6.3

CVSS3.1

CVE-2026-31014 - Cross‑Site Request Forgery Enables Unauthorized User Account Modification

Dovestones Softwares AD Self Update <4.0.0.5 is vulnerable to Cross Site Request Forgery (CSRF). The affected endpoint processes state-changing requests without requiring a CSRF token or equivalent protection. The endpoint accepts application/x-www-form-urlencoded requests, and an originally POST-b…

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 23, 2026, 4:21 p.m.

4.9

CVSS3.1

CVE-2026-35239 - mysql: DML unspecified vulnerability (CPU Apr 2026)

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL S…

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 23, 2026, 3:08 p.m.

4.9

CVSS3.1

CVE-2026-34278 - mysql: Optimizer unspecified vulnerability (CPU Apr 2026)

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attac…

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 23, 2026, 3:05 p.m.

6.1

CVSS3.1

CVE-2026-31013 -

Dovestones Softwares ADPhonebook <4.0.1.1 has a reflected cross-site scripting (XSS) vulnerability in the search parameter of the /ADPhonebook?Department=HR endpoint. User-supplied input is reflected in the HTTP response without proper input validation or output encoding, allowing execution of arbi…

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 23, 2026, 4:24 p.m.

7.2

CVSS3.1

CVE-2026-37748 -

Visitor Management System 1.0 by sanjay1313 is vulnerable to Unrestricted File Upload in vms/php/admin_user_insert.php and vms/php/update_1.php. The move_uploaded_file() function is called without any MIME type, extension, or content validation, allowing an authenticated admin to upload a PHP websh…

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 22, 2026, 4:02 p.m.

6.5

CVSS3.1

CVE-2026-30452 - Authenticated Users Can Bypass Access Control to Alter Higher-Privilege Articles in Textpattern CMS…

Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authenticated users with low privileges to modify articles owned by users with higher privileges. By manipulating the article ID parameter during the duplicate-and-save workflow in text…

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 22, 2026, 9:24 p.m.

4.9

CVSS3.1

CVE-2026-34293 - mysql: DML unspecified vulnerability (CPU Apr 2026)

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of …

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 23, 2026, 3:05 p.m.

9.8

CVSS3.1

CVE-2026-38835 - Command Injection Vulnerability in Tenda W30E via formSetUSBPartitionUmount

Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the formSetUSBPartitionUmount function via the usbPartitionName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 22, 2026, 9:24 p.m.

7.3

CVSS3.1

CVE-2026-38834 -

Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the do_ping_action function via the hostName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 22, 2026, 9:24 p.m.

4.9

CVSS3.1

CVE-2026-21998 - mysql: Optimizer unspecified vulnerability (CPU Apr 2026)

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise M…

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 23, 2026, 3:04 p.m.
Total resulsts: 346572
Page 119 of 34,658
Β« previous page Β» next page
Filters