8.7

CVSS4.0

CVE-2026-6903 - Path Traversal Vulnerability in LabOne User Interface

The LabOne Web Server, backing the LabOne User Interface, contains insufficient input validation in its file access functionality. An unauthenticated attacker could exploit this vulnerability to read arbitrary files on the host system that are accessible to the operating system user running the Lab…

📅 Published: April 23, 2026, 9:45 a.m. 🔄 Last Modified: April 23, 2026, 9:45 a.m.

9.3

CVSS4.0

CVE-2026-6887 - BorG Technology Corporation|Borg SPM 2007 - SQL Injection

Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

📅 Published: April 23, 2026, 9:30 a.m. 🔄 Last Modified: April 23, 2026, 9:31 a.m.

9.3

CVSS4.0

CVE-2026-6886 - BorG Technology Corporation|Borg SPM 2007 - Authentication Bypass

Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a Authentication Bypass vulnerability, allowing unauthenticated remote attackers to log into the system as any user.

📅 Published: April 23, 2026, 9:25 a.m. 🔄 Last Modified: April 23, 2026, 9:26 a.m.

9.3

CVSS4.0

CVE-2026-6885 - BorG Technology Corporation|Borg SPM 2007 - Arbitrary File Upload

Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

📅 Published: April 23, 2026, 9:05 a.m. 🔄 Last Modified: April 23, 2026, 9:05 a.m.

5.9

CVSS3.0

CVE-2026-3960 - Remote Code Execution in h2oai/h2o-3

A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0.9 and prior. The vulnerability arises due to insufficient security controls in the parameter blacklist mechanism, which only targets MySQL JDBC driver-specific d…

📅 Published: April 23, 2026, 8:47 a.m. 🔄 Last Modified: April 23, 2026, 8:47 a.m.
Load More Vulnerability
avatar

Mehmet Ince

@mdisec

CVE stats coming here

avatar

Nuri Çilengir

@ncilengir

CVE stats coming here

avatar

@aydinnyunus

CVE stats coming here

avatar

Onurcan Genç

@onurcangnc

CVE stats coming here

avatar

Seyit Sigirci

@h3xecute

CVE stats coming here

avatar

Ali İltizar

@iltosec

CVE stats coming here

avatar

@b3rsec

CVE stats coming here

avatar

@furkank

CVE stats coming here

avatar

kutaysec

@kutaysec

CVE stats coming here