Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 10 April 2026

RSS

146 vulnerabilities published on 10 April 2026

Severity:
JeecgBoot 3.9.1 - Unauthorized Access to Announcement System
CVE-2026-5999
A vulnerability in JeecgBoot's announcement system can allow an attacker to access unauthorized areas. This could potentially lead to sensitive information being viewed or modified without permission....
5.3
wolfSSL TLS 1.3 PQC KeyShare Processing Can Leak Sensitive Data
CVE-2026-5460
The wolfSSL TLS 1.3 implementation for post-quantum cryptography has a bug that allows sensitive data to be leaked. This is a security risk because it could potentially expose confidential information...
6.3
wolfSSL: Experimental Certificate Parsing Problem
CVE-2026-5393
A specific input can cause wolfSSL to access memory it shouldn't. When using wolfSSL with certain experimental features enabled, a crafted certificate can cause the software to accidentally read memor...
6.3
Royal WordPress Backup & Restore Plugin: Admin Clickjacking Attack Possible
CVE-2026-4305
The Royal WordPress Backup & Restore Plugin is at risk of being exploited if an administrator is tricked into clicking on a malicious link. Attackers could inject malicious scripts into the plugin's i...
6.1
WP-Optimize Plugin Allows Untrusted Users to Access Admin Functions
CVE-2026-2712
The WP-Optimize plugin for WordPress has a security issue that lets users with basic access levels perform actions reserved for administrators, such as accessing logs, deleting files, and modifying se...
5.4
Zhayujie ChatGPT on WeChat CowAgent Allows Remote File Access
CVE-2026-5998
A critical issue has been discovered in the CowAgent component of ChatGPT on WeChat, which could allow an attacker to access files on your system. This means that a hacker could potentially access sen...
5.5
WooCommerce Customer Reviews plugin allows anyone to post reviews
CVE-2026-4664
This plugin for WooCommerce has a security weakness that lets anyone submit, modify, or inject fake reviews for any product without needing a password. This can happen because the plugin doesn't prope...
5.3
Code-projects Online Library Management System SQL Database Backup File Handler Leaks Data
CVE-2026-6000
An unknown function in the SQL Database Backup File Handler of Code-projects Online Library Management System 1.0 can leak sensitive information. This could happen if an attacker remotely exploits a p...
2.1
UsersWP plugin allows attackers to delete sensitive user data
CVE-2026-4977
The UsersWP plugin for WordPress is affected by a security flaw that allows attackers with subscriber-level access to delete sensitive user information. This can happen when an attacker uses the plugi...
4.3
Unauthenticated users can alter protected files on WordPress with Download Manager
CVE-2026-4057
The Download Manager plugin for WordPress has a security flaw that allows attackers with Contributor-level access to make protected files public. This is a risk for sites using this plugin, as it coul...
4.3
Aruba HiSpeed Cache plugin for WordPress allows unauthorized settings reset
CVE-2026-1924
An attacker can trick a site administrator into resetting plugin settings to their default values without permission. This can happen if the administrator clicks on a malicious link. To fix this, upda...
4.3
OpenStack Keystone: Malicious credentials can create unauthorized AWS access
CVE-2026-33551
Certain OpenStack Keystone users with restricted permissions can create full AWS credentials, potentially allowing unauthorized access to AWS resources. This affects users who use restricted credentia...
3.5
Simple IT Discussion Forum v1.0: Cross-Site Scripting Risk in Admin User Management
CVE-2026-6003
The Simple IT Discussion Forum version 1.0 has a security issue that can allow an attacker to inject malicious code into the admin user management page. This could potentially allow an attacker to tak...
4.8
wolfSSL Misinterprets Malformed Certificate Data in Some Configurations
CVE-2026-5188
In certain cases, wolfSSL may incorrectly process X.509 certificates with intentionally malformed data. This can happen when using the default configuration. To avoid potential issues, review your wol...
2.3
wolfSSL Library: Error Parsing X.509 Certificate Dates
CVE-2026-5448
A bug in the wolfSSL library can cause a security issue if an attacker creates a specially crafted X.509 certificate. This bug only affects specific direct calls to the library, not regular operations...
2.3
Out-of-bounds read in OpenSSL's PKCS7 parsing
CVE-2026-5392
A malicious email message can cause OpenSSL to access memory it shouldn't, potentially leading to security issues. This issue affects OpenSSL's ability to properly handle certain types of encrypted em...
2.3
MINI-qx6q-mhrm-6369
MINI-qx6q-mhrm-6369
Adobe Flash Player allows remote attackers to execute arbitrary code
MINI-prfw-xfc3-7hpc
Adobe Flash Player has a security issue that could allow hackers to take control of your computer if you visit a malicious website. This is a serious issue, as it could lead to unauthorized access to ...
Adobe Acrobat and Reader: Malicious PDFs Can Crash or Execute Code
MINI-vprp-mgc5-3wcr
Adobe Acrobat and Adobe Reader can be tricked into crashing or executing malicious code if a specially crafted PDF is opened. This can lead to a denial of service or potentially allow an attacker to g...
MINI-p8qq-w72v-v5xm
MINI-p8qq-w72v-v5xm
MINI-m8wr-fjv5-v2v6
MINI-m8wr-fjv5-v2v6
MINI-jvjx-f2pq-hfm7
MINI-jvjx-f2pq-hfm7
MINI-mhjh-p4r7-vrwc
MINI-mhjh-p4r7-vrwc
MINI-m9cp-jr9g-pm66
MINI-m9cp-jr9g-pm66
MINI-jr72-cf64-5f3v
MINI-jr72-cf64-5f3v