8.5

CVSS4.0

CVE-2025-67491 - OpenEMR has Stored XSS in ub04 helper

OpenEMR is a free and open source electronic health records and medical practice management application. Versions 5.0.0.5 through 7.0.3.4 have a stored cross-site scripting vulnerability in the ub04 helper of the billing interface. The variable `$data` is passed in a click event handler enclosed in…

πŸ“… Published: Feb. 25, 2026, 12:31 a.m. πŸ”„ Last Modified: Feb. 27, 2026, 5:32 p.m.

7.1

CVSS4.0

CVE-2026-27598 - Dagu: Path traversal in DAG creation allows arbitrary YAML file write outside DAGs directory

Dagu is a workflow engine with a built-in Web user interface. In versions up to and including 1.16.7, the `CreateNewDAG` API endpoint (`POST /api/v1/dags`) does not validate the DAG name before passing it to the file store. An authenticated user with DAG write permissions can write arbitrary YAML f…

πŸ“… Published: Feb. 25, 2026, 12:27 a.m. πŸ”„ Last Modified: April 17, 2026, 3:45 p.m.

6.9

CVSS4.0

CVE-2026-3135 - itsourcecode News Portal Project add-category.php sql injection

A weakness has been identified in itsourcecode News Portal Project 1.0. The impacted element is an unknown function of the file /admin/add-category.php. This manipulation of the argument Category causes sql injection. It is possible to initiate the attack remotely. The exploit has been made availab…

πŸ“… Published: Feb. 25, 2026, 12:02 a.m. πŸ”„ Last Modified: April 17, 2026, 3:45 p.m.

9.6

CVSS3.1

CVE-2025-69771 -

Cross-Site Scripting (XSS) vulnerability in the subtitle loading function of the asbplayer Chrome Extension version 1.14.0 allows attackers to execute arbitrary JavaScript in the context of the active streaming platform via a crafted .srt subtitle file. Because the script executes within the same-s…

πŸ“… Published: Feb. 25, 2026, midnight πŸ”„ Last Modified: March 20, 2026, 7:16 p.m.

5.1

CVSS3.1

CVE-2026-1940 - Gstreamer: incomplete fix of cve-2026-1940

An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added a size validation check lsize + 8 > size, but it does not account for the GST_ROUND_UP_2(lsize) used in the actual offset calculation. When lsize is an odd number, the parser adv…

πŸ“… Published: Feb. 25, 2026, midnight πŸ”„ Last Modified: March 25, 2026, 8:36 p.m.

4.8

CVSS3.1

CVE-2026-26717 - HMAC Timing Attack Enabling Signature Forgery in OpenFUN Richie LMS

An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operator for HMAC signature verification in the sync_course_run_from_request function. This allows remote attackers to forge valid signatures and bypass authentication by measuring resp…

πŸ“… Published: Feb. 25, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 11 a.m.

6.9

CVSS4.0

CVE-2026-3134 - itsourcecode News Portal Project edit-category.php sql injection

A security flaw has been discovered in itsourcecode News Portal Project 1.0. The affected element is an unknown function of the file /newsportal/admin/edit-category.php. The manipulation of the argument Category results in sql injection. The attack may be performed from remote. The exploit has been…

πŸ“… Published: Feb. 24, 2026, 11:32 p.m. πŸ”„ Last Modified: April 17, 2026, 3:45 p.m.

6.9

CVSS4.0

CVE-2026-3133 - itsourcecode Document Management System Login loging.php sql injection

A vulnerability has been found in itsourcecode Document Management System 1.0. This issue affects some unknown processing of the file /loging.php of the component Login. The manipulation of the argument Username leads to sql injection. Remote exploitation of the attack is possible. The exploit has …

πŸ“… Published: Feb. 24, 2026, 11:32 p.m. πŸ”„ Last Modified: April 16, 2026, 4:30 p.m.

4.8

CVSS4.0

CVE-2026-26351 - GetSimpleCMS-CE < 3.3.22 Stored XSS via components.php

GetSimpleCMS Community Edition (CE) version 3.3.16 contains a stored cross-site scripting (XSS) vulnerability in the Theme to Components functionality within components.php. User-supplied input provided to the "slug" field of a component is stored without proper output encoding. While other fields …

πŸ“… Published: Feb. 24, 2026, 10:05 p.m. πŸ”„ Last Modified: April 17, 2026, 3:45 p.m.

5.5

CVSS3.1

CVE-2026-27117 - bit7z has a path traversal vulnerability

bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4.0.11, a path traversal vulnerability ("Zip Slip") exists in bit7z's archive extraction functionality. The library does not adequately validate file paths contained in archive ent…

πŸ“… Published: Feb. 24, 2026, 9:46 p.m. πŸ”„ Last Modified: April 18, 2026, 5:45 p.m.
Total resulsts: 346541
Page 1192 of 34,655
Β« previous page Β» next page
Filters