|
1261
|
8.6 |
HIGH
Network
|
-
|
-
|
Xerte Online Toolkits versions 3.15 and earlier contain a missing authentication vulnerability in the elFinder connector endpoint at /editor/elfinder/php/connector.php where an HTTP redirect to unaut…
|
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
|
CVE-2026-34413
|
2026-04-25 05:16 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1262
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in merkulove Buttoner for Elementor buttoner-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Buttoner for Elem…
|
CWE-862
Missing Authorization
|
CVE-2025-68085
|
2026-04-25 05:16 |
2025-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1263
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeNectar Salient Shortcodes salient-shortcodes allows Stored XSS.This issue affects Salient Sh…
|
CWE-79
Cross-site Scripting
|
CVE-2025-68079
|
2026-04-25 05:16 |
2025-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1264
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Authorization Bypass Through User-Controlled Key vulnerability in g5theme Essential Real Estate essential-real-estate allows Exploiting Incorrectly Configured Access Control Security Levels.This issu…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2025-68071
|
2026-04-25 05:16 |
2025-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1265
|
7.5 |
HIGH
Network
|
-
|
-
|
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PenciDesign Soledad soledad allows PHP Local File Inclusion.This issue affects…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2025-68066
|
2026-04-25 05:16 |
2025-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1266
|
8.5 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Hydra Booking hydra-booking allows SQL Injection.This issue affects Hydra Booking: from …
|
CWE-89
SQL Injection
|
CVE-2025-68055
|
2026-04-25 05:16 |
2025-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1267
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2019 windows_server_2022 windows_server_2022_…
|
Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally.
|
CWE-843
Type Confusion
|
CVE-2026-20806
|
2026-04-25 05:16 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1268
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in sonalsinha21 SKT Page Builder skt-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SKT Page Builder: from n/a …
|
CWE-862
Missing Authorization
|
CVE-2025-54005
|
2026-04-25 05:16 |
2025-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1269
|
7.8 |
HIGH
Local
|
giskard
|
giskard
|
Giskard is an open-source testing framework for AI models. In versions prior to 1.0.2b1, the ConformityCheck class rendered the rule parameter through Jinja2's default Template() constructor, silentl…
|
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2026-40320
|
2026-04-25 05:15 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1270
|
4.6 |
MEDIUM
Physics
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2016 windows_server_2019 w…
|
Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a physical attack.
|
CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer
|
CVE-2026-20928
|
2026-04-25 05:11 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|