4.6

CVSS4.0

CVE-2026-3219 - pip doesn't reject concatenated ZIP and tar archives

pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with …

📅 Published: April 20, 2026, 2:55 p.m. 🔄 Last Modified: April 22, 2026, 11:47 a.m.

9.2

CVSS4.0

CVE-2026-39918 - Vvveb < 1.0.8.1 Code Injection via Installation Endpoint

Vvveb prior to 1.0.8.1 contains a code injection vulnerability in the installation endpoint where the subdir POST parameter is written unsanitized into the env.php configuration file without escaping or validation. Attackers can inject arbitrary PHP code by breaking out of the string context in the…

📅 Published: April 20, 2026, 2:46 p.m. 🔄 Last Modified: April 20, 2026, 2:46 p.m.

4.8

CVSS4.0

CVE-2026-6651 - erponline.xyz ERP Online Inventory Edit Item cross site scripting

A security flaw has been discovered in erponline.xyz ERP Online up to 4.0.0. This vulnerability affects unknown code of the component Inventory Edit Item Page. The manipulation of the argument Item Name results in cross site scripting. The attack may be launched remotely. The exploit has been relea…

📅 Published: April 20, 2026, 2:45 p.m. 🔄 Last Modified: April 22, 2026, 11:47 a.m.

5.1

CVSS4.0

CVE-2026-6650 - Z-BlogPHP ZBA File app_upload.php UnPack unrestricted upload

A vulnerability was identified in Z-BlogPHP 1.7.5. This affects the function App::UnPack of the file /zb_users/plugin/AppCentre/app_upload.php of the component ZBA File Handler. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit is publicly available an…

📅 Published: April 20, 2026, 2:30 p.m. 🔄 Last Modified: April 22, 2026, 11:48 a.m.

8.3

CVSS4.0

CVE-2026-34428 - Vvveb < 1.0.8.1 SSRF via oEmbedProxy

Vvveb prior to 1.0.8.1 contains a server-side request forgery vulnerability in the oEmbedProxy action of the editor/editor module where the url parameter is passed directly to getUrl() via curl without scheme or destination validation. Authenticated backend users can supply file:// URLs to read arb…

📅 Published: April 20, 2026, 1:55 p.m. 🔄 Last Modified: April 20, 2026, 1:55 p.m.

8.7

CVSS4.0

CVE-2026-34427 - Vvveb < 1.0.8.1 Privilege Escalation via admin/user/save

Vvveb prior to 1.0.8.1 contains a privilege escalation vulnerability in the admin user profile save endpoint that allows authenticated users to modify privileged fields on their own profile. Attackers can inject role_id=1 into profile save requests to escalate to Super Administrator privileges, ena…

📅 Published: April 20, 2026, 1:55 p.m. 🔄 Last Modified: April 20, 2026, 1:55 p.m.

5.1

CVSS4.0

CVE-2026-34429 - Vvveb < 1.0.8.1 Stored XSS via Media Upload and Rename

Vvveb prior to 1.0.8.1 contains a stored cross-site scripting vulnerability that allows authenticated users with media upload and rename permissions to execute arbitrary JavaScript by bypassing MIME type validation and renaming uploaded files to executable extensions. Attackers can prepend a GIF89a…

📅 Published: April 20, 2026, 1:54 p.m. 🔄 Last Modified: April 20, 2026, 1:54 p.m.

0.0

CVE-2026-5760 - CVE-2026-5760

SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is loaded, as the Jinja2 chat templates are rendered using an unsandboxed jinja2.Environment().

📅 Published: April 20, 2026, 1:46 p.m. 🔄 Last Modified: April 20, 2026, 1:46 p.m.

5.7

CVSS4.0

CVE-2026-6369 - Exposed Session Token in canonical-livepatch client snap

An improper access control vulnerability in the canonical-livepatch snap client prior to version 10.15.0 allows a local unprivileged user to obtain a sensitive, root-level authentication token by sending an unauthenticated request to the livepatchd.sock Unix domain socket. This vulnerability is exp…

📅 Published: April 20, 2026, 1:38 p.m. 🔄 Last Modified: April 22, 2026, 11:48 a.m.

8.4

CVSS3.1

CVE-2026-4048 - OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Man…

OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in a custom WAF rule file during the file upload process.

📅 Published: April 20, 2026, 1:36 p.m. 🔄 Last Modified: April 22, 2026, 11:48 a.m.
Total resulsts: 346532
Page 124 of 34,654
« previous page » next page
Filters