|
4601
|
8.1 |
HIGH
Network
|
-
|
-
|
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Kunco kunco allows PHP Local File Inclusion.This issue affects Kunco: f…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-32531
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4602
|
8.1 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de Control inadecuado del nombre de fichero para la declaración Include/Require en programa PHP ('inclusión remota de ficheros PHP') en gavias Kunco kunco permite la inclusión local de…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-32531
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4603
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Contact Form & Lead Form Elementor Builder lead-form-builder allows Stored XSS.This iss…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32532
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4604
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en ThemeHunk Contact Form & Lead Form Elementor Builder lead-form-builder perm…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32532
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4605
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Authorization Bypass Through User-Controlled Key vulnerability in LatePoint LatePoint latepoint allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LatePoint: f…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-32533
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4606
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de omisión de autorización a través de clave controlada por el usuario en LatePoint LatePoint latepoint permite explotar niveles de seguridad de control de acceso configurados incorrec…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-32533
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4607
|
8.5 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help Desk js-support-ticket allows Blind SQL Injection.This issue affects JS Help Desk…
|
CWE-89
SQL Injection
|
CVE-2026-32534
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4608
|
8.5 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de Neutralización Incorrecta de Elementos Especiales utilizados en un Comando SQL ('Inyección SQL') en JoomSky JS Help Desk js-support-ticket permite Inyección SQL Ciega. Este problema…
|
CWE-89
SQL Injection
|
CVE-2026-32534
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4609
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Authorization Bypass Through User-Controlled Key vulnerability in JoomSky JS Help Desk js-support-ticket allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS …
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-32535
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4610
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de elusión de autorización a través de clave controlada por el usuario en JoomSky JS Help Desk js-support-ticket permite explotar niveles de seguridad de control de acceso configurados…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-32535
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4611
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Unrestricted Upload of File with Dangerous Type vulnerability in halfdata Green Downloads halfdata-paypal-green-downloads allows Using Malicious Files.This issue affects Green Downloads: from n/a thr…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-32536
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4612
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Vulnerabilidad de carga sin restricciones de archivo con tipo peligroso en halfdata Green Downloads halfdata-paypal-green-downloads permite el uso de archivos maliciosos. Este problema afecta a Green…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-32536
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4613
|
7.5 |
HIGH
Network
|
-
|
-
|
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in nK Visual Portfolio, Photo Gallery & Post Grid visual-portfolio allows PHP Loc…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-32537
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4614
|
7.5 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de control inadecuado del nombre de fichero para la declaración Include/Require en el programa PHP ('Inclusión Remota de Ficheros PHP') en nK Visual Portfolio, Photo Gallery & Post…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-32537
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4615
|
7.5 |
HIGH
Network
|
-
|
-
|
Insertion of Sensitive Information Into Sent Data vulnerability in Noor Alam SMTP Mailer smtp-mailer allows Retrieve Embedded Sensitive Data.This issue affects SMTP Mailer: from n/a through <= 1.1.24.
|
CWE-201
Insertion of Sensitive Information Into Sent Data
|
CVE-2026-32538
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4616
|
7.5 |
HIGH
Network
|
-
|
-
|
Inserción de información sensible en datos enviados vulnerabilidad en Noor Alam SMTP Mailer smtp-mailer permite recuperar datos sensibles incrustados. Este problema afecta a SMTP Mailer: desde n/a ha…
|
CWE-201
Insertion of Sensitive Information Into Sent Data
|
CVE-2026-32538
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4617
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PublishPress PublishPress Revisions revisionary allows Blind SQL Injection.This issue affects Pub…
|
CWE-89
SQL Injection
|
CVE-2026-32539
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4618
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Neutralización Incorrecta de Elementos Especiales utilizados en un Comando SQL ('Inyección SQL') vulnerabilidad en PublishPress PublishPress Revisions revisionary permite Inyección SQL Ciega. Este pr…
|
CWE-89
SQL Injection
|
CVE-2026-32539
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4619
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bookly Bookly bookly-responsive-appointment-booking-tool allows Reflected XSS.This issue affects …
|
CWE-79
Cross-site Scripting
|
CVE-2026-32540
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4620
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en Bookly Bookly bookly-responsive-appointment-booking-tool permite XSS Reflejado.…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32540
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4621
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Premmerce Premmerce Redirect Manager premmerce-redirect-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Premm…
|
CWE-862
Missing Authorization
|
CVE-2026-32541
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4622
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad por ausencia de autorización en Premmerce Premmerce Redirect Manager premmerce-redirect-manager permite la explotación de niveles de seguridad de control de acceso configurados incorre…
|
CWE-862
Missing Authorization
|
CVE-2026-32541
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4623
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeFusion Fusion Builder fusion-builder allows Reflected XSS.This issue affects Fusion Builder:…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32542
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4624
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en ThemeFusion Fusion Builder fusion-builder permite XSS Reflejado. Este problema …
|
CWE-79
Cross-site Scripting
|
CVE-2026-32542
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4625
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OOPSpam Team OOPSpam Anti-Spam oopspam-anti-spam allows Stored XSS.This issue affects OOPSpam Ant…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32544
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4626
|
7.1 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de Neutralización Inadecuada de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') en OOPSpam Team OOPSpam Anti-Spam oopspam-anti-spam permite XSS Almacenado. Est…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32544
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4627
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Taboola Taboola Pixel taboola-pixel allows Reflected XSS.This issue affects Taboola Pixel: from n…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32545
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4628
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en Taboola Taboola Pixel taboola-pixel permite XSS Reflejado. Este problema afecta…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32545
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4629
|
7.5 |
HIGH
Network
|
-
|
-
|
Missing Authorization vulnerability in StellarWP Restrict Content restrict-content allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Restrict Content: from n/…
|
CWE-862
Missing Authorization
|
CVE-2026-32546
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4630
|
7.5 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad por ausencia de autorización en StellarWP Restrict Content restrict-content permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este probl…
|
CWE-862
Missing Authorization
|
CVE-2026-32546
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4631
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in WP Folio Team PPWP password-protect-page allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PPWP: from n/a through <= 1.…
|
CWE-862
Missing Authorization
|
CVE-2026-32562
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4632
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de Autorización Faltante en WP Folio Team PPWP password-protect-page permite Explotar Niveles de Seguridad de Control de Acceso Incorrectamente Configurados. Este problema afecta a PPW…
|
CWE-862
Missing Authorization
|
CVE-2026-32562
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4633
|
6.8 |
MEDIUM
Network
|
-
|
-
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in icopydoc YML for Yandex Market yml-for-yandex-market allows Path Traversal.This issue affects YML for Y…
|
CWE-22
Path Traversal
|
CVE-2026-32567
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4634
|
6.8 |
MEDIUM
Network
|
-
|
-
|
Limitación Incorrecta de un Nombre de Ruta a un Directorio Restringido ('Salto de Ruta') vulnerabilidad en icopydoc YML para Yandex Market yml-for-yandex-market permite Salto de Ruta. Este problema a…
|
CWE-22
Path Traversal
|
CVE-2026-32567
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4635
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Code Injection.This issue affects Nelio AB Testing: from n/a through…
|
CWE-94
Code Injection
|
CVE-2026-32573
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4636
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Control inadecuado de la generación de código ('Inyección de Código') vulnerabilidad en Nelio Software Nelio AB Testing nelio-ab-testing permite la inyección de código. Este problema afecta a Nelio A…
|
CWE-94
Code Injection
|
CVE-2026-32573
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4637
|
8.8 |
HIGH
Network
|
-
|
-
|
The WP Job Portal plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'WPJOBPORTALcustomfields::removeFileCustom' function in all versions up…
|
CWE-22
Path Traversal
|
CVE-2026-4758
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4638
|
8.8 |
HIGH
Network
|
-
|
-
|
El plugin WP Job Portal para WordPress es vulnerable a la eliminación arbitraria de archivos debido a una validación insuficiente de la ruta de archivo en la función 'WPJOBPORTALcustomfields::removeF…
|
CWE-22
Path Traversal
|
CVE-2026-4758
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4639
|
8.8 |
HIGH
Network
|
-
|
-
|
The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6. This is due to the plugin allowing a user to update the user role through the…
|
CWE-862
Missing Authorization
|
CVE-2026-4484
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4640
|
8.8 |
HIGH
Network
|
-
|
-
|
El plugin Masteriyo LMS para WordPress es vulnerable a una escalada de privilegios en todas las versiones hasta la 2.1.6, inclusive. Esto se debe a que el plugin permite a un usuario actualizar el ro…
|
CWE-862
Missing Authorization
|
CVE-2026-4484
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4641
|
7.0 |
HIGH
Local
|
-
|
-
|
A vulnerability was detected in Enter Software Iperius Backup up to 8.7.3. Affected is an unknown function of the file C:\ProgramData\IperiusBackup\Jobs\ of the component Backup Service. Performing a…
|
CWE-377 CWE-378
Insecure Temporary File Creation of Temporary File With Insecure Permissions
|
CVE-2026-4822
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4642
|
7.0 |
HIGH
Local
|
-
|
-
|
Una vulnerabilidad fue detectada en Enter Software Iperius Backup hasta 8.7.3. Afecta a una función desconocida del archivo C:\ProgramData\IperiusBackup\Jobs\ del componente Backup Service. Realizar …
|
CWE-377 CWE-378
Insecure Temporary File Creation of Temporary File With Insecure Permissions
|
CVE-2026-4822
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4643
|
2.5 |
LOW
Local
|
-
|
-
|
A flaw has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this vulnerability is an unknown functionality of the component NTLM2 Handler. Executing a manipulation can lead to inf…
|
CWE-200 CWE-284
Information Exposure Improper Access Control
|
CVE-2026-4823
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4644
|
2.5 |
LOW
Local
|
-
|
-
|
Se ha encontrado una falla en Enter Software Iperius Backup hasta la versión 8.7.3. Afectada por esta vulnerabilidad es una funcionalidad desconocida del componente Gestor NTLM2. La ejecución de una …
|
CWE-200 CWE-284
Information Exposure Improper Access Control
|
CVE-2026-4823
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4645
|
7.0 |
HIGH
Local
|
-
|
-
|
A vulnerability has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this issue is some unknown functionality of the component Backup Job Configuration File Handler. The manipulat…
|
CWE-266 CWE-269
Incorrect Privilege Assignment Improper Privilege Management
|
CVE-2026-4824
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4646
|
3.3 |
LOW
Local
|
-
|
-
|
A weakness has been identified in Orc discount up to 3.0.1.2. This issue affects the function compile of the file markdown.c of the component Markdown Handler. This manipulation causes uncontrolled r…
|
CWE-404 CWE-674
Improper Resource Shutdown or Release Uncontrolled Recursion
|
CVE-2026-4833
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4647
|
3.5 |
LOW
Network
|
-
|
-
|
A security vulnerability has been detected in code-projects Accounting System 1.0. Impacted is an unknown function of the file /my_account/add_costumer.php of the component Web Application Interface.…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4835
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4648
|
3.5 |
LOW
Network
|
-
|
-
|
Una vulnerabilidad de seguridad ha sido detectada en code-projects Accounting System 1.0. Afectada es una función desconocida del archivo /my_account/add_costumer.PHP del componente Interfaz de Aplic…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4835
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4649
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in code-projects Accounting System 1.0. The affected element is an unknown function of the file /my_account/delete.php. Performing a manipulation of the argument cos_id r…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4836
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4650
|
7.0 |
HIGH
Local
|
-
|
-
|
Una vulnerabilidad ha sido encontrada en Enter Software Iperius Backup hasta la versión 8.7.3. Afectada por este problema está alguna funcionalidad desconocida del componente Gestor de Archivos de Co…
|
CWE-266 CWE-269
Incorrect Privilege Assignment Improper Privilege Management
|
CVE-2026-4824
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|