|
1211
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Missing Authorization in all versions u…
|
CWE-862
Missing Authorization
|
CVE-2026-4949
|
2026-04-16 08:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1212
|
- |
|
-
|
-
|
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accid…
|
-
|
CVE-2026-6398
|
2026-04-16 06:17 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1213
|
7.1 |
HIGH
Local
|
sleuthkit
|
the_sleuth_kit
|
The Sleuth Kit through 4.14.0 contains a path traversal vulnerability in tsk_recover that allows an attacker to write files to arbitrary locations outside the intended recovery directory via crafted …
|
CWE-22
Path Traversal
|
CVE-2026-40024
|
2026-04-16 05:52 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1214
|
6.1 |
MEDIUM
Local
|
sleuthkit
|
the_sleuth_kit
|
The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the APFS filesystem keybag parser where the wrapped_key_parser class follows attacker-controlled length fields without bo…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-40025
|
2026-04-16 05:52 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1215
|
6.5 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in Telegram webhook authentication that allows attackers to brute-force weak webhook secrets. The vulnerability enables repeat…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2026-35628
|
2026-04-16 05:38 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1216
|
7.1 |
HIGH
Local
|
huawei
|
harmonyos emui
|
UAF vulnerability in the kernel module.
Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
|
CWE-416
Use After Free
|
CVE-2026-34854
|
2026-04-16 05:19 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1217
|
5.5 |
MEDIUM
Local
|
huawei
|
harmonyos
|
UAF vulnerability in the communication module.
Impact: Successful exploitation of this vulnerability may affect availability.
|
CWE-362
Race Condition
|
CVE-2026-34857
|
2026-04-16 05:16 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1218
|
4.1 |
MEDIUM
Local
|
huawei
|
harmonyos
|
UAF vulnerability in the communication module.
Impact: Successful exploitation of this vulnerability may affect availability.
|
CWE-362
Race Condition
|
CVE-2026-34858
|
2026-04-16 05:13 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1219
|
7.1 |
HIGH
Local
|
huawei
|
harmonyos emui
|
UAF vulnerability in the kernel module.
Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
|
CWE-416
Use After Free
|
CVE-2026-34859
|
2026-04-16 05:12 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1220
|
7.4 |
HIGH
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.3.25 contains a server-side request forgery vulnerability in multiple channel extensions that fail to properly guard configured base URLs against SSRF attacks. Attackers can expl…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-35629
|
2026-04-16 05:09 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|