|
2681
|
7.1 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de autorización faltante en Theme-one The Grid the-grid permite explotar niveles de seguridad de control de acceso incorrectamente configurados. Este problema afecta a The Grid: desde …
|
CWE-862
Missing Authorization
|
CVE-2026-24369
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2682
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme-one The Grid the-grid allows Stored XSS.This issue affects The Grid: from n/a through < 2.8…
|
CWE-79
Cross-site Scripting
|
CVE-2026-24370
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2683
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en Theme-one The Grid the-grid permite XSS Almacenado. Este problema afecta a The …
|
CWE-79
Cross-site Scripting
|
CVE-2026-24370
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2684
|
7.5 |
HIGH
Network
|
-
|
-
|
Authentication Bypass by Spoofing vulnerability in WP Swings Subscriptions for WooCommerce subscriptions-for-woocommerce allows Input Data Manipulation.This issue affects Subscriptions for WooCommerc…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2026-24372
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2685
|
7.5 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de omisión de autenticación por suplantación en WP Swings Subscriptions for WooCommerce subscriptions-for-woocommerce permite la manipulación de datos de entrada. Este problema afecta …
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2026-24372
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2686
|
8.1 |
HIGH
Network
|
-
|
-
|
Incorrect Privilege Assignment vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Privilege Escalation.This issue affects RegistrationMagic: …
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-24373
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2687
|
8.1 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de Asignación Incorrecta de Privilegios en Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager permite escalada de privilegios. Este problema afecta a …
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-24373
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2688
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Javier Casares WPVulnerability wpvulnerability allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPVulnerability: from …
|
CWE-862
Missing Authorization
|
CVE-2026-24376
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2689
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad por falta de autorización en Javier Casares WPVulnerability wpvulnerability permite la explotación de niveles de seguridad de control de acceso mal configurados. Este problema afecta a…
|
CWE-862
Missing Authorization
|
CVE-2026-24376
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2690
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Object Injection.This issue affects EventPrime: from n/a through <= 4.2.8.0.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-24378
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|