|
3981
|
8.8 |
HIGH
Network
|
-
|
-
|
El plugin WP Job Portal para WordPress es vulnerable a la eliminación arbitraria de archivos debido a una validación insuficiente de la ruta de archivo en la función 'WPJOBPORTALcustomfields::removeF…
|
CWE-22
Path Traversal
|
CVE-2026-4758
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3982
|
8.8 |
HIGH
Network
|
-
|
-
|
The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6. This is due to the plugin allowing a user to update the user role through the…
|
CWE-862
Missing Authorization
|
CVE-2026-4484
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3983
|
8.8 |
HIGH
Network
|
-
|
-
|
El plugin Masteriyo LMS para WordPress es vulnerable a una escalada de privilegios en todas las versiones hasta la 2.1.6, inclusive. Esto se debe a que el plugin permite a un usuario actualizar el ro…
|
CWE-862
Missing Authorization
|
CVE-2026-4484
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3984
|
7.0 |
HIGH
Local
|
-
|
-
|
A vulnerability was detected in Enter Software Iperius Backup up to 8.7.3. Affected is an unknown function of the file C:\ProgramData\IperiusBackup\Jobs\ of the component Backup Service. Performing a…
|
CWE-377 CWE-378
Insecure Temporary File Creation of Temporary File With Insecure Permissions
|
CVE-2026-4822
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3985
|
7.0 |
HIGH
Local
|
-
|
-
|
Una vulnerabilidad fue detectada en Enter Software Iperius Backup hasta 8.7.3. Afecta a una función desconocida del archivo C:\ProgramData\IperiusBackup\Jobs\ del componente Backup Service. Realizar …
|
CWE-377 CWE-378
Insecure Temporary File Creation of Temporary File With Insecure Permissions
|
CVE-2026-4822
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3986
|
2.5 |
LOW
Local
|
-
|
-
|
A flaw has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this vulnerability is an unknown functionality of the component NTLM2 Handler. Executing a manipulation can lead to inf…
|
CWE-200 CWE-284
Information Exposure Improper Access Control
|
CVE-2026-4823
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3987
|
2.5 |
LOW
Local
|
-
|
-
|
Se ha encontrado una falla en Enter Software Iperius Backup hasta la versión 8.7.3. Afectada por esta vulnerabilidad es una funcionalidad desconocida del componente Gestor NTLM2. La ejecución de una …
|
CWE-200 CWE-284
Information Exposure Improper Access Control
|
CVE-2026-4823
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3988
|
7.0 |
HIGH
Local
|
-
|
-
|
A vulnerability has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this issue is some unknown functionality of the component Backup Job Configuration File Handler. The manipulat…
|
CWE-266 CWE-269
Incorrect Privilege Assignment Improper Privilege Management
|
CVE-2026-4824
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3989
|
3.3 |
LOW
Local
|
-
|
-
|
A weakness has been identified in Orc discount up to 3.0.1.2. This issue affects the function compile of the file markdown.c of the component Markdown Handler. This manipulation causes uncontrolled r…
|
CWE-404 CWE-674
Improper Resource Shutdown or Release Uncontrolled Recursion
|
CVE-2026-4833
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3990
|
3.5 |
LOW
Network
|
-
|
-
|
A security vulnerability has been detected in code-projects Accounting System 1.0. Impacted is an unknown function of the file /my_account/add_costumer.php of the component Web Application Interface.…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4835
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|