Overview
- timstrifler
- Exclusive Addons for Elementor
13 Mar 2024
Published
01 Aug 2024
Updated
CVSS v3.1
MEDIUM (6.4)
EPSS
6.68%
KEV
Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via data attribute in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Statistics
- 1 Post
Last activity: 20 hours ago
Bluesky
Overview
- rustdesk-client
- RustDesk Client
- rustdesk-client
05 Mar 2026
Published
05 Mar 2026
Updated
CVSS v4.0
HIGH (8.2)
EPSS
0.02%
KEV
Description
Insufficient Verification of Data Authenticity, Improper Handling of Exceptional Conditions vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Heartbeat sync loop, strategy processing modules) allows Protocol Manipulation. This vulnerability is associated with program files src/hbbs_http/sync.Rs and program routines stop-service handler in heartbeat loop.
This issue affects RustDesk Client: through 1.4.5.
Statistics
- 1 Post
Last activity: 23 hours ago
Overview
- Red Hat
- Red Hat Enterprise Linux 10
- libxml2
02 Feb 2026
Published
17 Feb 2026
Updated
CVSS
Pending
EPSS
0.02%
KEV
Description
A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command execution but fails to free the allocated buffer. Repeating this action causes memory to continuously accumulate. Over time, this can exhaust system memory and terminate the xmllint process, creating a denial-of-service condition on the local system.
Statistics
- 1 Post
Last activity: 13 hours ago
Overview
- Doditsolutions
- Homey BNB (Airbnb Clone Script)
27 Feb 2026
Published
27 Feb 2026
Updated
CVSS v4.0
HIGH (8.8)
EPSS
0.11%
KEV
Description
Homey BNB V4 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the hosting_id parameter. Attackers can send GET requests to the rooms/ajax_refresh_subtotal endpoint with malicious hosting_id values to extract sensitive database information or cause denial of service.
Statistics
- 1 Post
Last activity: 23 hours ago
Overview
- SimStudioAI
- sim
02 Mar 2026
Published
02 Mar 2026
Updated
CVSS v3.1
CRITICAL (9.8)
EPSS
0.07%
KEV
Description
On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller without authentication or host restrictions. An attacker can leverage these endpoints to connect to any reachable MongoDB instance and perform unauthorized operations including reading, modifying, and deleting data.
Statistics
- 1 Post
Last activity: 19 hours ago
Overview
Description
A flaw has been found in Tenda A21 1.0.0.0. Impacted is the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. Executing a manipulation of the argument ssid can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used.
Statistics
- 1 Post
Last activity: 15 hours ago
Overview
- Python Software Foundation
- CPython
20 Jan 2026
Published
03 Mar 2026
Updated
CVSS v4.0
MEDIUM (5.7)
EPSS
0.04%
KEV
Description
When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.
Statistics
- 1 Post
Last activity: 13 hours ago
Overview
- Go standard library
- crypto/x509
- crypto/x509
06 Mar 2026
Published
06 Mar 2026
Updated
CVSS
Pending
EPSS
0.01%
KEV
Description
When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.
Statistics
- 1 Post
Last activity: 13 hours ago
Overview
- Microsoft
- Windows 10 Version 1607
13 Jan 2026
Published
26 Feb 2026
Updated
CVSS v3.1
HIGH (7.8)
EPSS
0.02%
KEV
Description
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Statistics
- 1 Post
Last activity: 7 hours ago
Overview
- getsentry
- sentry
21 Feb 2026
Published
24 Feb 2026
Updated
CVSS v3.1
CRITICAL (9.1)
EPSS
0.05%
KEV
Description
Sentry is a developer-first error tracking and performance monitoring tool. Versions 21.12.0 through 26.1.0 have a critical vulnerability in its SAML SSO implementation which allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. Self-hosted users are only at risk if the following criteria is met: ore than one organizations are configured (SENTRY_SINGLE_ORGANIZATION = True), or malicious user has existing access and permissions to modify SSO settings for another organization in a multo-organization instance. This issue has been fixed in version 26.2.0. To workaround this issue, implement user account-based two-factor authentication to prevent an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account.
Statistics
- 1 Post
Last activity: 8 hours ago