|
3401
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kutethemes Boutique kute-boutique allows Reflected XSS.This issue affects Boutique: from n/a thro…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25342
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3402
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en kutethemes Boutique kute-boutique permite XSS Reflejado. Este problema afecta a…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25342
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3403
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in RadiusTheme Review Schema review-schema allows Retrieve Embedded Sensitive Data.This issue affects Review S…
|
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
|
CVE-2026-25344
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3404
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Exposición de Información Sensible del Sistema a una Esfera de Control No Autorizada vulnerabilidad en RadiusTheme Review Schema review-schema permite Recuperar Datos Sensibles Incrustados. Este prob…
|
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
|
CVE-2026-25344
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3405
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Improper Validation of Specified Quantity in Input vulnerability in GalleryCreator SimpLy Gallery simply-gallery-block allows Accessing Functionality Not Properly Constrained by ACLs.This issue affec…
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2026-25345
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3406
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Validación Incorrecta de Cantidad Especificada en la Entrada vulnerabilidad en GalleryCreator SimpLy Gallery simply-gallery-block permite Acceder a Funcionalidad No Restringida Adecuadamente por ACLs…
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2026-25345
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3407
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro FAQ Builder AYS faq-builder-ays allows Exploiting Incorrectly Configured Access Control S…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25346
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3408
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('Cross-site Scripting') vulnerabilidad en Ays Pro FAQ Builder AYS faq-builder-ays permite Explotar Niveles de Seguridad d…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25346
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3409
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Acato WP REST Cache wp-rest-cache allows Stored XSS.This issue affects WP REST Cache: from n/a th…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25347
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3410
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en Acato WP REST Cache wp-rest-cache permite XSS Almacenado. Este problema afecta …
|
CWE-79
Cross-site Scripting
|
CVE-2026-25347
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3411
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Loobek loobek allows Reflected XSS.This issue affects Loobek: from n/a through < 1.5.2.
|
CWE-79
Cross-site Scripting
|
CVE-2026-25349
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3412
|
7.1 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') en skygroup Loobek loobek permite XSS Reflejado. Este problema afecta a Loobek:…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25349
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3413
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Miti miti allows Reflected XSS.This issue affects Miti: from n/a through < 1.5.3.
|
CWE-79
Cross-site Scripting
|
CVE-2026-25350
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3414
|
7.1 |
HIGH
Network
|
-
|
-
|
La vulnerabilidad de Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') en skygroup Miti miti permite XSS Reflejado. Este problema afecta a Miti: de…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25350
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3415
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup MyMedi mymedi allows Reflected XSS.This issue affects MyMedi: from n/a through < 1.7.7.
|
CWE-79
Cross-site Scripting
|
CVE-2026-25351
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3416
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Inadecuada de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en skygroup MyMedi mymedi permite XSS Reflejado. Este problema afecta a MyMedi: de…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25351
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3417
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup MyDecor mydecor allows Reflected XSS.This issue affects MyDecor: from n/a through < 1.5.…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25352
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3418
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en skygroup MyDecor mydecor permite XSS Reflejado. Este problema afecta a MyDecor:…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25352
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3419
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Nooni nooni allows Reflected XSS.This issue affects Nooni: from n/a through < 1.5.1.
|
CWE-79
Cross-site Scripting
|
CVE-2026-25353
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3420
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en skygroup Nooni nooni permite XSS Reflejado. Este problema afecta a Nooni: desde…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25353
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3421
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Reebox reebox allows Reflected XSS.This issue affects Reebox: from n/a through < 1.4.8.
|
CWE-79
Cross-site Scripting
|
CVE-2026-25354
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3422
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en skygroup Reebox reebox permite XSS Reflejado. Este problema afecta a Reebox: de…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25354
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3423
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Sanzo sanzo allows Stored XSS.This issue affects Sanzo: from n/a through < 2.4.3.
|
CWE-79
Cross-site Scripting
|
CVE-2026-25355
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3424
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('Cross-site Scripting') en skygroup Sanzo sanzo permite XSS Almacenado. Este problema afecta a Sanzo: d…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25355
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3425
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Yobazar yobazar allows Reflected XSS.This issue affects Yobazar: from n/a through < 1.6.…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25356
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3426
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en skygroup Yobazar yobazar permite XSS Reflejado. Este problema afecta a Yobazar:…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25356
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3427
|
8.1 |
HIGH
Network
|
-
|
-
|
Authentication Bypass Using an Alternate Path or Channel vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro allows Authentication Abuse.This issue affects Ultimate Membership Pro…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-25357
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3428
|
8.1 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de omisión de autenticación Usando una Ruta o Canal Alternativo en azzaroco Ultimate Membership Pro indeed-membership-pro permite Abuso de Autenticación. Este problema afecta a Ultimat…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-25357
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3429
|
8.8 |
HIGH
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in rascals Meloo meloo allows Object Injection.This issue affects Meloo: from n/a through < 2.8.2.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-25358
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3430
|
8.8 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en rascals Meloo meloo permite la inyección de objetos. Este problema afecta a Meloo: desde n/a hasta < 2.8.2.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-25358
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3431
|
8.8 |
HIGH
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in rascals Pendulum pendulum allows Object Injection.This issue affects Pendulum: from n/a through < 3.1.5.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-25359
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3432
|
8.8 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en rascals Pendulum pendulum permite la inyección de objetos. Este problema afecta a Pendulum: desde n/a hasta < 3.1.5.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-25359
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3433
|
8.8 |
HIGH
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in rascals Vex vex allows Object Injection.This issue affects Vex: from n/a through < 1.2.9.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-25360
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3434
|
8.8 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en rascals Vex vex permite la inyección de objetos. Este problema afecta a Vex: desde n/a hasta < 1.2.9.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-25360
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3435
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magepeopleteam WpEvently mage-eventpress allows Reflected XSS.This issue affects WpEvently: from …
|
CWE-79
Cross-site Scripting
|
CVE-2026-25361
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3436
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en magepeopleteam WpEvently mage-eventpress permite XSS Reflejado. Este problema a…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25361
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3437
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Özgür KARALAR Kargo Takip kargo-takip-turkiye allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kargo Takip: from n/a t…
|
CWE-862
Missing Authorization
|
CVE-2026-25365
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3438
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de autorización faltante en Özgür KARALAR Kargo Takip kargo-takip-turkiye permite explotar niveles de seguridad de control de acceso incorrectamente configurados. Este problema afecta …
|
CWE-862
Missing Authorization
|
CVE-2026-25365
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3439
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Improper Control of Generation of Code ('Code Injection') vulnerability in Themeisle Woody ad snippets insert-php allows Code Injection.This issue affects Woody ad snippets: from n/a through <= 2.7.1.
|
CWE-94
Code Injection
|
CVE-2026-25366
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3440
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Vulnerabilidad de Control Inadecuado de la Generación de Código ('Inyección de Código') en Themeisle Woody ad snippets insert-PHP permite la Inyección de Código. Este problema afecta a Woody ad snipp…
|
CWE-94
Code Injection
|
CVE-2026-25366
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3441
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in King-Theme Lumise Product Designer lumise allows Blind SQL Injection.This issue affects Lumise Pr…
|
CWE-89
SQL Injection
|
CVE-2026-25371
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3442
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando SQL ('inyección SQL') en King-Theme Lumise Product Designer lumise permite inyección SQL ciega. Este probl…
|
CWE-89
SQL Injection
|
CVE-2026-25371
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3443
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
blktrace: fix __this_cpu_read/write in preemptible context
tracing_record_cmdline() internally uses __this_cpu_read() and
__this_…
|
NVD-CWE-noinfo
|
CVE-2026-23374
|
2026-04-25 01:32 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3444
|
9.8 |
CRITICAL
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerability allows remote attackers to bypass authentication on affected installations …
|
CWE-287
Improper Authentication
|
CVE-2026-41276
|
2026-04-25 01:32 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3445
|
7.5 |
HIGH
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GET /api/v1/public-chatflows/:id endpoint returns the full chatflow object without sanitiz…
|
CWE-200
Information Exposure
|
CVE-2026-41278
|
2026-04-25 01:31 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3446
|
7.5 |
HIGH
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the text-to-speech generation endpoint (POST /api/v1/text-to-speech/generate) is whitelisted (…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-41279
|
2026-04-25 01:31 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3447
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
mm: thp: deny THP for files on anonymous inodes
file_thp_enabled() incorrectly allows THP for files on anonymous inodes
(e.g. gue…
|
CWE-617
Reachable Assertion
|
CVE-2026-23375
|
2026-04-25 01:31 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3448
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
mm: thp: denegar THP para archivos en inodos anónimos
file_thp_enabled() permite incorrectamente THP para archivos en inodos anó…
|
CWE-617
Reachable Assertion
|
CVE-2026-23375
|
2026-04-25 01:31 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3449
|
5.0 |
MEDIUM
Adjacent
|
-
|
-
|
A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the component BLE Interface. Such manipulation leads to missing authentication. Th…
|
CWE-287 CWE-306
Improper Authentication Missing Authentication for Critical Function
|
CVE-2026-2756
|
2026-04-25 01:31 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3450
|
5.0 |
MEDIUM
Adjacent
|
-
|
-
|
Una vulnerabilidad de seguridad ha sido detectada en OmniPEMF NeoRhythm hasta el 20260308. Esto afecta una función desconocida del componente Interfaz BLE. Dicha manipulación conduce a la falta de au…
|
CWE-287 CWE-306
Improper Authentication Missing Authentication for Critical Function
|
CVE-2026-2756
|
2026-04-25 01:31 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|