|
2821
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en magepeopleteam WpEvently mage-eventpress permite XSS Reflejado. Este problema a…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25361
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2822
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Özgür KARALAR Kargo Takip kargo-takip-turkiye allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kargo Takip: from n/a t…
|
CWE-862
Missing Authorization
|
CVE-2026-25365
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2823
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de autorización faltante en Özgür KARALAR Kargo Takip kargo-takip-turkiye permite explotar niveles de seguridad de control de acceso incorrectamente configurados. Este problema afecta …
|
CWE-862
Missing Authorization
|
CVE-2026-25365
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2824
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Improper Control of Generation of Code ('Code Injection') vulnerability in Themeisle Woody ad snippets insert-php allows Code Injection.This issue affects Woody ad snippets: from n/a through <= 2.7.1.
|
CWE-94
Code Injection
|
CVE-2026-25366
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2825
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Vulnerabilidad de Control Inadecuado de la Generación de Código ('Inyección de Código') en Themeisle Woody ad snippets insert-PHP permite la Inyección de Código. Este problema afecta a Woody ad snipp…
|
CWE-94
Code Injection
|
CVE-2026-25366
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2826
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in King-Theme Lumise Product Designer lumise allows Blind SQL Injection.This issue affects Lumise Pr…
|
CWE-89
SQL Injection
|
CVE-2026-25371
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2827
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando SQL ('inyección SQL') en King-Theme Lumise Product Designer lumise permite inyección SQL ciega. Este probl…
|
CWE-89
SQL Injection
|
CVE-2026-25371
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2828
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
blktrace: fix __this_cpu_read/write in preemptible context
tracing_record_cmdline() internally uses __this_cpu_read() and
__this_…
|
NVD-CWE-noinfo
|
CVE-2026-23374
|
2026-04-25 01:32 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2829
|
9.8 |
CRITICAL
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerability allows remote attackers to bypass authentication on affected installations …
|
CWE-287
Improper Authentication
|
CVE-2026-41276
|
2026-04-25 01:32 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2830
|
7.5 |
HIGH
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GET /api/v1/public-chatflows/:id endpoint returns the full chatflow object without sanitiz…
|
CWE-200
Information Exposure
|
CVE-2026-41278
|
2026-04-25 01:31 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|