|
2841
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
tracing: Corrección de WARN_ON en tracing_buffers_mmap_close
Cuando un proceso hace fork, el proceso hijo copia los VMAs del pad…
|
CWE-617
Reachable Assertion
|
CVE-2026-23380
|
2026-04-25 01:28 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2842
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The ElementCamp plugin for WordPress is vulnerable to time-based SQL Injection via the 'meta_query[compare]' parameter in the 'tcg_select2_search_post' AJAX action in all versions up to, and includin…
|
CWE-89
SQL Injection
|
CVE-2026-2503
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2843
|
6.5 |
MEDIUM
Network
|
-
|
-
|
El plugin ElementCamp para WordPress es vulnerable a inyección SQL basada en tiempo a través del parámetro 'meta_query[compare]' en la acción AJAX 'tcg_select2_search_post' en todas las versiones has…
|
CWE-89
SQL Injection
|
CVE-2026-2503
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2844
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Hr Press Lite plugin for WordPress is vulnerable to unauthorized access of sensitive employee data due to a missing capability check on the `hrp-fetch-employees` AJAX action in all versions up to…
|
CWE-862
Missing Authorization
|
CVE-2026-2720
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2845
|
6.5 |
MEDIUM
Network
|
-
|
-
|
El plugin Hr Press Lite para WordPress es vulnerable a acceso no autorizado de datos sensibles de empleados debido a una comprobación de capacidad faltante en la acción AJAX 'hrp-fetch-employees' en …
|
CWE-862
Missing Authorization
|
CVE-2026-2720
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2846
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Post Snippits plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the settings page handlers for…
|
CWE-352
Origin Validation Error
|
CVE-2026-2723
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2847
|
6.1 |
MEDIUM
Network
|
-
|
-
|
El plugin Post Snippits para WordPress es vulnerable a la falsificación de petición en sitios cruzados en todas las versiones hasta la 1.0, inclusive. Esto se debe a la falta de validación de nonce e…
|
CWE-352
Origin Validation Error
|
CVE-2026-2723
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2848
|
4.4 |
MEDIUM
Network
|
-
|
-
|
The Ricerca – advanced search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin's settings in all versions up to, and including, 1.1.12 due to insufficient input sanitizati…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2837
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2849
|
4.4 |
MEDIUM
Network
|
-
|
-
|
El plugin de búsqueda avanzada Ricerca para WordPress es vulnerable a cross-site scripting almacenado a través de la configuración del plugin en todas las versiones hasta la 1.1.12, inclusive, debido…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2837
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2850
|
8.8 |
HIGH
Network
|
-
|
-
|
The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'linksy_search_and_replace_item_details' function in all…
|
CWE-862
Missing Authorization
|
CVE-2026-2941
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|