|
1151
|
8.1 |
HIGH
Network
|
-
|
-
|
The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.35 This is due to missing nonce verification on the bulk action handle…
|
CWE-352
Origin Validation Error
|
CVE-2026-6075
|
2026-05-29 22:09 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1152
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the update_site_editor_homepage function in al…
|
CWE-862
Missing Authorization
|
CVE-2025-12714
|
2026-05-29 22:09 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1153
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Payment Bypass via Insufficient Verification of Data Authenticity in all versions up to, and including, 2.4.9. Althou…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2026-9189
|
2026-05-29 22:09 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1154
|
4.3 |
MEDIUM
Network
|
apache
|
activemq_artemis artemis
|
A vulnerability exists in Apache Artemis whereby an application using the STOMP protocol with security credentials that grant either the consume or send permission on an address can augment the routi…
|
CWE-863
Incorrect Authorization
|
CVE-2026-40914
|
2026-05-29 21:25 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1155
|
8.8 |
HIGH
Network
|
-
|
-
|
Tanium addressed an unauthorized code execution vulnerability in Connect.
|
CWE-78
OS Command
|
CVE-2026-9208
|
2026-05-29 11:47 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1156
|
6.8 |
MEDIUM
Local
|
-
|
-
|
Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjection option which can be bypassed. An attacker can inject formulas into CSV fil…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2026-9673
|
2026-05-29 11:47 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1157
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera). Supported versions that are affected are 5.6.19.24, 5.6.22, 5.6.25.19…
|
-
|
CVE-2026-34311
|
2026-05-29 11:47 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1158
|
8.5 |
HIGH
Network
|
-
|
-
|
Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable v…
|
-
|
CVE-2026-46820
|
2026-05-29 11:47 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1159
|
9.0 |
CRITICAL
Network
|
-
|
-
|
Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with…
|
-
|
CVE-2026-46833
|
2026-05-29 11:47 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1160
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A flaw was found in glib-networking. A remote attacker can exploit this vulnerability by presenting a specially crafted certificate chain to an application that uses glib-networking with the GnuTLS b…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-10028
|
2026-05-29 11:47 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|