|
1201
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'separatorIconSVG' parameter in versions up to, and includi…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-2868
|
2026-05-5 12:15 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1202
|
4.9 |
MEDIUM
Network
|
-
|
-
|
The Loco Translate plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.8.2 via the `fsReference` AJAX route. This is due to the `findSourceFile()` method norm…
New
|
CWE-22
Path Traversal
|
CVE-2026-1921
|
2026-05-5 12:15 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1203
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Mentoring plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.8. This is due to the plugin not properly restricting the roles that users can regis…
New
|
CWE-269
Improper Privilege Management
|
CVE-2025-13618
|
2026-05-5 12:15 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1204
|
9.1 |
CRITICAL
Network
|
gnu redhat
|
gnutls openshift_container_platform enterprise_linux
|
A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This…
Update
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2026-33845
|
2026-05-5 12:03 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1205
|
7.5 |
HIGH
Network
|
u-speed
|
n300_firmware
|
A denial-of-service vulnerability exists in the U-SPEED N300 V1.0.0 wireless router. By sending a large number of concurrent HTTP requests to random or non-existent endpoints on the web management in…
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-36958
|
2026-05-5 12:00 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1206
|
7.5 |
HIGH
Network
|
u-speed
|
n300_firmware
|
U-SPEED N300 router V1.0.0 does not implement rate limiting or account lockout protections on the /api/login endpoint. This allows an attacker on the local network to perform unlimited authentication…
Update
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2026-36959
|
2026-05-5 12:00 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1207
|
5.4 |
MEDIUM
Network
|
redhat
|
build_of_keycloak
|
When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the versioned path `/account/v1alpha1` remain fully func…
Update
|
CWE-425 NVD-CWE-noinfo
Direct Request ('Forced Browsing')
|
CVE-2026-7500
|
2026-05-5 12:00 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1208
|
7.5 |
HIGH
Network
|
dbitnet
|
dbit_n300_t1_pro_firmware
|
Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router V1.0.0 is vulnerable to Denial of Service via the boa web server URI handler. By initiating a high-volume flood of HTTP GET requests to non-existent …
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-36957
|
2026-05-5 11:59 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1209
|
5.5 |
MEDIUM
Local
|
redhat
|
multicluster_engine_for_kubernetes
|
A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-sco…
Update
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2026-7163
|
2026-05-5 11:57 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1210
|
7.8 |
HIGH
Local
|
qt
|
qtdeclarative
|
Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution…
Update
|
CWE-20 CWE-94
Improper Input Validation Code Injection
|
CVE-2025-14576
|
2026-05-5 11:57 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|