🛡️ مركز معلومات الثغرات
قاعدة بيانات الثغرات والتهديدات الأمنية المحدّثة
| المعرّف | الخطورة | CVSS | الوصف | الحالة | النشر |
|---|---|---|---|---|---|
| CVE-2026-1636 | متوسط | 6.7 |
A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allo…
|
— | أبريل 15, 2026 |
| CVE-2026-4135 | متوسط | 6.6 |
During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during ins…
|
— | أبريل 15, 2026 |
| CVE-2026-20202 | متوسط | 6.6 |
In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.26…
|
— | أبريل 15, 2026 |
| CVE-2026-20081 | متوسط | 6.5 |
Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitr…
|
— | أبريل 15, 2026 |
| CVE-2026-20078 | متوسط | 6.5 |
Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitr…
|
— | أبريل 15, 2026 |
| CVE-2026-6385 | متوسط | 6.5 |
A flaw was found in FFmpeg. A remote attacker could exploit this vulnerability by providing a specially crafted MPEG-PS/…
|
— | أبريل 15, 2026 |
| CVE-2025-15470 | متوسط | 6.5 |
The Eleganzo theme for WordPress is vulnerable to arbitrary directory deletion due to insufficient path validation in th…
|
— | أبريل 15, 2026 |
| CVE-2026-4011 | متوسط | 6.4 |
The Power Charts Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [p…
|
— | أبريل 15, 2026 |
| CVE-2026-4005 | متوسط | 6.4 |
The Coachific Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userhash' shortcode a…
|
— | أبريل 15, 2026 |
| CVE-2026-5717 | متوسط | 6.4 |
The VI: Include Post By plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_container' attr…
|
— | أبريل 15, 2026 |
| CVE-2026-3659 | متوسط | 6.4 |
The WP Circliful plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute of t…
|
— | أبريل 15, 2026 |
| CVE-2026-3998 | متوسط | 6.4 |
The WM JqMath plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' shortcode attribute of t…
|
— | أبريل 15, 2026 |
| CVE-2026-40919 | متوسط | 6.1 |
A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited…
|
— | أبريل 15, 2026 |
| CVE-2026-20059 | متوسط | 6.1 |
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote a…
|
— | أبريل 15, 2026 |
| CVE-2026-1852 | متوسط | 6.1 |
The Product Pricing Table by WooBeWoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u…
|
— | أبريل 15, 2026 |
| CVE-2026-4091 | متوسط | 6.1 |
The OPEN-BRAIN plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.…
|
— | أبريل 15, 2026 |
| CVE-2026-20170 | متوسط | 6.1 |
A vulnerability in the Desktop Agent functionality of Cisco Webex Contact Center could have allowed an unauthenticated, …
|
— | أبريل 15, 2026 |
| CVE-2026-20136 | متوسط | 6.0 |
A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PI…
|
— | أبريل 15, 2026 |
| CVE-2026-6245 | متوسط | 5.5 |
A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PA…
|
— | أبريل 15, 2026 |
| CVE-2026-20161 | متوسط | 5.5 |
A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent could allow an authenticated, local attacker with low …
|
— | أبريل 15, 2026 |