6.9

CVSS4.0

CVE-2026-6595 - ProjectsAndPrograms School Management System HTTP GET Parameter buslocation.php sql injection

A vulnerability was identified in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This vulnerability affects unknown code of the file buslocation.php of the component HTTP GET Parameter Handler. The manipulation of the argument bus_id leads to sql inject…

πŸ“… Published: April 20, 2026, 2 a.m. πŸ”„ Last Modified: April 20, 2026, 2 a.m.

6.9

CVSS4.0

CVE-2026-6594 - brikcss merge prototype pollution

A vulnerability was determined in brikcss merge up to 1.3.0. This affects an unknown part. Executing a manipulation of the argument __proto__/constructor.prototype/prototype can lead to improperly controlled modification of object prototype attributes. The attack may be performed from remote. The v…

πŸ“… Published: April 20, 2026, 1:45 a.m. πŸ”„ Last Modified: April 22, 2026, 8:22 p.m.

5.1

CVSS4.0

CVE-2026-6593 - ComfyUI View Endpoint server.py cross site scripting

A vulnerability was found in ComfyUI up to 0.13.0. Affected by this issue is some unknown functionality of the file server.py of the component View Endpoint. Performing a manipulation results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been made publi…

πŸ“… Published: April 20, 2026, 1:30 a.m. πŸ”„ Last Modified: April 20, 2026, 1:30 a.m.

5.1

CVSS4.0

CVE-2026-6592 - ComfyUI userdata Endpoint user_manager.py getuserdata cross site scripting

A vulnerability has been found in ComfyUI up to 0.13.0. Affected by this vulnerability is the function getuserdata of the file app/user_manager.py of the component userdata Endpoint. Such manipulation leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed…

πŸ“… Published: April 20, 2026, 1:15 a.m. πŸ”„ Last Modified: April 22, 2026, 8:22 p.m.

5.3

CVSS4.0

CVE-2026-6591 - ComfyUI LoadImage Node folder_paths.py folder_paths.get_annotated_filepath path traversal

A flaw has been found in ComfyUI up to 0.13.0. Affected is the function folder_paths.get_annotated_filepath of the file folder_paths.py of the component LoadImage Node. This manipulation of the argument Name causes path traversal. Remote exploitation of the attack is possible. The exploit has been …

πŸ“… Published: April 20, 2026, 1 a.m. πŸ”„ Last Modified: April 20, 2026, 1 a.m.

5.3

CVSS4.0

CVE-2026-6590 - ComfyUI Model Preview Endpoint model_manager.py get_model_preview path traversal

A vulnerability was detected in ComfyUI up to 0.13.0. This impacts the function get_model_preview of the file app/model_manager.py of the component Model Preview Endpoint. The manipulation results in path traversal. The attack may be launched remotely. The exploit is now public and may be used. The…

πŸ“… Published: April 20, 2026, 12:45 a.m. πŸ”„ Last Modified: April 20, 2026, 12:45 a.m.

5.3

CVSS4.0

CVE-2026-6589 - ComfyUI server.py create_origin_only_middleware cross-site request forgery

A security vulnerability has been detected in ComfyUI up to 0.13.0. This affects the function create_origin_only_middleware of the file server.py. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The…

πŸ“… Published: April 20, 2026, 12:30 a.m. πŸ”„ Last Modified: April 20, 2026, 12:30 a.m.

6.9

CVSS4.0

CVE-2026-6588 - serge-chat serge Model API Endpoint model.py delete_model missing authentication

A weakness has been identified in serge-chat serge up to 1.4TB. The impacted element is the function download_model/delete_model of the file api/src/serge/routers/model.py of the component Model API Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched re…

πŸ“… Published: April 20, 2026, 12:15 a.m. πŸ”„ Last Modified: April 20, 2026, 12:15 a.m.

5.3

CVSS4.0

CVE-2026-6587 - vibrantlabsai RAGAS Collections util.py _try_process_url server-side request forgery

A security flaw has been discovered in vibrantlabsai RAGAS up to 0.4.3. The affected element is the function _try_process_local_file/_try_process_url of the file src/ragas/metrics/collections/multi_modal_faithfulness/util.py of the component Collections Module. Performing a manipulation of the argu…

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 20, 2026, midnight

0.0

CVE-2026-39109 -

SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the username parameter of the login page (index.php). This allows an unauthenticated attacker to manipulate backend SQL queries during authentication and retrieve sensitive database …

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 20, 2026, 5:18 p.m.
Total resulsts: 346298
Page 109 of 34,630
Β« previous page Β» next page
Filters