5.3

CVSS4.0

CVE-2026-5533 - badlogic pi-mono SVG Artifact SvgArtifact.ts cross site scripting

A vulnerability was determined in badlogic pi-mono 0.58.4. The impacted element is an unknown function of the file packages/web-ui/src/tools/artifacts/SvgArtifact.ts of the component SVG Artifact Handler. This manipulation causes cross site scripting. Remote exploitation of the attack is possible. …

📅 Published: April 5, 2026, 1:30 a.m. 🔄 Last Modified: April 5, 2026, 1:30 a.m.

5.3

CVSS4.0

CVE-2026-5532 - ScrapeGraphAI scrapegraph-ai GenerateCodeNode generate_code_node.py create_sandbox_and_execute os c…

A vulnerability was found in ScrapeGraphAI scrapegraph-ai up to 1.74.0. The affected element is the function create_sandbox_and_execute of the file scrapegraphai/nodes/generate_code_node.py of the component GenerateCodeNode Component. The manipulation results in os command injection. The attack may…

📅 Published: April 5, 2026, 1:15 a.m. 🔄 Last Modified: April 5, 2026, 1:15 a.m.

6.9

CVSS4.0

CVE-2026-5531 - SourceCodester Student Result Management System HTTP GET Request login_credentials.txt cleartext st…

A vulnerability has been found in SourceCodester Student Result Management System 1.0. Impacted is an unknown function of the file /login_credentials.txt of the component HTTP GET Request Handler. The manipulation leads to cleartext storage in a file or on disk. The attack may be initiated remotely…

📅 Published: April 5, 2026, 1 a.m. 🔄 Last Modified: April 5, 2026, 1 a.m.

5.3

CVSS4.0

CVE-2026-5530 - Ollama Model Pull API download.go server-side request forgery

A flaw has been found in Ollama up to 18.1. This issue affects some unknown processing of the file server/download.go of the component Model Pull API. Executing a manipulation can lead to server-side request forgery. The attack can be launched remotely. The vendor was contacted early about this dis…

📅 Published: April 5, 2026, 12:30 a.m. 🔄 Last Modified: April 5, 2026, 12:30 a.m.

5.3

CVSS4.0

CVE-2026-5529 - Dromara lamp-cloud DefUserController pageUser improper authorization

A vulnerability was detected in Dromara lamp-cloud up to 5.8.1. This vulnerability affects the function pageUser of the file /defUser/pageUser of the component DefUserController. Performing a manipulation results in improper authorization. The attack can be initiated remotely. The exploit is now pu…

📅 Published: April 5, 2026, 12:15 a.m. 🔄 Last Modified: April 5, 2026, 12:15 a.m.
Load More Vulnerability
avatar

Mehmet Ince

@mdisec

CVE stats coming here

avatar

Nuri Çilengir

@ncilengir

CVE stats coming here

avatar

@aydinnyunus

CVE stats coming here

avatar

Onurcan Genç

@onurcangnc

CVE stats coming here

avatar

Seyit Sigirci

@h3xecute

CVE stats coming here

avatar

Ali İltizar

@iltosec

CVE stats coming here

avatar

@b3rsec

CVE stats coming here

avatar

@furkank

CVE stats coming here

avatar

kutaysec

@kutaysec

CVE stats coming here