🛡️ مركز معلومات الثغرات
قاعدة بيانات الثغرات والتهديدات الأمنية المحدّثة
| المعرّف | الخطورة | CVSS | الوصف | الحالة | النشر |
|---|---|---|---|---|---|
| CVE-2026-40459 | مرتفع | 8.8 |
PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can inject crafted LDAP synt…
|
— | أبريل 17, 2026 |
| CVE-2026-40516 | مرتفع | 8.3 |
OpenHarness before commit bd4df81 contains a server-side request forgery vulnerability in the web_fetch and web_search t…
|
— | أبريل 17, 2026 |
| CVE-2025-36568 | مرتفع | 7.8 |
Dell PowerProtect Data Domain BoostFS for client of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release versio…
|
— | أبريل 17, 2026 |
| CVE-2026-40515 | مرتفع | 7.5 |
OpenHarness before commit bd4df81 contains a permission bypass vulnerability that allows attackers to read sensitive fil…
|
— | أبريل 17, 2026 |
| CVE-2026-4659 | مرتفع | 7.5 |
The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Arbitrary File Read via the Repeater JSON/CSV…
|
— | أبريل 17, 2026 |
| CVE-2026-6490 | مرتفع | 7.3 |
A weakness has been identified in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. Impacted is an unknown f…
|
— | أبريل 17, 2026 |
| CVE-2026-6483 | مرتفع | 7.2 |
A vulnerability was found in Wavlink WL-WN530H4 20220721. This vulnerability affects the function strcat/snprintf of the…
|
— | أبريل 17, 2026 |
| CVE-2026-23776 | مرتفع | 7.2 |
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5,…
|
✅ Patch | أبريل 17, 2026 |
| CVE-2026-5231 | مرتفع | 7.2 |
The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_source' parameter in al…
|
— | أبريل 17, 2026 |
| CVE-2026-6421 | مرتفع | 7.0 |
A vulnerability has been found in Mobatek MobaXterm Home Edition up to 26.1. This affects an unknown part in the library…
|
— | أبريل 17, 2026 |
| CVE-2026-4817 | متوسط | 6.5 |
The MasterStudy LMS WordPress Plugin for Online Courses and Education plugin for WordPress is vulnerable to Time-based B…
|
— | أبريل 17, 2026 |
| CVE-2026-3488 | متوسط | 6.5 |
The WP Statistics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 14.1…
|
— | أبريل 17, 2026 |
| CVE-2026-6080 | متوسط | 6.5 |
The Tutor LMS plugin for WordPress is vulnerable to SQL Injection in versions up to and including 3.9.8. This is due to …
|
— | أبريل 17, 2026 |
| CVE-2026-4666 | متوسط | 6.5 |
The wpForo Forum plugin for WordPress is vulnerable to unauthorized modification of data due to the use of `extract($arg…
|
— | أبريل 17, 2026 |
| CVE-2026-2434 | متوسط | 6.4 |
The Pz-LinkCard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blogcard' shortcode attribute…
|
— | أبريل 17, 2026 |
| CVE-2026-5162 | متوسط | 6.4 |
The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed …
|
— | أبريل 17, 2026 |
| CVE-2026-6488 | متوسط | 6.3 |
A vulnerability was identified in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. This vulnerability affec…
|
— | أبريل 17, 2026 |
| CVE-2026-6497 | متوسط | 6.3 |
A vulnerability was determined in prasathmani TinyFileManager up to 2.6. Affected by this vulnerability is an unknown fu…
|
— | أبريل 17, 2026 |
| CVE-2026-6489 | متوسط | 6.3 |
A security flaw has been discovered in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. This issue affects …
|
— | أبريل 17, 2026 |
| CVE-2026-6496 | متوسط | 5.4 |
A vulnerability was found in prasathmani TinyFileManager up to 2.6. Affected is an unknown function of the file /fileman…
|
— | أبريل 17, 2026 |