A vulnerability labeled as problematic has been found in CozyThemes Cozy Blocks Plugin up to 2.0.18 on WordPress. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to cross site scripting.
This vulnerability is registered as CVE-2024-50502. It is possible to launch the attack remotely. No exploit is available.
A vulnerability marked as problematic has been reported in WPXPO PostX Plugin up to 4.1.12 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2024-50443. The attack can be initiated remotely. There is not any exploit available.
A vulnerability was found in Brainstorm Force Astra Widgets Plugin up to 1.2.14 on WordPress. It has been declared as problematic. This affects an unknown part. Executing a manipulation can lead to cross site scripting.
The identification of this vulnerability is CVE-2024-50439. The attack may be launched remotely. There is no exploit available.
A vulnerability classified as problematic was found in Andy Moyle Church Admin Plugin up to 4.x on WordPress. Affected is an unknown function. The manipulation results in cross site scripting.
This vulnerability is reported as CVE-2024-50438. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
A vulnerability, which was classified as problematic, has been found in Chris Coyier CodePen Embedded Pens Shortcode Plugin up to 1.0.2 on WordPress. Affected by this vulnerability is an unknown functionality. This manipulation causes cross site scripting.
This vulnerability appears as CVE-2024-50440. The attack may be initiated remotely. There is no available exploit.
A vulnerability, which was classified as problematic, was found in CozyThemes Cozy Blocks Plugin up to 2.0.15 on WordPress. Affected by this issue is some unknown functionality. Such manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-50441. The attack may be launched remotely. There is no exploit available.
A vulnerability has been found in Merkulove Selection Lite Plugin up to 1.13 on WordPress and classified as problematic. This affects an unknown part. Performing a manipulation results in cross site scripting.
This vulnerability is known as CVE-2024-50445. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability was found in FuturioWP Futurio Extra Plugin up to 2.0.11 on WordPress and classified as problematic. This vulnerability affects unknown code. Executing a manipulation can lead to cross site scripting.
This vulnerability is handled as CVE-2024-50446. The attack can be executed remotely. There is not any exploit available.
Microsoft has deprecated and removed the Support and Recovery Assistant (SaRA) command-line utility from all in-support versions of Windows updates starting March 10. [...]
Alleged Breach of Colombia's Huila Department Government Extranet Exposes Officer Data, Municipal Offices, and Government Operations Across 8 Municipalities
A vulnerability classified as critical was found in lin-snow Ech0 up to 4.2.7. The affected element is an unknown function of the file /api/website/title of the component Endpoint. The manipulation of the argument website_url results in server-side request forgery.
This vulnerability is cataloged as CVE-2026-35037. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability classified as problematic has been found in ci4-cms-erp ci4ms 0.28.5.0/0.31.0.0. Impacted is an unknown function of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2026-35035. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability described as critical has been identified in lin-snow Ech0 up to 4.2.7. This issue affects some unknown processing of the file /api/website/title of the component Response Body Handler. Executing a manipulation can lead to server-side request forgery.
This vulnerability is tracked as CVE-2026-35036. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability marked as critical has been reported in nearform fast-jwt up to 6.0.x. This vulnerability affects unknown code. Performing a manipulation results in insufficient verification of data authenticity.
This vulnerability is identified as CVE-2026-35039. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
A vulnerability labeled as critical has been found in BerriAI litellm up to 1.82.x. This affects the function enable_jwt_auth of the component JWT/OIDC. Such manipulation leads to improper authentication.
This vulnerability is referenced as CVE-2026-35030. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
Bryan Fleming, founder of pcTattletale, was ordered to pay a $5,000 fine by a San Diego federal judge and will spend no time in prison beyond the one day he already served.