|
3521
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-booking-with-seat-reservation allows Object Injection.This issue affects Bus Tick…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-27095
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3522
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-booking-with-seat-reservation permite la inyección de objetos. Este prob…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-27095
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3523
|
8.6 |
HIGH
Network
|
-
|
-
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Whitebox-Studio Scape scape allows Path Traversal.This issue affects Scape: from n/a through < 1.5.16.
|
CWE-22
Path Traversal
|
CVE-2026-31913
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3524
|
8.6 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de Limitación Inadecuada de un Nombre de Ruta a un Directorio Restringido ('Salto de Ruta') en Whitebox-Studio Scape scape permite el Salto de Ruta. Este problema afecta a Scape: desde…
|
CWE-22
Path Traversal
|
CVE-2026-31913
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3525
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hookandhook WP Courses LMS wp-courses allows DOM-Based XSS.This issue affects WP Courses LMS: fro…
|
CWE-79
Cross-site Scripting
|
CVE-2026-31914
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3526
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en hookandhook WP Courses LMS wp-courses permite XSS basado en DOM. Este problema …
|
CWE-79
Cross-site Scripting
|
CVE-2026-31914
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3527
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocommerce allows Blind…
|
CWE-89
SQL Injection
|
CVE-2026-31920
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3528
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Neutralización incorrecta de elementos especiales utilizados en un comando SQL ('inyección SQL') vulnerabilidad en Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocommerce…
|
CWE-89
SQL Injection
|
CVE-2026-31920
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3529
|
8.2 |
HIGH
Network
|
-
|
-
|
Missing Authorization vulnerability in Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.Thi…
|
CWE-862
Missing Authorization
|
CVE-2026-31921
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3530
|
8.2 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de autorización faltante en Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocommerce permite la explotación de niveles de seguridad de control de acceso con…
|
CWE-862
Missing Authorization
|
CVE-2026-31921
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|