|
1841
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in fullworks Display Eventbrite Events widget-for-eventbrite-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Display…
|
CWE-862
Missing Authorization
|
CVE-2026-39535
|
2026-04-14 04:16 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1842
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in weDevs weDocs wedocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects weDocs: from n/a through <= 2.1.18.
|
CWE-862
Missing Authorization
|
CVE-2026-39520
|
2026-04-14 04:16 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1843
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in wpWax Directorist directorist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directorist: from n/a through <= 8.5.10.
|
CWE-862
Missing Authorization
|
CVE-2026-39509
|
2026-04-14 04:16 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1844
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Jordy Meow AI Engine (Pro) ai-engine-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Engine (Pro): from n/a th…
|
CWE-862
Missing Authorization
|
CVE-2026-39506
|
2026-04-14 04:16 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1845
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in InstaWP InstaWP Connect instawp-connect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects InstaWP Connect: from n/a thr…
|
CWE-862
Missing Authorization
|
CVE-2026-39504
|
2026-04-14 04:16 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1846
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in SureCart SureCart surecart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SureCart: from n/a through <= 4.0.2.
|
CWE-862
Missing Authorization
|
CVE-2026-39488
|
2026-04-14 04:16 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1847
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Brainstorm Force CartFlows cartflows allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CartFlows: from n/a through <= 2…
|
CWE-862
Missing Authorization
|
CVE-2026-39477
|
2026-04-14 04:16 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1848
|
7.5 |
HIGH
Network
|
-
|
-
|
When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affe…
|
-
|
CVE-2026-33810
|
2026-04-14 04:16 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1849
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS …
|
-
|
CVE-2026-32289
|
2026-04-14 04:16 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1850
|
5.5 |
MEDIUM
Local
|
-
|
-
|
tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.
|
-
|
CVE-2026-32288
|
2026-04-14 04:16 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|