7.1

CVSS4.0

CVE-2026-42515 - Insecure Direct Object Reference (IDOR) Vulnerability in e-Sushrut HMIS

This vulnerability exists in e-Sushrut due to improper access control in resource access validation. An authenticated attacker could exploit this vulnerability by manipulating parameter in the API request URL to gain unauthorized access to sensitive information of patients on the targeted system.

πŸ“… Published: April 29, 2026, 8:22 a.m. πŸ”„ Last Modified: April 29, 2026, 8:22 a.m.

8.8

CVSS4.0

CVE-2026-42514 - Sensitive Data Exposure Vulnerability in e-Sushrut HMIS

This vulnerability exists in e-Sushrut due to exposure of OTPs in plaintext within API responses. A remote attacker could exploit this vulnerability by intercepting API responses containing valid OTPs. Successful exploitation of this vulnerability could allow an attacker to impersonate the target …

πŸ“… Published: April 29, 2026, 8:17 a.m. πŸ”„ Last Modified: April 29, 2026, 8:17 a.m.

8.8

CVSS4.0

CVE-2026-42513 - Authentication Bypass Vulnerability in e-Sushrut HMIS

This vulnerability exists in e-Sushrut due to improper authentication logic that relies on client-side response parameters to determine authentication status. A remote attacker could exploit this vulnerability by intercepting and modifying the server response. Successful exploitation of this vul…

πŸ“… Published: April 29, 2026, 8:13 a.m. πŸ”„ Last Modified: April 29, 2026, 8:13 a.m.

6.1

CVSS3.1

CVE-2025-10503 - Reflected Cross-Site Scripting via Authentication Endpoint in WSO2 Identity Server

The authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a lack of proper output encoding. This allows for the injection of malicious JavaScript payloads, enabling reflected cross-site scripting. An attacker can leverage this vulnerabili…

πŸ“… Published: April 29, 2026, 8:08 a.m. πŸ”„ Last Modified: April 29, 2026, 8:08 a.m.

6.5

CVSS3.1

CVE-2026-42412 - WordPress WP User Frontend plugin <= 4.3.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP User Frontend: from n/a through 4.3.1.

πŸ“… Published: April 29, 2026, 7:51 a.m. πŸ”„ Last Modified: April 29, 2026, 7:51 a.m.

7.3

CVSS3.1

CVE-2026-42377 - WordPress SureForms Pro plugin <= 2.8.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in Brainstorm Force SureForms Pro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms Pro: from n/a through 2.8.0.

πŸ“… Published: April 29, 2026, 7:27 a.m. πŸ”„ Last Modified: April 29, 2026, 7:27 a.m.

6.9

CVSS4.0

CVE-2026-21023 -

Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local attackers to modify the installation restriction of specific application.

πŸ“… Published: April 29, 2026, 4:46 a.m. πŸ”„ Last Modified: April 29, 2026, 4:46 a.m.

7.1

CVSS3.1

CVE-2026-35155 -

Dell iDRAC10, versions 1.20.70.50 and 1.30.05.10, contains an Insufficiently Protected Credentials vulnerability. A race condition vulnerability exists that could allow an authenticated low‑privileged attacker to gain elevated access.

πŸ“… Published: April 29, 2026, 3:50 a.m. πŸ”„ Last Modified: April 29, 2026, 3:50 a.m.

4.3

CVSS3.1

CVE-2026-23773 -

Dell Disk Library for Mainframe, version(s) DLm 8700/2700 contain(s) a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.

πŸ“… Published: April 29, 2026, 3:39 a.m. πŸ”„ Last Modified: April 29, 2026, 3:39 a.m.

7.2

CVSS3.1

CVE-2026-42615 -

GCHQ CyberChef before 11.0.0 allows XSS via Show Base64 offsets, as demonstrated by the /#recipe=Show_Base64_offsets('%3Cscript substring.

πŸ“… Published: April 29, 2026, 2:55 a.m. πŸ”„ Last Modified: April 29, 2026, 2:56 a.m.
Total resulsts: 347066
Page 1 of 34,707
Β» next page
Filters