|
2931
|
7.5 |
HIGH
Network
|
-
|
-
|
El plugin JetFormBuilder para WordPress es vulnerable a la lectura arbitraria de archivos a través de salto de ruta en todas las versiones hasta la 3.5.6.2, inclusive. Esto se debe a que el método 'U…
|
CWE-36
Absolute Path Traversal
|
CVE-2026-4373
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2932
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in PbootCMS up to 3.2.12. Affected by this issue is some unknown functionality of the file apps/admin/controller/system/UserController.php of the component Backend. Executing a …
|
CWE-266 CWE-284
Incorrect Privilege Assignment Improper Access Control
|
CVE-2026-4514
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2933
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Se ha encontrado una vulnerabilidad en PbootCMS hasta la versión 3.2.12. Se ve afectada por este problema alguna funcionalidad desconocida del archivo apps/admin/controller/system/UserController.PHP …
|
CWE-266 CWE-284
Incorrect Privilege Assignment Improper Access Control
|
CVE-2026-4514
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2934
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net/sched: ets: fix divide by zero in the offload path
Offloading ETS requires computing each class' WRR weight: this is done by
…
|
CWE-369
Divide By Zero
|
CVE-2026-23379
|
2026-04-25 01:24 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2935
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
net/sched: ets: corregir división por cero en la ruta de descarga
La descarga de ETS requiere calcular el peso WRR de cada clase…
|
CWE-369
Divide By Zero
|
CVE-2026-23379
|
2026-04-25 01:24 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2936
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ice: change XDP RxQ frag_size from DMA write length to xdp.frame_sz
The only user of frag_size field in XDP RxQ info is
bpf_xdp_f…
|
NVD-CWE-noinfo
|
CVE-2026-23377
|
2026-04-25 01:23 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2937
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
ice: cambiar frag_size de XDP RxQ de la longitud de escritura DMA a xdp.frame_sz
El único usuario del campo frag_size en la info…
|
NVD-CWE-noinfo
|
CVE-2026-23377
|
2026-04-25 01:23 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2938
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
nvmet-fcloop: Check remoteport port_state before calling done callback
In nvme_fc_handle_ls_rqst_work, the lsrsp->done callback i…
|
NVD-CWE-noinfo
|
CVE-2026-23376
|
2026-04-25 01:21 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2939
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
nvmet-fcloop: Verificar el estado del puerto de remoteport antes de llamar a la función de devolución de llamada 'done'
En nvme_…
|
NVD-CWE-noinfo
|
CVE-2026-23376
|
2026-04-25 01:21 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2940
|
9.8 |
CRITICAL
Network
|
-
|
-
|
radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to execute arbitrary commands by bypassing the command filter through shell metachara…
|
-
|
CVE-2026-6942
|
2026-04-25 01:16 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|