6.9

CVSS4.0

CVE-2026-5676 - Totolink A8000R cstecgi.cgi setLanguageCfg missing authentication

A vulnerability was identified in Totolink A8000R 5.9c.681_B20180413. This issue affects the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument langType leads to missing authentication. The attack can be launched remotely. The exploit is publicly available a…

πŸ“… Published: April 6, 2026, 6:15 p.m. πŸ”„ Last Modified: April 7, 2026, 6:54 a.m.

6.2

CVSS3.1

CVE-2026-33817 - Vulnerability in go.etcd.io/bbolt

Index out-of-range when encountering a branch page with zero elements in go.etcd.io/bbolt

πŸ“… Published: April 6, 2026, 6:13 p.m. πŸ”„ Last Modified: April 6, 2026, 8:16 p.m.

5.3

CVSS4.0

CVE-2026-5675 - itsourcecode Construction Management System Parameter borrowed_tool.php sql injection

A vulnerability was found in itsourcecode Construction Management System 1.0. This affects an unknown part of the file /borrowed_tool.php of the component Parameter Handler. The manipulation of the argument emp results in sql injection. It is possible to launch the attack remotely. The exploit has …

πŸ“… Published: April 6, 2026, 6 p.m. πŸ”„ Last Modified: April 7, 2026, 6:54 a.m.

4.1

CVSS3.1

CVE-2026-35177 - Path traversal issue with zip.vim in Vim

Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allows overwriting of arbitrary files when opening specially crafted zip archives, circumventing the previous fix for CVE-2025-53906. This vulnerability is fixed in 9.2.0280.

πŸ“… Published: April 6, 2026, 5:54 p.m. πŸ”„ Last Modified: April 6, 2026, 6:16 p.m.

7.2

CVSS4.0

CVE-2026-35175 - Ajenti has an authorization bypass during custom package installation

Ajenti is a Linux and BSD modular server admin panel. Prior to 2.2.15, an authenticated user (using the auth_users plugin authentication method) could install a custom package even if this user is not superuser. This vulnerability is fixed in 2.2.15.

πŸ“… Published: April 6, 2026, 5:51 p.m. πŸ”„ Last Modified: April 7, 2026, 6:54 a.m.

9.1

CVSS3.1

CVE-2026-35174 - Chyrp Lite has a Path Traversal to Remote Code Execution

Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, a path traversal vulnerability exists in the administration console that allows an administrator or a user with Change Settings permission to change the uploads path to any folder. This vulnerability allows the user to download a…

πŸ“… Published: April 6, 2026, 5:50 p.m. πŸ”„ Last Modified: April 7, 2026, 6:54 a.m.

6.5

CVSS3.1

CVE-2026-35173 - Chyrp Lite has an IDOR via Mass Assignment in Post Model

Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, an IDOR / Mass Assignment issue exists in the Post model that allows authenticated users with post editing permissions (Edit Post, Edit Draft, Edit Own Post, Edit Own Draft) to modify posts they do not own and do not have permiss…

πŸ“… Published: April 6, 2026, 5:48 p.m. πŸ”„ Last Modified: April 7, 2026, 6:54 a.m.

9.8

CVSS3.1

CVE-2026-35171 - Arbitrary Code Execution via Malicious Logging Configuration in Kedro

Kedro is a toolbox for production-ready data science. Prior to 1.3.0, Kedro allows the logging configuration file path to be set via the KEDRO_LOGGING_CONFIG environment variable and loads it without validation. The logging configuration schema supports the special () key, which enables arbitrary c…

πŸ“… Published: April 6, 2026, 5:45 p.m. πŸ”„ Last Modified: April 7, 2026, 6:54 a.m.

6.9

CVSS4.0

CVE-2026-5672 - code-projects Simple IT Discussion Forum Parameter edit-category.php sql injection

A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. Affected by this issue is some unknown functionality of the file /edit-category.php of the component Parameter Handler. The manipulation of the argument cat_id leads to sql injection. It is possible to initiate the atta…

πŸ“… Published: April 6, 2026, 5:45 p.m. πŸ”„ Last Modified: April 7, 2026, 9:37 a.m.

7.1

CVSS3.1

CVE-2026-35167 - Kedro has a path traversal in versioned dataset loading via unsanitized version string

Kedro is a toolbox for production-ready data science. Prior to 1.3.0, the _get_versioned_path() method in kedro/io/core.py constructs filesystem paths by directly interpolating user-supplied version strings without sanitization. Because version strings are used as path components, traversal sequenc…

πŸ“… Published: April 6, 2026, 5:43 p.m. πŸ”„ Last Modified: April 6, 2026, 9:47 p.m.
Total resulsts: 342654
Page 11 of 34,266
Β« previous page Β» next page
Filters