|
1681
|
6.5 |
MEDIUM
Adjacent
|
zyxel
|
wre6505_firmware
|
** UNSUPPORTED WHEN ASSIGNED ** An improper restriction of excessive authentication attempts vulnerability in the web management interface of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could a…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2026-7255
|
2026-05-13 23:48 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1682
|
5.3 |
MEDIUM
Local
|
-
|
-
|
A flaw has been found in Squirrel up to 3.2. Impacted is the function validate_format in the library sqstdlib/sqstdstring.cpp. Executing a manipulation can lead to stack-based buffer overflow. The at…
|
CWE-119 CWE-121
Incorrect Access of Indexable Resource ('Range Error') Stack-based Buffer Overflow
|
CVE-2026-8258
|
2026-05-13 23:47 |
2026-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1683
|
5.9 |
MEDIUM
Local
|
-
|
-
|
A vulnerability was determined in Squirrel up to 3.2. This affects the function SQFunctionProto::Load of the file squirrel/sqobject.cpp. This manipulation causes heap-based buffer overflow. The attac…
|
CWE-119 CWE-122
Incorrect Access of Indexable Resource ('Range Error') Heap-based Buffer Overflow
|
CVE-2026-8261
|
2026-05-13 23:47 |
2026-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1684
|
7.5 |
HIGH
Network
|
pillarjs
|
multiparty
|
multiparty@4.2.3 and lower versions are vulnerable to denial of service via regular expression backtracking in the Content-Disposition filename parameter parser. A crafted multipart upload with a lon…
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2026-8159
|
2026-05-13 23:44 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1685
|
7.5 |
HIGH
Network
|
pillarjs
|
multiparty
|
multiparty@4.2.3 and lower versions are vulnerable to denial of service via uncaught exception. By sending a multipart/form-data request with a field name that collides with an inherited Object.proto…
|
CWE-248 CWE-1321
Uncaught Exception Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2026-8161
|
2026-05-13 23:43 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1686
|
7.5 |
HIGH
Network
|
pillarjs
|
multiparty
|
multiparty@4.2.3 and lower versions are vulnerable to denial of service via uncaught exception. By sending a multipart/form-data request with a Content-Disposition header whose filename* parameter co…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2026-8162
|
2026-05-13 23:43 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1687
|
7.5 |
HIGH
Network
|
-
|
-
|
The Court Reservation – Manage Your Court Bookings Online plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.10.11 due to insuf…
|
CWE-89
SQL Injection
|
CVE-2026-1250
|
2026-05-13 23:43 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1688
|
7.1 |
HIGH
Network
|
-
|
-
|
The MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability…
|
CWE-862
Missing Authorization
|
CVE-2026-5371
|
2026-05-13 23:43 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1689
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Broadstreet plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.53.1 via the get_sponsored_meta() AJAX action. This makes it possible for …
|
CWE-200
Information Exposure
|
CVE-2025-9987
|
2026-05-13 23:43 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1690
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Price Manipulation and Insecure Direct Object Reference (IDOR) in all versions up to, and including, 4.0.1 only when …
|
CWE-862
Missing Authorization
|
CVE-2025-14755
|
2026-05-13 23:43 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|