|
4081
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Se ha identificado una debilidad en Free5GC 4.1.0. Afecta a la función HandleRegistrationComplete del archivo internal/gmm/handler.go del componente AMF. La ejecución de una manipulación puede conduc…
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2026-4531
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4082
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the `jsonText` block attribute in all versions up to, an…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3427
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4083
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin Yoast SEO – Advanced SEO con guía en tiempo real e IA integrada para WordPress es vulnerable a cross-site scripting almacenado a través del atributo de bloque 'jsonText' en todas las versio…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3427
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4084
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was found in Acrel Environmental Monitoring Cloud Platform 1.1.0. This issue affects some unknown processing. Performing a manipulation results in unrestricted upload. The attack may …
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-4536
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4085
|
7.3 |
HIGH
Network
|
-
|
-
|
Se encontró una vulnerabilidad en Acrel Environmental Monitoring Cloud Platform 1.1.0. Este problema afecta algún procesamiento desconocido. Realizar una manipulación resulta en una carga sin restric…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-4536
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4086
|
8.8 |
HIGH
Network
|
-
|
-
|
The 'The Ultimate WordPress Toolkit – WP Extended' plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.4. This is due to the `isDashboardOrProfileRequ…
|
CWE-269
Improper Privilege Management
|
CVE-2026-4314
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4087
|
8.8 |
HIGH
Network
|
-
|
-
|
El plugin 'The Ultimate WordPress Toolkit – WP Extended' para WordPress es vulnerable a escalada de privilegios en todas las versiones hasta la 3.2.4, inclusive. Esto se debe a que el método `isDashb…
|
CWE-269
Improper Privilege Management
|
CVE-2026-4314
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4088
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in Cudy TR1200 R46-2.4.15-20250721-164017. Impacted is the function action_ipsec_conn of the file /usr/bin/lib/lua/luci/controller/ipsec.lua. Executing a manipulation c…
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-4537
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4089
|
4.7 |
MEDIUM
Network
|
-
|
-
|
Se determinó una vulnerabilidad en Cudy TR1200 R46-2.4.15-20250721-164017. Se ve afectada la función action_ipsec_conn del archivo /usr/bin/lib/lua/luci/controller/ipsec.lua. La ejecución de una mani…
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-4537
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4090
|
3.3 |
LOW
Local
|
-
|
-
|
A security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular e…
|
CWE-400 CWE-1333
Uncontrolled Resource Consumption Inefficient Regular Expression Complexity
|
CVE-2026-4539
|
2026-04-25 01:32 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|