|
3911
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad por falta de autorización en Anton Voytenko Petitioner petitioner permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta…
|
CWE-862
Missing Authorization
|
CVE-2026-32514
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3912
|
7.5 |
HIGH
Network
|
-
|
-
|
Missing Authorization vulnerability in kamleshyadav Miraculous miraculous allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Miraculous: from n/a through < 2.1…
|
CWE-862
Missing Authorization
|
CVE-2026-32515
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3913
|
7.5 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de autorización faltante en kamleshyadav Miraculous miraculous permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a …
|
CWE-862
Missing Authorization
|
CVE-2026-32515
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3914
|
8.5 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Miraculous Core Plugin miraculouscore allows Blind SQL Injection.This issue affects …
|
CWE-89
SQL Injection
|
CVE-2026-32516
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3915
|
8.5 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de Elementos Especiales utilizados en un Comando SQL ('inyección SQL') vulnerabilidad en kamleshyadav Miraculous Core Plugin miraculouscore permite inyección SQL a ciegas. E…
|
CWE-89
SQL Injection
|
CVE-2026-32516
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3916
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kleor Contact Manager contact-manager allows Reflected XSS.This issue affects Contact Manager: fr…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32517
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3917
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en Kleor Contact Manager contact-manager permite XSS Reflejado. Este problema afec…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32517
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3918
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in imithemes Gaea gaea allows Reflected XSS.This issue affects Gaea: from n/a through < 3.8.
|
CWE-79
Cross-site Scripting
|
CVE-2026-32518
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3919
|
7.1 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de Neutralización Inadecuada de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') en imithemes Gaea gaea permite XSS Reflejado. Este problema afecta a Gaea: desd…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32518
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3920
|
9.0 |
CRITICAL
Network
|
-
|
-
|
Incorrect Privilege Assignment vulnerability in Bit Apps Bit SMTP bit-smtp allows Privilege Escalation.This issue affects Bit SMTP: from n/a through <= 1.2.2.
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-32519
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|