5.3

CVSS4.0

CVE-2026-3150 - itsourcecode College Management System display-teacher.php sql injection

A security vulnerability has been detected in itsourcecode College Management System 1.0. This affects an unknown part of the file /admin/display-teacher.php. The manipulation of the argument teacher_id leads to sql injection. The attack is possible to be carried out remotely. The exploit has been โ€ฆ

๐Ÿ“… Published: Feb. 25, 2026, 4:32 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:30 p.m.

4.7

CVSS3.1

CVE-2025-0976 - Information Exposure Vulnerability in Hitachi Configuration Manager, Hitachi Ops Center API Configuโ€ฆ

Information Exposure Vulnerability inย Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0-00 before 11.0.4-00; Hitachi Configuration Manager: from 8.6.1-00 before 11.0.5-00.

๐Ÿ“… Published: Feb. 25, 2026, 4:17 a.m. ๐Ÿ”„ Last Modified: Feb. 27, 2026, 7:13 p.m.

8.6

CVSS3.1

CVE-2026-27696 - changedetection.io Vulnerable to Server-Side Request Forgery (SSRF) via Watch URLs

changedetection.io is a free open source web page change detection tool. In versions prior to 0.54.1, changedetection.io is vulnerable to Server-Side Request Forgery (SSRF) because the URL validation function `is_safe_valid_url()` does not validate the resolved IP address of watch URLs against privโ€ฆ

๐Ÿ“… Published: Feb. 25, 2026, 4:16 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:30 p.m.

6.1

CVSS3.1

CVE-2026-27645 - changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response

changedetection.io is a free open source web page change detection tool. In versions prior to 0.54.1, the RSS single-watch endpoint reflects the UUID path parameter directly in the HTTP response body without HTML escaping. Since Flask returns text/html by default for plain string responses, the broโ€ฆ

๐Ÿ“… Published: Feb. 25, 2026, 4:06 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:30 p.m.

7.2

CVSS3.1

CVE-2026-27624 - Coturn: IPv4-mapped IPv6 (::ffff:0:0/96) bypasses denied-peer-ip ACL

Coturn is a free open source implementation of TURN and STUN Server. Coturn is commonly configured to block loopback and internal ranges using "denied-peer-ip" and/or default loopback restrictions. CVE-2020-26262 addressed bypasses involving "0.0.0.0", "[::1]" and "[::]", but IPv4-mapped IPv6 is noโ€ฆ

๐Ÿ“… Published: Feb. 25, 2026, 4:04 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:30 p.m.

3.7

CVSS3.1

CVE-2026-3184 - Util-linux: util-linux: access control bypass due to improper hostname canonicalization

A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing โ€ฆ

๐Ÿ“… Published: Feb. 25, 2026, 4:04 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 4:16 p.m.

5.3

CVSS4.0

CVE-2026-3149 - itsourcecode College Management System asign-single-student-subjects.php sql injection

A weakness has been identified in itsourcecode College Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/asign-single-student-subjects.php. Executing a manipulation of the argument course_code can lead to sql injection. The attack can be executed remotelโ€ฆ

๐Ÿ“… Published: Feb. 25, 2026, 4:02 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:30 p.m.

6.9

CVSS4.0

CVE-2026-3148 - SourceCodester Simple and Nice Shopping Cart Script signup.php sql injection

A vulnerability was determined in SourceCodester Simple and Nice Shopping Cart Script 1.0. This impacts an unknown function of the file /signup.php. This manipulation of the argument Username causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and mayโ€ฆ

๐Ÿ“… Published: Feb. 25, 2026, 4:02 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:30 p.m.

10

CVSS3.1

CVE-2026-27597 - @enclave-vm/core is vulnerable to Sandbox Escape

Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to version 2.11.1, it is possible to escape the security boundraries set by `@enclave-vm/core`, which can be used to achieve remote code execution (RCE). The issue has been fixed in version 2.11.1.

๐Ÿ“… Published: Feb. 25, 2026, 3:56 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 11 a.m.

9.8

CVSS3.1

CVE-2026-27641 - Flask-Reuploaded vulnerable to Remote Code Execution via Server-Side Template Injection

Flask-Reuploaded provides file uploads for Flask. A critical path traversal and extension bypass vulnerability in versions prior to 1.5.0 allows remote attackers to achieve arbitrary file write and remote code execution through Server-Side Template Injection (SSTI). Flask-Reuploaded has been patcheโ€ฆ

๐Ÿ“… Published: Feb. 25, 2026, 3:54 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:30 p.m.
Total resulsts: 346514
Page 1184 of 34,652
ยซ previous page ยป next page
Filters