6.9

CVSS4.0

CVE-2026-6621 - 1024bit extend-deep index.js prototype pollution

A vulnerability was determined in 1024bit extend-deep up to 0.1.6. The impacted element is an unknown function of the file index.js. This manipulation of the argument __proto__ causes improperly controlled modification of object prototype attributes. Remote exploitation of the attack is possible. T…

📅 Published: April 20, 2026, 8:30 a.m. 🔄 Last Modified: April 20, 2026, 2:57 p.m.

5.3

CVSS4.0

CVE-2026-6620 - SonicCloudOrg sonic-server File Upload Endpoint FileTool.java upload path traversal

A vulnerability was found in SonicCloudOrg sonic-server up to 2.0.0. The affected element is the function Upload of the file FileTool.java of the component File Upload Endpoint. The manipulation of the argument Type results in path traversal. The attack may be launched remotely. The exploit has bee…

📅 Published: April 20, 2026, 8:15 a.m. 🔄 Last Modified: April 20, 2026, 2:58 p.m.

8.5

CVSS4.0

CVE-2026-39454 -

SKYSEA Client View and SKYMEC IT Manager provided by Sky Co.,LTD. configure the installation folder with improper file access permission settings. A non-administrative user may manipulate and/or place arbitrary files within the installation folder of the product. As a result, arbitrary code may be …

📅 Published: April 20, 2026, 8:04 a.m. 🔄 Last Modified: April 20, 2026, 1:28 p.m.

5.1

CVSS4.0

CVE-2026-6619 - langgenius dify ImagePreview image-preview.tsx openInNewTab cross site scripting

A vulnerability has been found in langgenius dify up to 1.13.3. Impacted is the function openInNewTab of the file web/app/components/base/image-uploader/image-preview.tsx of the component ImagePreview. The manipulation of the argument filename leads to cross site scripting. The attack may be initia…

📅 Published: April 20, 2026, 8 a.m. 🔄 Last Modified: April 20, 2026, 1:29 p.m.

5.3

CVSS4.0

CVE-2026-6618 - langgenius dify ApiBasedToolSchemaParser parser.py parse_openai_plugin_json_to_tool_bundle server-s…

A flaw has been found in langgenius dify up to 1.13.3. This issue affects the function parse_openai_plugin_json_to_tool_bundle of the file api/core/tools/utils/parser.py of the component ApiBasedToolSchemaParser. Executing a manipulation of the argument url can lead to server-side request forgery. …

📅 Published: April 20, 2026, 7:45 a.m. 🔄 Last Modified: April 20, 2026, 2:30 p.m.

8.7

CVSS4.0

CVE-2026-5967 - TeamT5|ThreatSonar Anti-Ransomware - Privilege Escalation

ThreatSonar Anti-Ransomware developed by TeamT5 has an Privilege Escalation vulnerability. Authenticated remote attackers with shell access can inject OS commands and execute them with root privileges.

📅 Published: April 20, 2026, 7:44 a.m. 🔄 Last Modified: April 20, 2026, 1:29 p.m.

7.2

CVSS4.0

CVE-2026-5966 - TeamT5|ThreatSonar Anti-Ransomware - Arbitrary File Deletion

ThreatSonar Anti-Ransomware developed by TeamT5 has an Arbitrary File Deletion vulnerability. Authenticated remote attackers with web access can exploit Path Traversal to delete arbitrary files on the system.

📅 Published: April 20, 2026, 7:40 a.m. 🔄 Last Modified: April 20, 2026, 1:30 p.m.

9.3

CVSS4.0

CVE-2026-5964 - Digiwin|EasyFlow .NET - SQL Injection

EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

📅 Published: April 20, 2026, 7:36 a.m. 🔄 Last Modified: April 20, 2026, 1:38 p.m.

9.3

CVSS4.0

CVE-2026-5963 - Digiwin|EasyFlow .NET - SQL Injection

EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

📅 Published: April 20, 2026, 7:32 a.m. 🔄 Last Modified: April 20, 2026, 1:42 p.m.

5.3

CVSS4.0

CVE-2026-6617 - langgenius dify ApiToolManageService api_tools_manage_service.py get_api_tool_provider_remote_schem…

A vulnerability was detected in langgenius dify up to 0.6.9. This vulnerability affects the function get_api_tool_provider_remote_schema of the file api/services/tools/api_tools_manage_service.py of the component ApiToolManageService. Performing a manipulation of the argument url results in server-…

📅 Published: April 20, 2026, 7:30 a.m. 🔄 Last Modified: April 20, 2026, 7:30 a.m.
Total resulsts: 345342
Page 12 of 34,535
« previous page » next page
Filters