6.9

CVSS4.0

CVE-2026-4613 - SourceCodester E-Commerce Site products.php sql injection

A vulnerability was found in SourceCodester E-Commerce Site 1.0. This vulnerability affects unknown code of the file /products.php. The manipulation of the argument Search results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.

πŸ“… Published: March 23, 2026, 11:04 p.m. πŸ”„ Last Modified: March 24, 2026, 10:30 a.m.

2.3

CVSS4.0

CVE-2026-33168 - Rails has a possible XSS vulnerability in its Action View tag helpers

Action View provides conventions and helpers for building web pages with the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when a blank string is used as an HTML attribute name in Action View tag helpers, the attribute escaping is bypassed, producing malformed HTML. A carefully …

πŸ“… Published: March 23, 2026, 11:01 p.m. πŸ”„ Last Modified: March 25, 2026, 8:36 p.m.

1.3

CVSS4.0

CVE-2026-33167 - Rails has a possible XSS vulnerability in its Action Pack debug exceptions

Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1, the debug exceptions page does not properly escape exception messages. A carefully crafted exception message could inject arbitrary HTML and JavaScript into the page, leadi…

πŸ“… Published: March 23, 2026, 10:58 p.m. πŸ”„ Last Modified: March 25, 2026, 8:36 p.m.

7.7

CVSS4.0

CVE-2026-33046 - Indico discloses local files resulting in Remote Code Execution through LaTeX injection

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In versions prior to 3.3.12, due to vulnerabilities in TeXLive and obscure LaTeX syntax that allowed circumventing Indico's LaTeX sanitizer, it is possible to use specially-crafted LaTeX…

πŸ“… Published: March 23, 2026, 10:45 p.m. πŸ”„ Last Modified: March 25, 2026, 8:36 p.m.

4.3

CVSS3.1

CVE-2026-3225 - LearnPress <= 4.3.2.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Quiz Answer …

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized deletion of quiz question answers due to a missing capability check in the delete_question_answer() function of the EditQuestionAjax class in all versions up to, and including, 4.3.2.8. The AbstractAjax::catch_…

πŸ“… Published: March 23, 2026, 10:25 p.m. πŸ”„ Last Modified: March 25, 2026, 8:36 p.m.

7.5

CVSS3.1

CVE-2026-4306 - WP Job Portal <= 2.4.8 - Unauthenticated SQL Injection via 'radius' Parameter

The WP Job Portal plugin for WordPress is vulnerable to SQL Injection via the 'radius' parameter in all versions up to, and including, 2.4.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthent…

πŸ“… Published: March 23, 2026, 10:25 p.m. πŸ”„ Last Modified: March 24, 2026, 10:30 a.m.

6.5

CVSS3.1

CVE-2026-2412 - Quiz and Survey Master (QSM) <= 10.3.5 - Authenticated (Contributor+) SQL Injection via 'merged_que…

The Quiz and Survey Master (QSM) plugin for WordPress is vulnerable to SQL Injection via the 'merged_question' parameter in all versions up to, and including, 10.3.5. This is due to insufficient sanitization of user-supplied input before being used in a SQL query. The sanitize_text_field() function…

πŸ“… Published: March 23, 2026, 10:25 p.m. πŸ”„ Last Modified: March 25, 2026, 8:36 p.m.

4.3

CVSS3.1

CVE-2026-4066 - Smart Custom Fields <= 5.0.6 - Missing Authorization to Authenticated (Contributor+) Sensitive Info…

The Smart Custom Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relational_posts_search() function in all versions up to, and including, 5.0.6. This makes it possible for authenticated attackers, with Contributor-level access and ab…

πŸ“… Published: March 23, 2026, 10:25 p.m. πŸ”„ Last Modified: March 24, 2026, 10:30 a.m.

6.9

CVSS4.0

CVE-2026-4612 - itsourcecode Free Hotel Reservation System Parameter index.php sql injection

A vulnerability has been found in itsourcecode Free Hotel Reservation System 1.0. This affects an unknown part of the file /hotel/admin/mod_users/index.php?view=edit&id=8 of the component Parameter Handler. The manipulation of the argument account_id leads to sql injection. Remote exploitation of t…

πŸ“… Published: March 23, 2026, 9:57 p.m. πŸ”„ Last Modified: March 24, 2026, 10:30 a.m.

9.3

CVSS4.0

CVE-2026-4681 - Critical Remote Code Execution vulnerability reported in Windchill

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. This issue affects Windchill PDMLink: 11.0 M030, 11.1 M020, 11.2.1.0, 12.0.2.0, 12.1.2.0, 13.0.2.0, 13.1.0.0, 1…

πŸ“… Published: March 23, 2026, 9:48 p.m. πŸ”„ Last Modified: March 24, 2026, 10:30 a.m.
Total resulsts: 340871
Page 132 of 34,088
Β« previous page Β» next page
Filters