|
1221
|
7.5 |
HIGH
Network
|
-
|
-
|
The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.9.8. This is due to the plugin containin…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2026-1233
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1222
|
7.2 |
HIGH
Network
|
-
|
-
|
The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_title' parameter in all versions up to, and including, 8.4 due to insufficient…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2936
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1223
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all ve…
|
CWE-94
Code Injection
|
CVE-2026-3309
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1224
|
8.8 |
HIGH
Network
|
-
|
-
|
The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.4.16. This is due to a missing file name/path validation against path traversal …
|
CWE-22
Path Traversal
|
CVE-2026-3666
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1225
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in MoussaabBadla code-screenshot-mcp up to 0.1.0. This affects an unknown part of the component HTTP Interface. Such manipulation leads to os command inject…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-5528
|
2026-04-25 03:13 |
2026-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1226
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in Dromara lamp-cloud up to 5.8.1. This vulnerability affects the function pageUser of the file /defUser/pageUser of the component DefUserController. Performing a manipul…
|
CWE-266 CWE-285
Incorrect Privilege Assignment Improper Authorization
|
CVE-2026-5529
|
2026-04-25 03:13 |
2026-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1227
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in Ollama up to 18.1. This issue affects some unknown processing of the file server/download.go of the component Model Pull API. Executing a manipulation can lead to server-side…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-5530
|
2026-04-25 03:13 |
2026-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1228
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in SourceCodester Student Result Management System 1.0. Impacted is an unknown function of the file /login_credentials.txt of the component HTTP GET Request Handler. Th…
|
CWE-312 CWE-313
Cleartext Storage of Sensitive Information Cleartext Storage in a File or on Disk
|
CVE-2026-5531
|
2026-04-25 03:13 |
2026-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1229
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was determined in code-projects Student Membership System 1.0. The impacted element is an unknown function of the file /admin/index.php of the component Admin Login. This manipulation…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5198
|
2026-04-25 03:12 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1230
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in CMS Made Simple up to 2.2.22. This impacts the function _copyFilesToFolder in the library modules/UserGuide/lib/class.UserGuideImporterExporter.php of the component UserG…
|
CWE-22
Path Traversal
|
CVE-2026-5203
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|