|
2901
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Unrestricted Upload of File with Dangerous Type vulnerability in halfdata Green Downloads halfdata-paypal-green-downloads allows Using Malicious Files.This issue affects Green Downloads: from n/a thr…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-32536
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2902
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Vulnerabilidad de carga sin restricciones de archivo con tipo peligroso en halfdata Green Downloads halfdata-paypal-green-downloads permite el uso de archivos maliciosos. Este problema afecta a Green…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-32536
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2903
|
7.5 |
HIGH
Network
|
-
|
-
|
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in nK Visual Portfolio, Photo Gallery & Post Grid visual-portfolio allows PHP Loc…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-32537
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2904
|
7.5 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de control inadecuado del nombre de fichero para la declaración Include/Require en el programa PHP ('Inclusión Remota de Ficheros PHP') en nK Visual Portfolio, Photo Gallery & Post…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-32537
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2905
|
7.5 |
HIGH
Network
|
-
|
-
|
Insertion of Sensitive Information Into Sent Data vulnerability in Noor Alam SMTP Mailer smtp-mailer allows Retrieve Embedded Sensitive Data.This issue affects SMTP Mailer: from n/a through <= 1.1.24.
|
CWE-201
Insertion of Sensitive Information Into Sent Data
|
CVE-2026-32538
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2906
|
7.5 |
HIGH
Network
|
-
|
-
|
Inserción de información sensible en datos enviados vulnerabilidad en Noor Alam SMTP Mailer smtp-mailer permite recuperar datos sensibles incrustados. Este problema afecta a SMTP Mailer: desde n/a ha…
|
CWE-201
Insertion of Sensitive Information Into Sent Data
|
CVE-2026-32538
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2907
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PublishPress PublishPress Revisions revisionary allows Blind SQL Injection.This issue affects Pub…
|
CWE-89
SQL Injection
|
CVE-2026-32539
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2908
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Neutralización Incorrecta de Elementos Especiales utilizados en un Comando SQL ('Inyección SQL') vulnerabilidad en PublishPress PublishPress Revisions revisionary permite Inyección SQL Ciega. Este pr…
|
CWE-89
SQL Injection
|
CVE-2026-32539
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2909
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bookly Bookly bookly-responsive-appointment-booking-tool allows Reflected XSS.This issue affects …
|
CWE-79
Cross-site Scripting
|
CVE-2026-32540
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2910
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en Bookly Bookly bookly-responsive-appointment-booking-tool permite XSS Reflejado.…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32540
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2911
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Premmerce Premmerce Redirect Manager premmerce-redirect-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Premm…
|
CWE-862
Missing Authorization
|
CVE-2026-32541
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2912
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad por ausencia de autorización en Premmerce Premmerce Redirect Manager premmerce-redirect-manager permite la explotación de niveles de seguridad de control de acceso configurados incorre…
|
CWE-862
Missing Authorization
|
CVE-2026-32541
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2913
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeFusion Fusion Builder fusion-builder allows Reflected XSS.This issue affects Fusion Builder:…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32542
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2914
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en ThemeFusion Fusion Builder fusion-builder permite XSS Reflejado. Este problema …
|
CWE-79
Cross-site Scripting
|
CVE-2026-32542
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2915
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OOPSpam Team OOPSpam Anti-Spam oopspam-anti-spam allows Stored XSS.This issue affects OOPSpam Ant…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32544
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2916
|
7.1 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de Neutralización Inadecuada de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') en OOPSpam Team OOPSpam Anti-Spam oopspam-anti-spam permite XSS Almacenado. Est…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32544
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2917
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Taboola Taboola Pixel taboola-pixel allows Reflected XSS.This issue affects Taboola Pixel: from n…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32545
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2918
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en Taboola Taboola Pixel taboola-pixel permite XSS Reflejado. Este problema afecta…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32545
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2919
|
7.5 |
HIGH
Network
|
-
|
-
|
Missing Authorization vulnerability in StellarWP Restrict Content restrict-content allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Restrict Content: from n/…
|
CWE-862
Missing Authorization
|
CVE-2026-32546
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2920
|
7.5 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad por ausencia de autorización en StellarWP Restrict Content restrict-content permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este probl…
|
CWE-862
Missing Authorization
|
CVE-2026-32546
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2921
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in WP Folio Team PPWP password-protect-page allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PPWP: from n/a through <= 1.…
|
CWE-862
Missing Authorization
|
CVE-2026-32562
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2922
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de Autorización Faltante en WP Folio Team PPWP password-protect-page permite Explotar Niveles de Seguridad de Control de Acceso Incorrectamente Configurados. Este problema afecta a PPW…
|
CWE-862
Missing Authorization
|
CVE-2026-32562
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2923
|
6.8 |
MEDIUM
Network
|
-
|
-
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in icopydoc YML for Yandex Market yml-for-yandex-market allows Path Traversal.This issue affects YML for Y…
|
CWE-22
Path Traversal
|
CVE-2026-32567
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2924
|
6.8 |
MEDIUM
Network
|
-
|
-
|
Limitación Incorrecta de un Nombre de Ruta a un Directorio Restringido ('Salto de Ruta') vulnerabilidad en icopydoc YML para Yandex Market yml-for-yandex-market permite Salto de Ruta. Este problema a…
|
CWE-22
Path Traversal
|
CVE-2026-32567
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2925
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Code Injection.This issue affects Nelio AB Testing: from n/a through…
|
CWE-94
Code Injection
|
CVE-2026-32573
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2926
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Control inadecuado de la generación de código ('Inyección de Código') vulnerabilidad en Nelio Software Nelio AB Testing nelio-ab-testing permite la inyección de código. Este problema afecta a Nelio A…
|
CWE-94
Code Injection
|
CVE-2026-32573
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2927
|
8.8 |
HIGH
Network
|
-
|
-
|
The WP Job Portal plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'WPJOBPORTALcustomfields::removeFileCustom' function in all versions up…
|
CWE-22
Path Traversal
|
CVE-2026-4758
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2928
|
8.8 |
HIGH
Network
|
-
|
-
|
El plugin WP Job Portal para WordPress es vulnerable a la eliminación arbitraria de archivos debido a una validación insuficiente de la ruta de archivo en la función 'WPJOBPORTALcustomfields::removeF…
|
CWE-22
Path Traversal
|
CVE-2026-4758
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2929
|
8.8 |
HIGH
Network
|
-
|
-
|
The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6. This is due to the plugin allowing a user to update the user role through the…
|
CWE-862
Missing Authorization
|
CVE-2026-4484
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2930
|
8.8 |
HIGH
Network
|
-
|
-
|
El plugin Masteriyo LMS para WordPress es vulnerable a una escalada de privilegios en todas las versiones hasta la 2.1.6, inclusive. Esto se debe a que el plugin permite a un usuario actualizar el ro…
|
CWE-862
Missing Authorization
|
CVE-2026-4484
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2931
|
7.0 |
HIGH
Local
|
-
|
-
|
A vulnerability was detected in Enter Software Iperius Backup up to 8.7.3. Affected is an unknown function of the file C:\ProgramData\IperiusBackup\Jobs\ of the component Backup Service. Performing a…
|
CWE-377 CWE-378
Insecure Temporary File Creation of Temporary File With Insecure Permissions
|
CVE-2026-4822
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2932
|
7.0 |
HIGH
Local
|
-
|
-
|
Una vulnerabilidad fue detectada en Enter Software Iperius Backup hasta 8.7.3. Afecta a una función desconocida del archivo C:\ProgramData\IperiusBackup\Jobs\ del componente Backup Service. Realizar …
|
CWE-377 CWE-378
Insecure Temporary File Creation of Temporary File With Insecure Permissions
|
CVE-2026-4822
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2933
|
2.5 |
LOW
Local
|
-
|
-
|
A flaw has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this vulnerability is an unknown functionality of the component NTLM2 Handler. Executing a manipulation can lead to inf…
|
CWE-200 CWE-284
Information Exposure Improper Access Control
|
CVE-2026-4823
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2934
|
2.5 |
LOW
Local
|
-
|
-
|
Se ha encontrado una falla en Enter Software Iperius Backup hasta la versión 8.7.3. Afectada por esta vulnerabilidad es una funcionalidad desconocida del componente Gestor NTLM2. La ejecución de una …
|
CWE-200 CWE-284
Information Exposure Improper Access Control
|
CVE-2026-4823
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2935
|
7.0 |
HIGH
Local
|
-
|
-
|
A vulnerability has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this issue is some unknown functionality of the component Backup Job Configuration File Handler. The manipulat…
|
CWE-266 CWE-269
Incorrect Privilege Assignment Improper Privilege Management
|
CVE-2026-4824
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2936
|
3.3 |
LOW
Local
|
-
|
-
|
A weakness has been identified in Orc discount up to 3.0.1.2. This issue affects the function compile of the file markdown.c of the component Markdown Handler. This manipulation causes uncontrolled r…
|
CWE-404 CWE-674
Improper Resource Shutdown or Release Uncontrolled Recursion
|
CVE-2026-4833
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2937
|
3.5 |
LOW
Network
|
-
|
-
|
A security vulnerability has been detected in code-projects Accounting System 1.0. Impacted is an unknown function of the file /my_account/add_costumer.php of the component Web Application Interface.…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4835
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2938
|
3.5 |
LOW
Network
|
-
|
-
|
Una vulnerabilidad de seguridad ha sido detectada en code-projects Accounting System 1.0. Afectada es una función desconocida del archivo /my_account/add_costumer.PHP del componente Interfaz de Aplic…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4835
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2939
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in code-projects Accounting System 1.0. The affected element is an unknown function of the file /my_account/delete.php. Performing a manipulation of the argument cos_id r…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4836
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2940
|
7.0 |
HIGH
Local
|
-
|
-
|
Una vulnerabilidad ha sido encontrada en Enter Software Iperius Backup hasta la versión 8.7.3. Afectada por este problema está alguna funcionalidad desconocida del componente Gestor de Archivos de Co…
|
CWE-266 CWE-269
Incorrect Privilege Assignment Improper Privilege Management
|
CVE-2026-4824
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2941
|
5.6 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in kalcaddle kodbox 1.64. This issue affects the function Add of the file app/controller/explorer/userShare.class.php of the component Public Share Handler. Such manipu…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-4830
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2942
|
5.6 |
MEDIUM
Network
|
-
|
-
|
Se identificó una vulnerabilidad en kalcaddle kodbox 1.64. Este problema afecta a la función Add del archivo app/controller/explorer/userShare.class.php del componente Gestor de Compartición Pública.…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-4830
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2943
|
3.7 |
LOW
Network
|
-
|
-
|
A security flaw has been discovered in kalcaddle kodbox 1.64. Impacted is the function can of the file /workspace/source-code/app/controller/explorer/auth.class.php of the component Password-protecte…
|
CWE-287
Improper Authentication
|
CVE-2026-4831
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2944
|
3.7 |
LOW
Network
|
-
|
-
|
Una falla de seguridad ha sido descubierta en kalcaddle kodbox 1.64. Afectada es la función can del archivo /workspace/source-code/app/controller/explorer/auth.class.php del componente Gestor de Comp…
|
CWE-287
Improper Authentication
|
CVE-2026-4831
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2945
|
3.3 |
LOW
Local
|
-
|
-
|
Se ha identificado una debilidad en Orc discount hasta 3.0.1.2. Este problema afecta a la función compile del archivo markdown.c del componente Markdown Gestor. Esta manipulación causa recursión inco…
|
CWE-404 CWE-674
Improper Resource Shutdown or Release Uncontrolled Recursion
|
CVE-2026-4833
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2946
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad fue detectada en code-projects Accounting System 1.0. El elemento afectado es una función desconocida del archivo /my_account/delete.php. Realizar una manipulación del argumento co…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4836
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2947
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The FloristPress for Woo – Customize your eCommerce store for your Florist plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'noresults' parameter in all versions up to, an…
|
CWE-79
Cross-site Scripting
|
CVE-2026-1986
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2948
|
6.1 |
MEDIUM
Network
|
-
|
-
|
El plugin FloristPress para Woo – Personaliza tu tienda de comercio electrónico para tu floristería para WordPress es vulnerable a cross-site scripting reflejado a través del parámetro 'noresults' en…
|
CWE-79
Cross-site Scripting
|
CVE-2026-1986
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2949
|
7.2 |
HIGH
Network
|
-
|
-
|
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to PHP Object Injection via deserialization of the 'post_content' of admin_form posts in all versions up to, and including, 3.28.31…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-3328
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2950
|
7.2 |
HIGH
Network
|
-
|
-
|
El plugin Frontend Admin de DynamiApps para WordPress es vulnerable a Inyección de Objetos PHP a través de la deserialización del 'post_content' de publicaciones de tipo admin_form en todas las versi…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-3328
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|