|
941
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'max_width' attribute of the `su_box` shortcode in all versions up to, and inc…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2480
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
942
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin WP Shortcodes Plugin — Shortcodes Ultimate para WordPress es vulnerable a cross-site scripting almacenado a través del atributo 'max_width' del shortcode 'su_box' en todas las versiones has…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2480
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
943
|
5.3 |
MEDIUM
Local
|
-
|
-
|
A vulnerability was determined in Axiomatic Bento4 up to 1.6.0-641. This impacts the function AP4_BitReader::ReadCache of the file Ap4Dac4Atom.cpp of the component MP4 File Parser. This manipulation …
|
CWE-119 CWE-122
Incorrect Access of Indexable Resource ('Range Error') Heap-based Buffer Overflow
|
CVE-2026-5235
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
944
|
5.3 |
MEDIUM
Local
|
-
|
-
|
Una vulnerabilidad fue determinada en Axiomatic Bento4 hasta 1.6.0-641. Esto afecta la función AP4_BitReader::ReadCache del archivo Ap4Dac4Atom.cpp del componente MP4 File Parser. Esta manipulación c…
|
CWE-119 CWE-122
Incorrect Access of Indexable Resource ('Range Error') Heap-based Buffer Overflow
|
CVE-2026-5235
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
945
|
5.3 |
MEDIUM
Local
|
-
|
-
|
A vulnerability was identified in Axiomatic Bento4 up to 1.6.0-641. Affected is the function AP4_BitReader::SkipBits of the file Ap4Dac4Atom.cpp of the component DSI v1 Parser. Such manipulation of t…
|
CWE-119 CWE-122
Incorrect Access of Indexable Resource ('Range Error') Heap-based Buffer Overflow
|
CVE-2026-5236
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
946
|
7.3 |
HIGH
Network
|
-
|
-
|
A security flaw has been discovered in itsourcecode Payroll Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /manage_user.php of the component Parameter H…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5237
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
947
|
7.3 |
HIGH
Network
|
-
|
-
|
Una falla de seguridad ha sido descubierta en itsourcecode Payroll Management System 1.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /manage_user.php del componente…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5237
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
948
|
7.3 |
HIGH
Network
|
-
|
-
|
A weakness has been identified in itsourcecode Payroll Management System 1.0. Affected by this issue is some unknown functionality of the file /view_employee.php of the component Parameter Handler. E…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5238
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
949
|
5.3 |
MEDIUM
Local
|
-
|
-
|
Se identificó una vulnerabilidad en Axiomatic Bento4 hasta la versión 1.6.0-641. Se ve afectada la función AP4_BitReader::SkipBits del archivo Ap4Dac4Atom.cpp del componente DSI v1 Parser. Dicha mani…
|
CWE-119 CWE-122
Incorrect Access of Indexable Resource ('Range Error') Heap-based Buffer Overflow
|
CVE-2026-5236
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
950
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to SQL Injection via the `sort` parameter in the payments listing endpoint in all versions up to, and incl…
|
CWE-89
SQL Injection
|
CVE-2026-4668
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|