|
4331
|
7.7 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de Limitación Incorrecta de un Nombre de Ruta a un Directorio Restringido ('Salto de Ruta') en designingmedia Energox energox permite Salto de Ruta. Este problema afecta a Energox: des…
|
CWE-22
Path Traversal
|
CVE-2026-24970
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4332
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Incorrect Privilege Assignment vulnerability in Elated-Themes Search & Go searchgo allows Privilege Escalation.This issue affects Search & Go: from n/a through <= 2.8.
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-24971
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4333
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Vulnerabilidad de Asignación de Privilegios Incorrecta en Elated-Themes Search & Go searchgo permite la escalada de privilegios. Este problema afecta a Search & Go: desde n/a hasta <= 2.8.
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-24971
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4334
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Elated-Themes Elated Listing eltd-listing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elated Listing: from n/a th…
|
CWE-862
Missing Authorization
|
CVE-2026-24972
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4335
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de Autorización faltante en Elated-Themes Elated Listing eltd-listing permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema af…
|
CWE-862
Missing Authorization
|
CVE-2026-24972
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4336
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme CitiLights noo-citilights allows Reflected XSS.This issue affects CitiLights: from n/a t…
|
CWE-79
Cross-site Scripting
|
CVE-2026-24973
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4337
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en NooTheme CitiLights noo-citilights permite XSS Reflejado. Este problema afecta a C…
|
CWE-79
Cross-site Scripting
|
CVE-2026-24973
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4338
|
8.8 |
HIGH
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in NooTheme CitiLights noo-citilights allows Object Injection.This issue affects CitiLights: from n/a through <= 3.7.1.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-24974
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4339
|
8.8 |
HIGH
Network
|
-
|
-
|
Deserialización de Datos No Confiables vulnerabilidad en NooTheme CitiLights noo-citilights permite Inyección de Objetos. Este problema afecta a CitiLights: desde n/a hasta <= 3.7.1.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-24974
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4340
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Organici Library noo-organici-library allows Reflected XSS.This issue affects Organici L…
|
CWE-79
Cross-site Scripting
|
CVE-2026-24975
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|