|
1451
|
3.3 |
LOW
Local
|
-
|
-
|
A weakness has been identified in Noelse Individuals & Pro App up to 2.1.7 on Android. This impacts an unknown function of the file com/reactnative/antelop/BuildConfig.java of the component com.afone…
|
CWE-320 CWE-321
Key Management Errors Use of Hard-coded Cryptographic Key
|
CVE-2026-5458
|
2026-04-25 03:13 |
2026-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1452
|
3.3 |
LOW
Local
|
-
|
-
|
A vulnerability was identified in Wahoo Fitness SYSTM App up to 7.2.1 on Android. Impacted is an unknown function of the file com/WahooFitness/SYSTM/BuildConfig.java of the component com.WahooFitness…
|
CWE-320 CWE-321
Key Management Errors Use of Hard-coded Cryptographic Key
|
CVE-2026-5462
|
2026-04-25 03:13 |
2026-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1453
|
8.1 |
HIGH
Network
|
-
|
-
|
The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method proc…
|
CWE-22
Path Traversal
|
CVE-2026-4350
|
2026-04-25 03:13 |
2026-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1454
|
3.3 |
LOW
Local
|
-
|
-
|
A vulnerability was detected in Investory Toy Planet Trouble App up to 1.5.5 on Android. Impacted is an unknown function of the file assets/google-services-desktop.json of the component app.investory…
|
CWE-320 CWE-321
Key Management Errors Use of Hard-coded Cryptographic Key
|
CVE-2026-5471
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1455
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in mixelpixx Google-Research-MCP 1e062d7bd887bfe5f6e582b6cc288bb897b35cf2/ca613b736ab787bc926932f59cddc69457185a83. This issue affects the function extractC…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-5470
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1456
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. The affected element is an unknown function of the file /admin_panel/settings.php…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-5472
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1457
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in BookStackApp BookStack up to 26.03. Affected is the function chapterToMarkdown of the file app/Exports/ExportFormatter.php of the component Chapter Export Handler. E…
|
CWE-266 CWE-284
Incorrect Privilege Assignment Improper Access Control
|
CVE-2026-5484
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1458
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Pie Register – User Registration, Profiles & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pie_main() functi…
|
CWE-862
Missing Authorization
|
CVE-2026-3571
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1459
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'imageLoad' parameter in versions up to, and including, 3.4…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2924
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1460
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Icon Box widget in versions up to, and including, 1.4.24 due to insufficient inp…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2949
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|