9.8

CVSS3.1

CVE-2026-36234 -

itsourcecode Online Student Enrollment System v1.0 is vulnerable to SQL Injection in newCourse.php via the 'coursename' parameter.

πŸ“… Published: April 10, 2026, midnight πŸ”„ Last Modified: April 14, 2026, 5:40 p.m.

8.8

CVSS3.1

CVE-2026-23780 -

An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in the MFT API's debug interface allows an authenticated attacker to inject malicious queries due to improper input validation and unsafe dynamic SQL handling. Successful exploitation can enable arbitr…

πŸ“… Published: April 10, 2026, midnight πŸ”„ Last Modified: April 14, 2026, 4:36 p.m.

6.1

CVSS3.1

CVE-2026-31262 - Cross‑Site Scripting in Altenar Sportsbook Platform 2.0 Allowing Remote Code Execution

Cross Site Scripting vulnerability in Altenar Sportsbook Software Platform (SB2) v.2.0 allows a remote attacker to obtain sensitive information and execute arbitrary code via the URL parameter

πŸ“… Published: April 10, 2026, midnight πŸ”„ Last Modified: April 14, 2026, 3:16 p.m.

9.8

CVSS3.1

CVE-2025-44560 -

owntone-server 2ca10d9 is vulnerable to Buffer Overflow due to lack of recursive checking.

πŸ“… Published: April 10, 2026, midnight πŸ”„ Last Modified: April 14, 2026, 4:39 p.m.

9.8

CVSS3.1

CVE-2026-36236 -

SourceCodester Engineers Online Portal v1.0 is vulnerable to SQL Injection in update_password.php via the new_password parameter.

πŸ“… Published: April 10, 2026, midnight πŸ”„ Last Modified: April 14, 2026, 5:42 p.m.

9.8

CVSS3.1

CVE-2026-29861 -

PHP-MYSQL-User-Login-System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at login.php.

πŸ“… Published: April 10, 2026, midnight πŸ”„ Last Modified: April 14, 2026, 4:36 p.m.

9.8

CVSS3.1

CVE-2026-36233 -

A SQL injection vulnerability was found in the assignInstructorSubjects.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that attackers can inject malicious code via the parameter "subjcode" and use it directly in SQL queries without the need for appropri…

πŸ“… Published: April 10, 2026, midnight πŸ”„ Last Modified: April 14, 2026, 5:40 p.m.

5.4

CVSS3.1

CVE-2026-40212 -

OpenStack Skyline before 5.0.1, 6.0.0, and 7.0.0 has a DOM-based Cross-Site Scripting (XSS) vulnerability in the console because document.write is used unsafely, which is relevant in scenarios where administrators use the console web interface to view instance console logs.

πŸ“… Published: April 10, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 12:51 p.m.

8.1

CVSS3.1

CVE-2026-40200 - musl: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption i…

An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 32-bit platforms (or…

πŸ“… Published: April 10, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 3:02 p.m.

9.8

CVSS3.1

CVE-2026-23781 -

An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A set of default debug user credentials is hardcoded in cleartext within the application package. If left unchanged, these credentials can be easily obtained and may allow unauthorized access to the MFT API debug interface.

πŸ“… Published: April 10, 2026, midnight πŸ”„ Last Modified: April 14, 2026, 4:37 p.m.
Total resulsts: 344690
Page 101 of 34,469
Β« previous page Β» next page
Filters