto afecta a la función stbi__gif_load_next del archivo stb_image.h del componente Gestor de Archivos GIF de Múltiples…
|
CWE-119 CWE-122
Incorrect Access of Indexable Resource ('Range Error') Heap-based Buffer Overflow
|
CVE-2026-5185
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1309
|
5.3 |
MEDIUM
Local
|
-
|
-
|
A weakness has been identified in Nothings stb up to 2.30. This impacts the function stbi__load_gif_main of the file stb_image.h of the component Multi-frame GIF File Handler. This manipulation cause…
|
CWE-119 CWE-415
Incorrect Access of Indexable Resource ('Range Error') Double Free
|
CVE-2026-5186
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1310
|
5.3 |
MEDIUM
Local
|
-
|
-
|
Se ha identificado una debilidad en Nothings stb hasta la versión 2.30. Esto afecta a la función stbi__load_gif_main del archivo stb_image.h del componente Gestor de archivos GIF de múltiples fotogra…
|
CWE-119 CWE-415
Incorrect Access of Indexable Resource ('Range Error') Double Free
|
CVE-2026-5186
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1311
|
7.3 |
HIGH
Network
|
-
|
-
|
A flaw has been found in code-projects Student Membership System 1.0. This issue affects some unknown processing of the component User Registration Handler. Executing a manipulation can lead to sql i…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5195
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1312
|
7.3 |
HIGH
Network
|
-
|
-
|
Se ha encontrado una vulnerabilidad en el Sistema de Membresía Estudiantil 1.0 de code-projects. Este problema afecta a algún procesamiento desconocido del componente Gestor de Registro de Usuario. L…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5195
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1313
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in code-projects Student Membership System 1.0. Impacted is an unknown function of the file /delete_member.php. The manipulation of the argument ID leads to sql injecti…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5196
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1314
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Se ha encontrado una vulnerabilidad en code-projects Student Membership System 1.0. Afectada es una función desconocida del archivo /delete_member.php. La manipulación del argumento ID conduce a inye…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5196
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1315
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in code-projects Student Membership System 1.0. The affected element is an unknown function of the file /delete_user.php. The manipulation of the argument ID results in sql …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5197
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1316
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad fue encontrada en code-projects Student Membership System 1.0. El elemento afectado es una función desconocida del archivo /delete_user.php. La manipulación del argumento ID result…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5197
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1317
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including,…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-3139
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1318
|
5.4 |
MEDIUM
Network
|
-
|
-
|
The Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.12. This is due to missing or incorrect nonce validation on the 'minify_html…
|
CWE-352
Origin Validation Error
|
CVE-2026-3191
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1319
|
7.2 |
HIGH
Network
|
-
|
-
|
The Query Monitor – The developer tools panel for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘$_SERVER['REQUEST_URI']’ parameter in all versions up to, and…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4267
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1320
|
7.5 |
HIGH
Network
|
apache
|
log4j
|
Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vulnerable to log injection via CRLF sequences due to…
|
CWE-117 CWE-684
Improper Output Neutralization for Logs Incorrect Provision of Specified Functionality
|
CVE-2026-34478
|
2026-04-25 03:10 |
2026-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1321
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
can: usb: f81604: correctly anchor the urb in the read bulk callback
When submitting an urb, that is using the anchor pattern, it…
|
NVD-CWE-noinfo
|
CVE-2026-23347
|
2026-04-25 03:10 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1322
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
can: usb: f81604: anclar correctamente el urb en la devolución de llamada de lectura masiva
Al enviar un urb, que está usando el…
|
NVD-CWE-noinfo
|
CVE-2026-23347
|
2026-04-25 03:10 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1323
|
4.7 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
cxl: Fix race of nvdimm_bus object when creating nvdimm objects
Found issue during running of cxl-translate.sh unit test. Adding …
|
CWE-362
Race Condition
|
CVE-2026-23348
|
2026-04-25 03:08 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1324
|
4.7 |
MEDIUM
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
cxl: Corrige la condición de carrera del objeto nvdimm_bus al crear objetos nvdimm
Se encontró el problema durante la ejecución …
|
CWE-362
Race Condition
|
CVE-2026-23348
|
2026-04-25 03:08 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1325
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Kubio AI Page Builder allows Stored XSS.This issue affects Kubio AI Page Builder: f…
|
CWE-79
Cross-site Scripting
|
CVE-2026-34887
|
2026-04-25 03:08 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1326
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en Extend Themes Kubio AI Page Builder permite XSS Almacenado. Este problema afect…
|
CWE-79
Cross-site Scripting
|
CVE-2026-34887
|
2026-04-25 03:08 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1327
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Ultimate Addons for WPBakery Page Builder allows DOM-Based XSS.This issue affect…
|
CWE-79
Cross-site Scripting
|
CVE-2026-34889
|
2026-04-25 03:08 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1328
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark O’Donnell MSTW League Manager allows DOM-Based XSS.This issue affects MSTW League Manager: f…
|
CWE-79
Cross-site Scripting
|
CVE-2026-34890
|
2026-04-25 03:08 |
2026-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1329
|
8.5 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows SQL Injection.This issue affects Media LIbrary Assis…
|
CWE-89
SQL Injection
|
CVE-2026-34885
|
2026-04-25 03:08 |
2026-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1330
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant allows Stored XSS.This issue affects Media LIbrary Assistan…
|
CWE-79
Cross-site Scripting
|
CVE-2026-34897
|
2026-04-25 03:08 |
2026-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1331
|
7.5 |
HIGH
Network
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in Analytify Under Construction, Coming Soon & Maintenance Mode allows Cross Site Request Forgery.This issue affects Under Construction, Coming Soon & …
|
CWE-352
Origin Validation Error
|
CVE-2026-34896
|
2026-04-25 03:08 |
2026-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1332
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Eniture technology LTL Freight Quotes – Worldwide Express Edition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LTL…
|
CWE-862
Missing Authorization
|
CVE-2026-34899
|
2026-04-25 03:08 |
2026-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1333
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in OceanWP Ocean Extra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ocean Extra: from n/a through 2.5.3.
|
CWE-862
Missing Authorization
|
CVE-2026-34903
|
2026-04-25 03:08 |
2026-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1334
|
7.5 |
HIGH
Network
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in Analytify Simple Social Media Share Buttons allows Cross Site Request Forgery.This issue affects Simple Social Media Share Buttons: from n/a through…
|
CWE-352
Origin Validation Error
|
CVE-2026-34904
|
2026-04-25 03:08 |
2026-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1335
|
5.5 |
MEDIUM
Network
|
-
|
-
|
Server-Side Request Forgery (SSRF) vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd coming-soon allows Server Side Request Forgery.This issue affects Comi…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-39464
|
2026-04-25 03:08 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1336
|
7.6 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Broken Link Checker broken-link-checker allows Blin…
|
CWE-89
SQL Injection
|
CVE-2026-39466
|
2026-04-25 03:08 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1337
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Softaculous PageLayer pagelayer allows Retrieve Embedded Sensitive Data.This issue affects PageLayer: from …
|
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
|
CVE-2026-39469
|
2026-04-25 03:08 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1338
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Insertion of Sensitive Information Into Sent Data vulnerability in Pär Thernström Simple History simple-history allows Retrieve Embedded Sensitive Data.This issue affects Simple History: from n/a thr…
|
CWE-201
Insertion of Sensitive Information Into Sent Data
|
CVE-2026-39473
|
2026-04-25 03:08 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1339
|
8.5 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Syed Balkhi User Feedback userfeedback-lite allows Blind SQL Injection.This issue affects User Fe…
|
CWE-89
SQL Injection
|
CVE-2026-39475
|
2026-04-25 03:08 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1340
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Syed Balkhi User Feedback userfeedback-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Feedback: from n/a t…
|
CWE-862
Missing Authorization
|
CVE-2026-39476
|
2026-04-25 03:08 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1341
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Brainstorm Force CartFlows cartflows allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CartFlows: from n/a through <= 2…
|
CWE-862
Missing Authorization
|
CVE-2026-39477
|
2026-04-25 03:08 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1342
|
7.6 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force OttoKit suretriggers allows Blind SQL Injection.This issue affects OttoKit: from…
|
CWE-89
SQL Injection
|
CVE-2026-39479
|
2026-04-25 03:08 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1343
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress Post Expirator post-expirator allows DOM-Based XSS.This issue affects Post Expirator…
|
CWE-79
Cross-site Scripting
|
CVE-2026-39482
|
2026-04-25 03:08 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1344
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hidekazu Ishikawa VK All in One Expansion Unit vk-all-in-one-expansion-unit allows Stored XSS.Thi…
|
CWE-79
Cross-site Scripting
|
CVE-2026-39483
|
2026-04-25 03:08 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1345
|
4.7 |
MEDIUM
Network
|
-
|
-
|
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in John Darrel Hide My WP Ghost hide-my-wp allows Phishing.This issue affects Hide My WP Ghost: from n/a through < 7.0.00.
|
CWE-601
Open Redirect
|
CVE-2026-39484
|
2026-04-25 03:08 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1346
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in embedplus Youtube Embed Plus youtube-embed-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Youtube Embed Plus: f…
|
CWE-862
Missing Authorization
|
CVE-2026-39485
|
2026-04-25 03:08 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1347
|
7.6 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Chill Download Monitor download-monitor allows Blind SQL Injection.This issue affects Download…
|
CWE-89
SQL Injection
|
CVE-2026-39486
|
2026-04-25 03:08 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1348
|
7.6 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ameliabooking Amelia ameliabooking allows Blind SQL Injection.This issue affects Amelia: from n/a…
|
CWE-89
SQL Injection
|
CVE-2026-39487
|
2026-04-25 03:08 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1349
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in SureCart SureCart surecart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SureCart: from n/a through <= 4.0.2.
|
CWE-862
Missing Authorization
|
CVE-2026-39488
|
2026-04-25 03:08 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1350
|
8.5 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Blind SQL Injection.Thi…
|
CWE-89
SQL Injection
|
CVE-2026-39495
|
2026-04-25 03:08 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|