4.8

CVSS3.1

CVE-2026-25595 - InvoicePlane has Stored XSS via Invoice Number in Invoice View and Dashboard

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability exists in InvoicePlane 1.7.0 via the Invoice Number field. An authenticated administrator can inject malicious JavaScript that executes when any admi…

📅 Published: Feb. 18, 2026, 10:52 p.m. 🔄 Last Modified: Feb. 20, 2026, 5:07 p.m.

4.8

CVSS3.1

CVE-2026-25594 - InvoicePlane has Stored XSS via Family Name in Product Form

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability exists in InvoicePlane 1.7.0 via the Family Name field. The `family_name` value is rendered without HTML encoding inside the family dropdown on the p…

📅 Published: Feb. 18, 2026, 10:50 p.m. 🔄 Last Modified: Feb. 20, 2026, 5:07 p.m.

9.1

CVSS3.1

CVE-2026-25548 - InvoicePlane Vulnerable to Remote Code Execution via Local File Inclusion and Log Poisoning

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A critical Remote Code Execution (RCE) vulnerability exists in InvoicePlane 1.7.0 through a chained Local File Inclusion (LFI) and Log Poisoning attack. An authenticated administrator can execute arb…

📅 Published: Feb. 18, 2026, 10:49 p.m. 🔄 Last Modified: Feb. 20, 2026, 6:45 p.m.

5.7

CVSS3.1

CVE-2026-24745 - InvoicePlane has a Stored Cross-Site Scripting (XSS) issue

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability occurs in the upload Login Logo functions of InvoicePlane version 1.7.0. In the Upload Login Logo, the application allows uploading svg files. Althou…

📅 Published: Feb. 18, 2026, 10:47 p.m. 🔄 Last Modified: Feb. 20, 2026, 6:45 p.m.

5.3

CVSS4.0

CVE-2026-2682 - Tsinghua Unigroup Electronic Archives System prinReport.html sql injection

A vulnerability has been found in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). Impacted is an unknown function of the file /mine/PublicReport/prinReport.html?token=java. Such manipulation of the argument comid leads to sql injection. The attack can be launched remotely. The…

📅 Published: Feb. 18, 2026, 10:32 p.m. 🔄 Last Modified: March 3, 2026, 4:57 p.m.

5.3

CVSS4.0

CVE-2025-12812 - Cloud Suite and Privilege Access Service – SQL Injection

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Delinea Inc. Cloud Suite and Privileged Access Service. Remediation: This issue is fixed in Cloud Suite: 25.1

📅 Published: Feb. 18, 2026, 10:10 p.m. 🔄 Last Modified: Feb. 19, 2026, 4:09 p.m.

6.9

CVSS4.0

CVE-2025-12811 - Cloud Suite and Privilege Access Service– HTTP request smuggling vulnerability

Improper Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in Delinea Inc. Cloud Suite and Privileged Access Service. If you're not using the latest Server Suite agents, this fix requires that you upgrade to Server Suite 2023.1 (agent 6.0.1) or later. * If you cannot upgrad…

📅 Published: Feb. 18, 2026, 10:08 p.m. 🔄 Last Modified: Feb. 19, 2026, 4:04 p.m.

5.3

CVSS4.0

CVE-2026-2676 - GoogTech sms-ssm API LoginInterceptor.java preHandle improper authorization

A weakness has been identified in GoogTech sms-ssm up to e8534c766fd13f5f94c01dab475d75f286918a8d. Affected by this issue is the function preHandle of the file LoginInterceptor.java of the component API Interface. Executing a manipulation can lead to improper authorization. The attack may be perfor…

📅 Published: Feb. 18, 2026, 10:02 p.m. 🔄 Last Modified: Feb. 23, 2026, 10:25 a.m.

8.7

CVSS4.0

CVE-2019-25401 - Bematech Printer MP-4200 TH Denial of Service

Bematech (formerly Logic Controls, now Elgin) MP-4200 TH printer contains a denial of service vulnerability in the admin configuration page. Remote attackers can send crafted POST requests with malformed 'admin' and 'person' parameters to crash the printer's web service, causing a denial of service…

📅 Published: Feb. 18, 2026, 9:55 p.m. 🔄 Last Modified: Feb. 19, 2026, 8:08 p.m.

8.4

CVSS4.0

CVE-2019-25365 - ChaosPro 2.0 - Buffer Overflow

ChaosPro 2.0 contains a buffer overflow vulnerability in the configuration file path handling that allows attackers to execute arbitrary code by overwriting the Structured Exception Handler. Attackers can craft a malicious configuration file with carefully constructed payload to overwrite memory an…

📅 Published: Feb. 18, 2026, 9:55 p.m. 🔄 Last Modified: Feb. 19, 2026, 8:08 p.m.
Total resulsts: 343975
Page 1063 of 34,398
« previous page » next page
Filters