6.9

CVSS4.0

CVE-2026-6490 - QueryMine sms GET Request Parameter deletecourse.php sql injection

A weakness has been identified in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. Impacted is an unknown function of the file admin/deletecourse.php of the component GET Request Parameter Handler. This manipulation of the argument ID causes sql injection. The attack may be initiated r…

πŸ“… Published: April 17, 2026, 1:15 p.m. πŸ”„ Last Modified: April 18, 2026, 9:30 a.m.

5.3

CVSS4.0

CVE-2026-6489 - QueryMine sms Background Management addteacher.php unrestricted upload

A security flaw has been discovered in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. This issue affects some unknown processing of the file admin/addteacher.php of the component Background Management Page. The manipulation of the argument image results in unrestricted upload. The at…

πŸ“… Published: April 17, 2026, 1 p.m. πŸ”„ Last Modified: April 17, 2026, 8:35 p.m.

5.3

CVSS4.0

CVE-2026-6488 - QueryMine sms GET Request Parameter editcourse.php sql injection

A vulnerability was identified in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. This vulnerability affects unknown code of the file admin/editcourse.php of the component GET Request Parameter Handler. The manipulation of the argument ID leads to sql injection. The attack can be init…

πŸ“… Published: April 17, 2026, 12:45 p.m. πŸ”„ Last Modified: April 18, 2026, 9:30 a.m.

5.3

CVSS4.0

CVE-2026-6487 - Qihui jtbc5 CMS Code Endpoint manage.php path traversal

A flaw has been found in Qihui jtbc5 CMS 5.0.3.6. Affected is an unknown function of the file /dev/code/common/diplomat/manage.php of the component Code Endpoint. This manipulation of the argument path causes path traversal. The attack is possible to be carried out remotely. The exploit has been pu…

πŸ“… Published: April 17, 2026, 12:30 p.m. πŸ”„ Last Modified: April 18, 2026, 9:30 a.m.

5.1

CVSS4.0

CVE-2026-6486 - classroombookings User Display Name layout.php read cross site scripting

A vulnerability was detected in classroombookings up to 2.17.0. This impacts the function read of the file crbs-core/application/views/layout.php of the component User Display Name Handler. The manipulation of the argument displayname results in cross site scripting. The attack can be executed remo…

πŸ“… Published: April 17, 2026, 12:15 p.m. πŸ”„ Last Modified: April 18, 2026, 2:58 a.m.

4.3

CVSS3.1

CVE-2026-23777 - Remote Access Sensitive Information Exposure in Dell PowerProtect Data Domain

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain an exposure of sensitive information to an unauthorized actor vulne…

πŸ“… Published: April 17, 2026, 11:52 a.m. πŸ”„ Last Modified: April 18, 2026, 9:30 a.m.

5.9

CVSS3.1

CVE-2026-28263 -

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain a cross-site Scripting vulnerability. A high privileged attacker wi…

πŸ“… Published: April 17, 2026, 11:44 a.m. πŸ”„ Last Modified: April 18, 2026, 2:56 a.m.

7.5

CVSS3.1

CVE-2026-6507 - Dnsmasq: dnsmasq: denial of service due to out-of-bounds write in dhcp bootreply processing

A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds write vulnerability by sending a specially crafted BOOTREPLY (Bootstrap Protocol Reply) packet to a dnsmasq server configured with the `--dhcp-split-relay` option. This can lead to memory corruption, causing the dnsmasq d…

πŸ“… Published: April 17, 2026, 11:37 a.m. πŸ”„ Last Modified: April 18, 2026, 9:30 a.m.

6.2

CVSS3.1

CVE-2025-46606 -

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper restriction of excessive authentication attempts vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading…

πŸ“… Published: April 17, 2026, 11:36 a.m. πŸ”„ Last Modified: April 18, 2026, 3:55 a.m.

6.2

CVSS3.1

CVE-2025-46605 -

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain a session fixation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.

πŸ“… Published: April 17, 2026, 11:27 a.m. πŸ”„ Last Modified: April 18, 2026, 3:55 a.m.
Total resulsts: 346087
Page 107 of 34,609
Β« previous page Β» next page
Filters