|
2611
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Alfie – Feed Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing nonce validation on the alfie_manage() fun…
|
CWE-352
Origin Validation Error
|
CVE-2026-4070
|
2026-05-22 14:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2612
|
5.7 |
MEDIUM
Adjacent
|
-
|
-
|
There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of the access control mechanism, attackers can obtain information without authorization, causing the r…
|
CWE-200
Information Exposure
|
CVE-2026-44409
|
2026-05-22 14:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2613
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The WP Blockade plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode' parameter in all versions up to and including 0.9.14. This is due to insufficient input saniti…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3481
|
2026-05-22 14:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2614
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The FastX theme for WordPress is vulnerable to unauthorized limited plugin installation and activation due to missing capability checks on the 'ultp_install_callback' and 'ultp_activate_callback' fun…
|
CWE-862
Missing Authorization
|
CVE-2026-2518
|
2026-05-22 14:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2615
|
- |
|
-
|
-
|
An attacker sending tcp, il, rudp, rudp, or gre packets with a length less than the header size would trigger a kernel panic.
|
-
|
CVE-2026-9054
|
2026-05-22 13:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2616
|
- |
|
-
|
-
|
Mothra would respect a default value given by a website for HTML file upload forms. An attacker could craft a website with a malicious default file path, and then conceal this form element.
|
-
|
CVE-2026-9053
|
2026-05-22 13:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2617
|
7.5 |
HIGH
Network
|
-
|
-
|
The WP ERP Pro plugin for WordPress is vulnerable to SQL Injection via the 'search_key' parameter in all versions up to, and including, 1.5.1. This is due to insufficient escaping on the user supplie…
|
CWE-89
SQL Injection
|
CVE-2026-4834
|
2026-05-22 13:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2618
|
7.8 |
HIGH
Local
|
-
|
-
|
In `src/havegecmd.c`, the `socket_handler` function performs a credential check on the abstract UNIX socket (`\0/sys/entropy/haveged`). However, while it detects if the connecting user is not root (`…
|
CWE-305
Authentication Bypass by Primary Weakness
|
CVE-2026-41054
|
2026-05-22 13:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2619
|
- |
|
-
|
-
|
The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch …
|
-
|
CVE-2026-39831
|
2026-05-22 13:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2620
|
- |
|
-
|
-
|
A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), r…
|
-
|
CVE-2026-39830
|
2026-05-22 13:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|