0.0

CVE-2026-33454 - Apache Camel: Inbound Header Filter Missing in MailHeaderFilterStrategy Allows Remote Code Executio…

The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterStrategy) only filters the 'out' direction via setOutFilterStartsWith, while it does not configure the 'in' direction via setInFilterStartsWith. As a re…

📅 Published: April 27, 2026, 9:42 a.m. 🔄 Last Modified: April 27, 2026, 9:42 a.m.

0.0

CVE-2026-40022 - Apache Camel Platform HTTP Main: Authentication Bypass on Non-Root Context Paths in camel main runt…

When authentication is enabled on the Apache Camel embedded HTTP server or embedded management server (camel-platform-http-main) and a non-root context path such as /api or /admin is configured via camel.server.path or camel.management.path, the BasicAuthenticationConfigurer and JWTAuthenticationCo…

📅 Published: April 27, 2026, 9:40 a.m. 🔄 Last Modified: April 27, 2026, 9:50 a.m.

0.0

CVE-2026-40858 - Apache Camel: Camel-Infinispan: Unsafe Deserialization in Remote Aggregation Repository

The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInputFilter. An attacker who can write to the Infinispan cache used by a Camel application can inject a c…

📅 Published: April 27, 2026, 9:38 a.m. 🔄 Last Modified: April 27, 2026, 9:38 a.m.

5.1

CVSS4.0

CVE-2026-7110 - code-projects Invoice System in Laravel item cross site scripting

A flaw has been found in code-projects Invoice System in Laravel 1.0. Affected is an unknown function of the file /item. Executing a manipulation of the argument item name/description can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and …

📅 Published: April 27, 2026, 9:30 a.m. 🔄 Last Modified: April 27, 2026, 9:30 a.m.

9.8

CVSS3.1

CVE-2026-41409 - Apache MINA: CWE-502 Deserialization of Untrusted Data

The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too late after a static initializer in a class to be read might already have been executed. Affected versions are Apache MINA 2.0.0 <=…

📅 Published: April 27, 2026, 9:20 a.m. 🔄 Last Modified: April 27, 2026, 9:20 a.m.

6.9

CVSS4.0

CVE-2026-7109 - code-projects Invoice System in Laravel API Endpoint item improper authorization

A vulnerability was detected in code-projects Invoice System in Laravel 1.0. This impacts an unknown function of the file /item of the component API Endpoint. Performing a manipulation results in improper authorization. It is possible to initiate the attack remotely. The exploit is now public and m…

📅 Published: April 27, 2026, 9:15 a.m. 🔄 Last Modified: April 27, 2026, 9:15 a.m.

5.3

CVSS4.0

CVE-2026-7108 - code-projects Invoice System in Laravel cross-site request forgery

A security vulnerability has been detected in code-projects Invoice System in Laravel 1.0. This affects an unknown function. Such manipulation leads to cross-site request forgery. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

📅 Published: April 27, 2026, 9 a.m. 🔄 Last Modified: April 27, 2026, 9 a.m.

9.8

CVSS3.1

CVE-2026-41635 - Apache MINA: AbstractIoBuffer.resolveClass() null-clazz Branch Skips acceptMatchers Filter — Full O…

Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at all, bypassing the classname allowlist and allowing arbitrary code to be executed. The fix checks if the class is present in the accepted class fi…

📅 Published: April 27, 2026, 8:59 a.m. 🔄 Last Modified: April 27, 2026, 8:59 a.m.

5.3

CVSS4.0

CVE-2026-7107 - code-projects Invoice System in Laravel company unrestricted upload

A weakness has been identified in code-projects Invoice System in Laravel 1.0. The impacted element is an unknown function of the file /company. This manipulation of the argument logo causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made available …

📅 Published: April 27, 2026, 8:45 a.m. 🔄 Last Modified: April 27, 2026, 8:45 a.m.

6.3

CVSS4.0

CVE-2026-7103 - code-projects Chat System MD5 Hash update_user.php weak hash

A vulnerability was determined in code-projects Chat System 1.0. Affected is an unknown function of the file update_user.php of the component MD5 Hash Handler. This manipulation of the argument Password causes use of weak hash. The attack is possible to be carried out remotely. The attack's complex…

📅 Published: April 27, 2026, 8:30 a.m. 🔄 Last Modified: April 27, 2026, 8:30 a.m.
Total resulsts: 347725
Page 101 of 34,773
« previous page » next page
Filters