|
1141
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in themebeez Royale News royale-news allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Royale News: from n/a through <= 2.…
|
CWE-862
Missing Authorization
|
CVE-2026-39649
|
2026-04-25 03:06 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1142
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Unitech Web UnitechPay unitechpay-paiements-mobile-money allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UnitechPay: …
|
CWE-862
Missing Authorization
|
CVE-2026-39650
|
2026-04-25 03:06 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1143
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in TotalSuite Total Poll Lite totalpoll-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Total Poll Lite: from n/a t…
|
CWE-862
Missing Authorization
|
CVE-2026-39651
|
2026-04-25 03:06 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1144
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in igms iGMS Direct Booking igms-direct-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects iGMS Direct Booking: fro…
|
CWE-862
Missing Authorization
|
CVE-2026-39652
|
2026-04-25 03:06 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1145
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Deepen Bajracharya Video Conferencing with Zoom video-conferencing-with-zoom-api allows Exploiting Incorrectly Configured Access Control Security Levels.This is…
|
CWE-862
Missing Authorization
|
CVE-2026-39653
|
2026-04-25 03:06 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1146
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ashish Ajani WP Simple HTML Sitemap wp-simple-html-sitemap allows DOM-Based XSS.This issue affect…
|
CWE-79
Cross-site Scripting
|
CVE-2026-39654
|
2026-04-25 03:06 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1147
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
HID: pidff: Fix condition effect bit clearing
As reported by MPDarkGuy on discord, NULL pointer dereferences were
happening becau…
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-23349
|
2026-04-25 03:06 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1148
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad:
HID: pidff: Corrección del borrado de bits de efecto de condición
Según lo informado por MPDarkGuy en Discord, se estaban producie…
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-23349
|
2026-04-25 03:06 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1149
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Razorpay Razorpay for WooCommerce woo-razorpay allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Razorpay for WooCommer…
|
CWE-862
Missing Authorization
|
CVE-2026-39656
|
2026-04-25 03:06 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1150
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in leadlovers leadlovers forms leadlovers-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects leadlovers forms: from n…
|
CWE-862
Missing Authorization
|
CVE-2026-39657
|
2026-04-25 03:06 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|