9.3

CVSS4.0

CVE-2026-35459 - pyLoad has SSRF fix bypass via HTTP redirect

pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, pyLoad has a server-side request forgery (SSRF) vulnerability. The fix for CVE-2026-33992 added IP validation to BaseDownloader.download() that checks the hostname of the initial download URL. Howeverโ€ฆ

๐Ÿ“… Published: April 6, 2026, 7:37 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 8:16 p.m.

7.7

CVSS3.1

CVE-2026-35187 - pyLoad has SSRF in parse_urls API endpoint via unvalidated URL parameter

pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the parse_urls API function in src/pyload/core/api/__init__.py fetches arbitrary URLs server-side via get_url(url) (pycurl) without any URL validation, protocol restriction, or IP blacklist. An authenโ€ฆ

๐Ÿ“… Published: April 6, 2026, 7:33 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 3:17 p.m.

8.7

CVSS4.0

CVE-2026-35185 - HAX CMS's public /server-status endpoint exposes authentication tokens, user activity, and client Iโ€ฆ

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to 25.0.0, the /server-status endpoint is publicly accessible and exposes sensitive information including authentication tokens (user_token), user activity, client IP addresses, and server configuration details. This allows โ€ฆ

๐Ÿ“… Published: April 6, 2026, 7:24 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:20 p.m.

8.7

CVSS4.0

CVE-2026-35184 - EcclesiaCRM has a Critical SQL Injection

EcclesiaCRM is CRM Software for church management. Prior to 8.0.0, there is a SQL injection vulnerability in v2/templates/query/queryview.php via the custom and value parameters. This vulnerability is fixed in 8.0.0.

๐Ÿ“… Published: April 6, 2026, 7:21 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 8:16 p.m.

5.3

CVSS4.0

CVE-2026-5681 - itsourcecode sanitize or validate this input Parameter borrowedequip.php sql injection

A flaw has been found in itsourcecode sanitize or validate this input 1.0. This impacts an unknown function of the file /borrowedequip.php of the component Parameter Handler. This manipulation of the argument emp_id causes sql injection. The attack is possible to be carried out remotely. The exploiโ€ฆ

๐Ÿ“… Published: April 6, 2026, 7:15 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 6:54 a.m.

7.1

CVSS3.1

CVE-2026-35183 - Brave CMS has an Insecure Direct Object Reference in Article Image Deletion

Brave CMS is an open-source CMS. Prior to 2.0.6, an Insecure Direct Object Reference (IDOR) vulnerability exists in the article image deletion feature. It is located in app/Http/Controllers/Dashboard/ArticleController.php within the deleteImage method. The endpoint accepts a filename from the URL bโ€ฆ

๐Ÿ“… Published: April 6, 2026, 7:11 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:20 p.m.

8.8

CVSS3.1

CVE-2026-35182 - Missing Authorization Privilege Escalation

Brave CMS is an open-source CMS. Prior to 2.0.6, this vulnerability is a missing authorization check found in the update role endpoint at routes/web.php. The POST route for /rights/update-role/{id} lacks the checkUserPermissions:assign-user-roles middleware. This allows any authenticated user to chโ€ฆ

๐Ÿ“… Published: April 6, 2026, 7:10 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 3:17 p.m.

4.3

CVSS3.1

CVE-2026-35181 - WWBN AVideo Affected by CSRF on Player Skin Configuration via admin/playerUpdate.json.php

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the player skin configuration endpoint at admin/playerUpdate.json.php does not validate CSRF tokens. The plugins table is explicitly excluded from the ORM's domain-based security check via ignoreTableSecurityCheck(), removingโ€ฆ

๐Ÿ“… Published: April 6, 2026, 7:09 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:20 p.m.

7.5

CVSS3.1

CVE-2026-35172 - Distribution has stale blob access resurrection via repo-scoped redis descriptor cache invalidation

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore read access in repo a after an explicit delete when storage.cache.blobdescriptor: redis and storage.delete.enabled: true are both enabled. The delete path clears the shared digestโ€ฆ

๐Ÿ“… Published: April 6, 2026, 7:08 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 7:50 p.m.

4.3

CVSS3.1

CVE-2026-35180 - WWBN AVideo affected by CSRF on Site Customization Endpoint Enables Logo Overwrite via Base64 File โ€ฆ

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the site customization endpoint at admin/customize_settings_nativeUpdate.json.php lacks CSRF token validation and writes uploaded logo files to disk before the ORM's domain-based security check executes. Combined with SameSitโ€ฆ

๐Ÿ“… Published: April 6, 2026, 7:06 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 2:44 p.m.
Total resulsts: 343921
Page 135 of 34,393
ยซ previous page ยป next page
Filters