9.3

CVSS4.0

CVE-2026-3422 - e-Excellence|U-Office Force - Insecure Deserialization

U-Office Force developed by e-Excellence has a Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted serialized content.

📅 Published: March 2, 2026, 6:24 a.m. 🔄 Last Modified: March 2, 2026, 6:24 a.m.

5.3

CVSS4.0

CVE-2025-15597 - Dataease SQLBot API Endpoint assistant.py access control

A vulnerability has been found in Dataease SQLBot up to 1.4.0. This affects an unknown function of the file backend/apps/system/api/assistant.py of the component API Endpoint. Such manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been dis…

📅 Published: March 2, 2026, 6:16 a.m. 🔄 Last Modified: March 2, 2026, 6:16 a.m.

9.3

CVSS4.0

CVE-2026-3000 - Changing|IDExpert Windows Logon Agent - Remote Code Execution

IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary DLL files from a remote source and execute them.

📅 Published: March 2, 2026, 6:03 a.m. 🔄 Last Modified: March 2, 2026, 6:03 a.m.

6.9

CVSS4.0

CVE-2026-3413 - itsourcecode University Management System admin_single_student.php sql injection

A flaw has been found in itsourcecode University Management System 1.0. This vulnerability affects unknown code of the file /admin_single_student.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may…

📅 Published: March 2, 2026, 6:02 a.m. 🔄 Last Modified: March 2, 2026, 6:02 a.m.

9.3

CVSS4.0

CVE-2026-2999 - Changing|IDExpert Windows Logon Agent - Remote Code Execution

IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary executable files from a remote source and execute them.

📅 Published: March 2, 2026, 5:59 a.m. 🔄 Last Modified: March 2, 2026, 5:59 a.m.

5.3

CVSS4.0

CVE-2026-3412 - itsourcecode University Management System att_single_view.php cross site scripting

A vulnerability was detected in itsourcecode University Management System 1.0. This affects an unknown part of the file /att_single_view.php. The manipulation of the argument dt results in cross site scripting. The attack can be executed remotely. The exploit is now public and may be used.

📅 Published: March 2, 2026, 5:32 a.m. 🔄 Last Modified: March 2, 2026, 5:32 a.m.

6.9

CVSS4.0

CVE-2026-3411 - itsourcecode University Management System admin_single_student_update.php sql injection

A security vulnerability has been detected in itsourcecode University Management System 1.0. Affected by this issue is some unknown functionality of the file /admin_single_student_update.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. …

📅 Published: March 2, 2026, 5:02 a.m. 🔄 Last Modified: March 2, 2026, 5:02 a.m.

6.9

CVSS4.0

CVE-2026-3410 - itsourcecode Society Management System check_studid.php sql injection

A weakness has been identified in itsourcecode Society Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/check_studid.php. Executing a manipulation of the argument student_id can lead to sql injection. The attack may be launched remotely. The explo…

📅 Published: March 2, 2026, 4:32 a.m. 🔄 Last Modified: March 2, 2026, 4:32 a.m.

6.9

CVSS4.0

CVE-2026-3409 - eosphoros-ai db-gpt Flow Import Endpoint import importlib.machinery.SourceFileLoader.exec_module co…

A security flaw has been discovered in eosphoros-ai db-gpt 0.7.5. Affected is the function importlib.machinery.SourceFileLoader.exec_module of the file /api/v1/serve/awel/flow/import of the component Flow Import Endpoint. Performing a manipulation as part of File results in code injection. The atta…

📅 Published: March 2, 2026, 4:02 a.m. 🔄 Last Modified: March 2, 2026, 4:02 a.m.

5.3

CVSS4.0

CVE-2026-3408 - Open Babel CDXML File atom.cpp GetExplicitValence null pointer dereference

A vulnerability was identified in Open Babel up to 3.1.1. This impacts the function OBAtom::GetExplicitValence of the file isrc/atom.cpp of the component CDXML File Handler. Such manipulation leads to null pointer dereference. The attack can be launched remotely. The exploit is publicly available a…

📅 Published: March 2, 2026, 3:32 a.m. 🔄 Last Modified: March 2, 2026, 3:32 a.m.
Total resulsts: 335227
Page 1 of 33,523
» next page
Filters