6.9

CVSS4.0

CVE-2026-2669 - Rongzhitong Visual Integrated Command and Dispatch Platform User delete access control

A vulnerability was determined in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. This impacts an unknown function of the file /dm/dispatch/user/delete of the component User Handler. This manipulation of the argument ID causes improper access controls. Remote exploitatioโ€ฆ

๐Ÿ“… Published: Feb. 18, 2026, 9:02 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 8:31 p.m.

5.7

CVSS3.1

CVE-2026-24744 - InvoicePlane has a Stored Cross-Site Scripting (XSS) issue

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability occurs in the Edit Invoices functions of InvoicePlane version 1.7.0. When editing invoices, the application does not validate user input at the `invoโ€ฆ

๐Ÿ“… Published: Feb. 18, 2026, 9:01 p.m. ๐Ÿ”„ Last Modified: Feb. 20, 2026, 7:35 p.m.

5.7

CVSS3.1

CVE-2026-24743 - InvoicePlane has a Stored Cross-Site Scripting (XSS) issue

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability occurs in the upload Invoice Logo functions of InvoicePlane version 1.7.0. The Upload Invoice Logo function allows the application to upload svg fileโ€ฆ

๐Ÿ“… Published: Feb. 18, 2026, 8:59 p.m. ๐Ÿ”„ Last Modified: Feb. 20, 2026, 6:39 p.m.

8.6

CVSS4.0

CVE-2026-27182 - Saturn Remote Mouse Server UDP Command Injection RCE

Saturn Remote Mouse Server contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending specially crafted UDP JSON frames to port 27000. Attackers on the local network can send malformed packets with unsanitized command data that the servโ€ฆ

๐Ÿ“… Published: Feb. 18, 2026, 8:59 p.m. ๐Ÿ”„ Last Modified: Feb. 19, 2026, 3:53 p.m.

4.8

CVSS4.0

CVE-2019-25400 - IPFire 2.21 Core Update 127 Multiple XSS via fwhosts.cgi

IPFire 2.21 Core Update 127 contains multiple reflected cross-site scripting vulnerabilities in the fwhosts.cgi script that allow attackers to inject malicious scripts through multiple parameters including HOSTNAME, IP, SUBNET, NETREMARK, HOSTREMARK, newhost, grp_name, remark, SRV_NAME, SRV_PORT, Sโ€ฆ

๐Ÿ“… Published: Feb. 18, 2026, 8:59 p.m. ๐Ÿ”„ Last Modified: March 5, 2026, 1:26 a.m.

5.1

CVSS4.0

CVE-2019-25399 - IPFire 2.21 Core Update 127 Stored XSS via extrahd.cgi

IPFire 2.21 Core Update 127 contains multiple stored cross-site scripting vulnerabilities in the extrahd.cgi script that allow attackers to inject malicious scripts through the FS, PATH, and UUID parameters. Attackers can submit POST requests with script payloads in these parameters to execute arbiโ€ฆ

๐Ÿ“… Published: Feb. 18, 2026, 8:59 p.m. ๐Ÿ”„ Last Modified: March 5, 2026, 1:26 a.m.

5.1

CVSS4.0

CVE-2019-25398 - IPFire 2.21 Core Update 127 Cross-Site Scripting via ovpnmain.cgi

IPFire 2.21 Core Update 127 contains multiple cross-site scripting vulnerabilities in the ovpnmain.cgi script that allow attackers to inject malicious scripts through VPN configuration parameters. Attackers can submit POST requests with script payloads in parameters like VPN_IP, DMTU, ccdname, ccdsโ€ฆ

๐Ÿ“… Published: Feb. 18, 2026, 8:59 p.m. ๐Ÿ”„ Last Modified: March 5, 2026, 1:26 a.m.

5.1

CVSS4.0

CVE-2019-25397 - IPFire 2.21 Core Update 127 Cross-Site Scripting via hosts.cgi

IPFire 2.21 Core Update 127 contains multiple reflected cross-site scripting vulnerabilities in the hosts.cgi script that allow attackers to inject malicious scripts through unvalidated parameters. Attackers can submit POST requests with script payloads in the KEY1, IP, HOST, or DOM parameters to eโ€ฆ

๐Ÿ“… Published: Feb. 18, 2026, 8:59 p.m. ๐Ÿ”„ Last Modified: March 5, 2026, 1:26 a.m.

5.1

CVSS4.0

CVE-2019-25396 - IPFire 2.21 Core Update 127 Reflected XSS via updatexlrator.cgi

IPFire 2.21 Core Update 127 contains a reflected cross-site scripting vulnerability in the updatexlrator.cgi script that allows attackers to inject malicious scripts through POST parameters. Attackers can submit crafted requests with script payloads in the MAX_DISK_USAGE or MAX_DOWNLOAD_RATE parameโ€ฆ

๐Ÿ“… Published: Feb. 18, 2026, 8:59 p.m. ๐Ÿ”„ Last Modified: March 5, 2026, 1:26 a.m.

5.7

CVSS3.1

CVE-2026-24746 - InvoicePlane has a Stored Cross-Site Scripting (XSS) issue

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability occurs in the Edit Quotes functions of InvoicePlane version 1.7.0. In the Editing Quotes function, the application does not validate user input at thโ€ฆ

๐Ÿ“… Published: Feb. 18, 2026, 8:51 p.m. ๐Ÿ”„ Last Modified: Feb. 20, 2026, 6:33 p.m.
Total resulsts: 343968
Page 1066 of 34,397
ยซ previous page ยป next page
Filters