8.8

CVSS4.0

CVE-2019-25498 - Simple Job Script SQL Injection via searched Endpoint

Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the landing_location parameter. Attackers can send POST requests to the searched endpoint with malicious SQL payloads to bypass authenticationโ€ฆ

๐Ÿ“… Published: March 4, 2026, 5:15 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 2:04 p.m.

6

CVSS3.1

CVE-2026-20008 - Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Lua Cโ€ฆ

A vulnerability in a small subset of CLI commands that are used on Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to craft Lua code that could be used on the underlying operating sโ€ฆ

๐Ÿ“… Published: March 4, 2026, 5:07 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 1:30 p.m.

5.3

CVSS3.1

CVE-2026-20009 - Cisco Secure Firewall Adaptive Security Appliance SSH Partial Private Key Authentication Bypass Vulโ€ฆ

A vulnerability in the implementation of the proprietary SSH stack with SSH key-based authentication in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to log in to a Cisco Secure Firewall ASA device and execute commands as a specificโ€ฆ

๐Ÿ“… Published: March 4, 2026, 5:06 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 8:13 p.m.

5.5

CVSS3.1

CVE-2026-26949 - Elevation of Privileges via Incorrect Authorization in Dell Device Management Agent

Dell Device Management Agent (DDMA), versions prior to 26.02, contain an Incorrect Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

๐Ÿ“… Published: March 4, 2026, 5:04 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 1:45 p.m.

6.5

CVSS3.1

CVE-2026-20001 - Cisco Secure Firewall Management Center Software SQL Injection Vulnerabilities

A vulnerability in the REST API of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to inadequate validation of user-supplied input. An attacker could exploit this vulnerability by sending crโ€ฆ

๐Ÿ“… Published: March 4, 2026, 5:03 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 10:15 a.m.

5.8

CVSS3.1

CVE-2026-20005 -

Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection. This vulnerability is due to incomplete parsing of theโ€ฆ

๐Ÿ“… Published: March 4, 2026, 5:02 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 1:15 p.m.

3.3

CVSS3.1

CVE-2026-22760 - Denial of Service via Improper Condition Check in Dell Device Management Agent

Dell Device Management Agent (DDMA), versions prior to 26.02, contain an Improper Check for Unusual or Exceptional Conditions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of Service.

๐Ÿ“… Published: March 4, 2026, 4:59 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 1:45 p.m.

6.9

CVSS4.0

CVE-2026-29069 - Craft has an unauthenticated activation email trigger with potential user enumeration

Craft is a content management system (CMS). Prior to 5.9.0-beta.2 and 4.17.0-beta.2, the actionSendActivationEmail() endpoint is accessible to unauthenticated users and does not require a permission check for pending users. An attacker with no prior access can trigger activation emails for any pendโ€ฆ

๐Ÿ“… Published: March 4, 2026, 4:57 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 1:45 p.m.

8.6

CVSS4.0

CVE-2026-28784 - Craft is affected by potential authenticated Remote Code Execution via Twig SSTI

Craft is a content management system (CMS). Prior to 5.8.22 and 4.16.18, it is possible to craft a malicious payload using the Twig map filter in text fields that accept Twig input under Settings in the Craft control panel or using the System Messages utility, which could lead to a RCE. For this toโ€ฆ

๐Ÿ“… Published: March 4, 2026, 4:53 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 1:45 p.m.

9.4

CVSS4.0

CVE-2026-28783 - Craft has a Twig Function Blocklist Bypass

Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, Craft CMS implements a blocklist to prevent potentially dangerous PHP functions from being called via Twig non-Closure arrow functions. In order to be able to successfully execute this attack, you need to either haโ€ฆ

๐Ÿ“… Published: March 4, 2026, 4:50 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 1:45 p.m.
Total resulsts: 348413
Page 1268 of 34,842
ยซ previous page ยป next page
Filters