|
1191
|
8.8 |
HIGH
Network
|
-
|
-
|
The AcyMailing plugin for WordPress is vulnerable to privilege escalation in all versions From 9.11.0 up to, and including, 10.8.1 due to a missing capability check on the `wp_ajax_acymailing_router`…
|
CWE-862
Missing Authorization
|
CVE-2026-3614
|
2026-04-16 15:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1192
|
7.5 |
HIGH
Network
|
-
|
-
|
The Riaxe Product Customizer plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter keys within 'product_data' of the /wp-json/InkXEProductDesignerLite/add-item-to-cart REST …
|
CWE-89
SQL Injection
|
CVE-2026-3599
|
2026-04-16 15:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1193
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Riaxe Product Customizer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.2. The plugin registers an unauthenticated AJAX action ('wp_ajax_nopr…
|
CWE-862
Missing Authorization
|
CVE-2026-3596
|
2026-04-16 15:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1194
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Riaxe Product Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.2. This is due to the plugin registering a REST API route at POST /wp…
|
CWE-862
Missing Authorization
|
CVE-2026-3595
|
2026-04-16 15:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1195
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Basic Google Maps Placemarks plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.10.7. This is due to the plugin not properly verifying that a user is a…
|
CWE-862
Missing Authorization
|
CVE-2026-3581
|
2026-04-16 15:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1196
|
4.4 |
MEDIUM
Network
|
-
|
-
|
The Custom New User Notification plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's admin settings in all versions up to, and including, 1.2.0. This is due to insuffic…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3551
|
2026-04-16 15:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1197
|
5.9 |
MEDIUM
Network
|
huawei
|
harmonyos
|
Race condition vulnerability in the notification service.
Impact: Successful exploitation of this vulnerability may affect availability.
|
CWE-362
Race Condition
|
CVE-2026-34850
|
2026-04-16 14:05 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1198
|
7.5 |
HIGH
Network
|
huawei
|
harmonyos
|
Race condition vulnerability in the event notification module.
Impact: Successful exploitation of this vulnerability may affect availability.
|
CWE-362
Race Condition
|
CVE-2026-34851
|
2026-04-16 14:01 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1199
|
6.5 |
MEDIUM
Network
|
huawei
|
harmonyos
|
Stack overflow vulnerability in the media platform.
Impact: Successful exploitation of this vulnerability may affect availability.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-34852
|
2026-04-16 13:54 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1200
|
7.5 |
HIGH
Network
|
huawei
|
harmonyos emui
|
Permission bypass vulnerability in the LBS module.
Impact: Successful exploitation of this vulnerability may affect availability.
|
CWE-270
Privilege Context Switching Error
|
CVE-2026-34853
|
2026-04-16 13:52 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|