8.7

CVSS4.0

CVE-2026-23735 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in grap…

GraphQL Modules is a toolset of libraries and guidelines dedicated to create reusable, maintainable, testable and extendable modules out of your GraphQL server. From 2.2.1 to before 2.4.1 and 3.1.1, when 2 or more parallel requests are made which trigger the same service, the context of the request…

📅 Published: Jan. 16, 2026, 8:04 p.m. 🔄 Last Modified: Jan. 19, 2026, 9:19 a.m.

4.3

CVSS3.1

CVE-2026-23731 - WeGIA Clickjacking Vulnerability

WeGIA is a web manager for charitable institutions. Prior to 3.6.2, The web application is vulnerable to clickjacking attacks. The WeGIA application does not send any defensive HTTP headers related to framing protection. In particular, X-Frame-Options is missing andContent-Security-Policy with fram…

📅 Published: Jan. 16, 2026, 7:50 p.m. 🔄 Last Modified: Jan. 19, 2026, 9:19 a.m.

4.8

CVSS4.0

CVE-2026-23730 - WeGIA has an Open Redirect Vulnerability in control.php Endpoint via nextPage Parameter (metodo=lis…

WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php endpoint of the WeGIA application, specifically through the nextPage parameter when combined with metodo=listarTodos and nomeClasse=ProdutoControle. T…

📅 Published: Jan. 16, 2026, 7:48 p.m. 🔄 Last Modified: Jan. 19, 2026, 9:19 a.m.

4.8

CVSS4.0

CVE-2026-23729 - WeGIA has an Open Redirect Vulnerability in control.php Endpoint via nextPage Parameter (metodo=lis…

WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php endpoint of the WeGIA application, specifically through the nextPage parameter when combined with metodo=listarDescricao and nomeClasse=ProdutoControl…

📅 Published: Jan. 16, 2026, 7:47 p.m. 🔄 Last Modified: Jan. 19, 2026, 9:19 a.m.

4.8

CVSS4.0

CVE-2026-23728 - WeGIA has an Open Redirect Vulnerability in control.php Endpoint via nextPage Parameter (metodo=lis…

WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php endpoint of the WeGIA application, specifically through the nextPage parameter when combined with metodo=listarTodos and nomeClasse=DestinoControle. T…

📅 Published: Jan. 16, 2026, 7:46 p.m. 🔄 Last Modified: Jan. 19, 2026, 9:19 a.m.

4.8

CVSS4.0

CVE-2026-23727 - WeGIA has an Open Redirect Vulnerability in control.php Endpoint via nextPage Parameter (metodo=lis…

WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php endpoint of the WeGIA application, specifically through the nextPage parameter when combined with metodo=listarTodos and nomeClasse=TipoSaidaControle.…

📅 Published: Jan. 16, 2026, 7:41 p.m. 🔄 Last Modified: Jan. 19, 2026, 9:19 a.m.

4.8

CVSS4.0

CVE-2026-23726 - WeGIA has an Open Redirect Vulnerability in control.php Endpoint via nextPage Parameter (metodo=lis…

WeGIA is a web manager for charitable institutions. Prior to 3.6.2, An Open Redirect vulnerability was identified in the /WeGIA/controle/control.php endpoint of the WeGIA application, specifically through the nextPage parameter when combined with metodo=listarTodos and nomeClasse=TipoEntradaControl…

📅 Published: Jan. 16, 2026, 7:40 p.m. 🔄 Last Modified: Jan. 19, 2026, 9:19 a.m.

5.3

CVSS4.0

CVE-2026-23725 - WeGIA Stored Cross-Site Scripting (XSS) – nome Parameter on Adopters Information Page

WeGIA is a web manager for charitable institutions. Prior to 3.6.2, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the html/pet/adotantes/cadastro_adotante.php and html/pet/adotantes/informacao_adotantes.php endpoint of the WeGIA application. The application does not sanitize u…

📅 Published: Jan. 16, 2026, 7:38 p.m. 🔄 Last Modified: Jan. 19, 2026, 9:19 a.m.

4.3

CVSS3.1

CVE-2026-23724 - WeGIA Stored Cross-Site Scripting (XSS) – atendido_idatendido Parameter on Occurrence Registration …

WeGIA is a web manager for charitable institutions. Prior to 3.6.2, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the html/atendido/cadastro_ocorrencia.php endpoint of the WeGIA application. The application does not sanitize user-controlled data before rendering it inside the …

📅 Published: Jan. 16, 2026, 7:37 p.m. 🔄 Last Modified: Jan. 19, 2026, 9:20 a.m.

9.1

CVSS3.1

CVE-2026-23722 - WeGIA has a Reflected Cross-Site Scripting (XSS) vulnerability allowing arbitrary code execution an…

WeGIA is a Web Manager for Charitable Institutions. Prior to 3.6.2, a Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the WeGIA system, specifically within the html/memorando/insere_despacho.php file. The application fails to properly sanitize or encode user-supplied input via …

📅 Published: Jan. 16, 2026, 7:29 p.m. 🔄 Last Modified: Jan. 19, 2026, 9:20 a.m.
Total resulsts: 329425
Page 131 of 32,943
« previous page » next page
Filters