|
4001
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Object Injection.This issue affects EventPrime: from n/a through <= 4.2.8.0.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-24378
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4002
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en Metagauss EventPrime eventprime-event-calendar-management permite la inyección de objetos. Este problema afecta a EventPrime: desde n/a has…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-24378
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4003
|
7.5 |
HIGH
Network
|
-
|
-
|
Missing Authorization vulnerability in wproyal News Magazine X news-magazine-x allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects News Magazine X: from n/a thr…
|
CWE-862
Missing Authorization
|
CVE-2026-24382
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4004
|
7.5 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de autorización faltante en wproyal News Magazine X news-magazine-x permite explotar niveles de seguridad de control de acceso incorrectamente configurados. Este problema afecta a News…
|
CWE-862
Missing Authorization
|
CVE-2026-24382
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4005
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeMakers Car Dealer cardealer allows Reflected XSS.This issue affects Car Dealer: from n/a thr…
|
CWE-79
Cross-site Scripting
|
CVE-2026-24391
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4006
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en ThemeMakers Car Dealer cardealer permite XSS Reflejado. Este problema afecta a …
|
CWE-79
Cross-site Scripting
|
CVE-2026-24391
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4007
|
6.4 |
MEDIUM
Network
|
-
|
-
|
Server-Side Request Forgery (SSRF) vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Server Side Request Forgery.This issue affects Contest Gallery: …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-24964
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4008
|
6.4 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de falsificación de petición del lado del servidor (SSRF) en Wasiliy Strecker / desarrollador de ContestGallery Contest Gallery contest-gallery permite la falsificación de petición del…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-24964
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4009
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Incorrect Privilege Assignment vulnerability in Xagio SEO Xagio SEO xagio-seo allows Privilege Escalation.This issue affects Xagio SEO: from n/a through <= 7.1.0.30.
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-24968
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4010
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Vulnerabilidad de Asignación Incorrecta de Privilegios en Xagio SEO Xagio SEO xagio-seo permite la escalada de privilegios. Este problema afecta a Xagio SEO: desde n/a hasta <= 7.1.0.30.
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-24968
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|