|
561
|
6.5 |
MEDIUM
Network
|
-
|
-
|
When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total leng…
New
|
CWE-130
Improper Handling of Length Parameter Inconsistency
|
CVE-2026-5265
|
2026-04-24 23:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
562
|
8.6 |
HIGH
Network
|
-
|
-
|
A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynamic Host Configuration Protocol for IPv6) SOLICIT packets with an inflated Client ID length, could ca…
New
|
CWE-130
Improper Handling of Length Parameter Inconsistency
|
CVE-2026-5367
|
2026-04-24 23:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
563
|
- |
|
-
|
-
|
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.
Authentication bypass occurs when the URL ends with Authentication with certain…
New
|
CWE-290 CWE-863
Authentication Bypass by Spoofing Incorrect Authorization
|
CVE-2026-25660
|
2026-04-24 23:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
564
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption
The -EBUSY handling in tls_do_encryption(), introduced by c…
New
|
-
|
CVE-2026-31533
|
2026-04-24 23:38 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
565
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The MaxiBlocks Builder plugin for WordPress is vulnerable to arbitrary media file deletion due to insufficient file ownership validation on the 'maxi_remove_custom_image_size' AJAX action in all vers…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-2028
|
2026-04-24 23:38 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
566
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The BetterDocs plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.3.11. This is due to a missing capability check in the generate_openai_content_callback() …
New
|
CWE-862
Missing Authorization
|
CVE-2026-6393
|
2026-04-24 23:38 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
567
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the Image Grid/Slider/Carousel widget in versions up to and including 1.7.1056. This…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-5428
|
2026-04-24 23:38 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
568
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 9.1.2. This is due to missing capability checks…
New
|
CWE-862
Missing Authorization
|
CVE-2026-5488
|
2026-04-24 23:38 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
569
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The HM Books Gallery plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.8.0. This is due to the absence of capability checks and nonce verification in the a…
New
|
CWE-862
Missing Authorization
|
CVE-2026-5347
|
2026-04-24 23:38 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
570
|
8.1 |
HIGH
Network
|
-
|
-
|
The Drag and Drop File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.1.3. This is due to the plugin extracting the file ext…
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-5364
|
2026-04-24 23:38 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|