|
4351
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en NooTheme Visionary Core noo-visionary-core permite XSS Reflejado. Este problema…
|
CWE-79
Cross-site Scripting
|
CVE-2026-24980
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4352
|
8.8 |
HIGH
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in NooTheme Visionary Core noo-visionary-core allows Object Injection.This issue affects Visionary Core: from n/a through <= 1.4.9.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-24981
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4353
|
8.8 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en NooTheme Visionary Core noo-visionary-core permite la inyección de objetos. Este problema afecta a Visionary Core: desde n/a hasta <= 1.…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-24981
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4354
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UpSolution UpSolution Core us-core allows Reflected XSS.This issue affects UpSolution Core: from …
|
CWE-79
Cross-site Scripting
|
CVE-2026-24983
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4355
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en UpSolution UpSolution Core us-core permite XSS Reflejado. Este problema afecta …
|
CWE-79
Cross-site Scripting
|
CVE-2026-24983
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4356
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in activity-log.com WP System Log winterlock allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP System Log: from n/a thr…
|
CWE-862
Missing Authorization
|
CVE-2026-24987
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4357
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de autorización faltante en activity-log.com WP System Log winterlock permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema af…
|
CWE-862
Missing Authorization
|
CVE-2026-24987
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4358
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Object Injection.This issue affects SUMO Affiliates Pro: from n/a through < 11.4.0.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-24989
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4359
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en FantasticPlugins SUMO Affiliates Pro affs permite la inyección de objetos. Este problema afecta a SUMO Affiliates Pro: desde n/a hasta <…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-24989
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4360
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced WooCommerce Product Sales Reporting webd-woocommerce-advanced-reporting-statis…
|
CWE-89
SQL Injection
|
CVE-2026-24993
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|