|
1221
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.9.8.4. This is due to the plugin not properl…
New
|
CWE-862
Missing Authorization
|
CVE-2026-4607
|
2026-05-13 23:43 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1222
|
7.2 |
HIGH
Network
|
-
|
-
|
The Custom Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.5.4. This is due to insufficient output escaping in the CTF_Display_Elemen…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-6177
|
2026-05-13 23:43 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1223
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind SQL Injection via the 'rid' parameter in all versions up to, and including, 5.9.8.4 due to insuffic…
New
|
CWE-89
SQL Injection
|
CVE-2026-4608
|
2026-05-13 23:43 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1224
|
7.1 |
HIGH
Network
|
-
|
-
|
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the pm_invite_user function in all versions up t…
New
|
CWE-862
Missing Authorization
|
CVE-2026-4609
|
2026-05-13 23:43 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1225
|
5.5 |
MEDIUM
Local
|
apple
|
ipados iphone_os macos visionos watchos
|
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5, watchOS 26.5. An app may be able to bypass certain Pr…
New
|
CWE-284
Improper Access Control
|
CVE-2026-28988
|
2026-05-13 23:43 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1226
|
4.3 |
MEDIUM
Network
|
apple
|
ipados iphone_os macos tvos visionos watchos
|
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-39869
|
2026-05-13 23:42 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1227
|
7.5 |
HIGH
Network
|
golang
|
go http2
|
When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.
Update
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-33814
|
2026-05-13 23:41 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1228
|
7.5 |
HIGH
Network
|
apple
|
macos
|
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. Processing a maliciously crafted image may corrupt process m…
New
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2026-39870
|
2026-05-13 23:39 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1229
|
9.1 |
CRITICAL
Network
|
artica
|
pandora_fms
|
Insecure Default Initialization of Resource vulnerability allows Authentication Bypass via API access. This issue affects Pandora FMS: from 777 through 800
New
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2026-30805
|
2026-05-13 23:39 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1230
|
6.2 |
MEDIUM
Local
|
apple
|
ipados iphone_os macos tvos
|
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5. An attacker on …
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-43653
|
2026-05-13 23:39 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|