8.3

CVSS3.1

CVE-2026-2751 - Blind SQL Injection

Blind SQL Injection via unsanitized array keys in Service Dependencies deletion. Vulnerability in Centreon Centreon Web on Central Server on Linux (Service Dependencies modules) allows Blind SQL Injection.This issue affects Centreon Web on Central Server before 25.10.8, 24.10.20, 24.04.24.

๐Ÿ“… Published: Feb. 27, 2026, 1:33 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 10:30 a.m.

8.4

CVSS4.0

CVE-2026-3223 - Zip Slip leading to Arbitrary File Write and Privilege Escalation in Google Web Designer

Arbitrary file write & potential privilege escalation exploiting zip slip vulnerability in Google Web Designer.

๐Ÿ“… Published: Feb. 27, 2026, 1:12 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 10:30 a.m.

6.3

CVSS3.1

CVE-2025-11950 - Reflected XSS in Knowhy's EduAsist

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in KNOWHY Advanced Technology Trading Ltd. Co. EduAsist allows Reflected XSS.This issue affects EduAsist: before v2.1.

๐Ÿ“… Published: Feb. 27, 2026, 12:55 p.m. ๐Ÿ”„ Last Modified: March 9, 2026, 11:16 a.m.

9.8

CVSS3.1

CVE-2025-11252 - SQLi in Signum Technologies' windesk.fm

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Signum Technology Promotion and Training Inc. Windesk.Fm allows SQL Injection.This issue affects windesk.Fm: before v2.3.4.ย  NOTE:ย  The vendor patched the vulnerability after the CVE was published.

๐Ÿ“… Published: Feb. 27, 2026, 12:32 p.m. ๐Ÿ”„ Last Modified: April 20, 2026, 3:45 p.m.

9.8

CVSS3.1

CVE-2025-11251 - SQLi in Dayneks Software's E-Commerce Platform

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dayneks Software Industry and Trade Inc. E-Commerce Platform allows SQL Injection.This issue affects E-Commerce Platform: through 27022026. NOTE: The vendor was contacted early about this disclosuโ€ฆ

๐Ÿ“… Published: Feb. 27, 2026, 11:58 a.m. ๐Ÿ”„ Last Modified: March 25, 2026, 1:51 p.m.

4.8

CVSS4.0

CVE-2026-24352 - Session Fixation in PluXml CMS

PluXml CMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID for a victim and later hijack the authenticated session. The vendor was notified early about this โ€ฆ

๐Ÿ“… Published: Feb. 27, 2026, 11:35 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 5:45 p.m.

5.1

CVSS4.0

CVE-2026-24351 - Stored XSS in PluXml CMS

PluXml CMS is vulnerable to Stored XSS in Static Pages editing functionality. Attacker with editing privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. The vendor was notified early about this vulnerability, but didn't respond with tโ€ฆ

๐Ÿ“… Published: Feb. 27, 2026, 11:35 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 2:15 p.m.

5.1

CVSS4.0

CVE-2026-24350 - Stored XSS in PluXml CMS

PluXml CMS is vulnerable to Stored XSS in file uploading functionality. An authenticated attacker can upload an SVG file containing a malicious payload, which will be executed when a victim clicks the link associated with the uploaded image. In versionย 5.9.0-rc7 clicking the link associated with thโ€ฆ

๐Ÿ“… Published: Feb. 27, 2026, 11:35 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 2:15 p.m.

4.9

CVSS3.1

CVE-2026-2831 - MailArchiver <= 4.5.0 - Authenticated (Admininistrator+) SQL Injection via 'logid' Parameter

The MailArchiver plugin for WordPress is vulnerable to SQL Injection via the โ€˜logidโ€™ parameter in all versions up to, and including, 4.5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticaโ€ฆ

๐Ÿ“… Published: Feb. 27, 2026, 11:22 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 6:15 p.m.

5.1

CVSS4.0

CVE-2026-1434 - Reflected XSS in Omega-PSIR

Omega-PSIR is vulnerable to Reflected XSS via the lang parameter. An attacker can craft a malicious URL that, when opened, causes arbitrary JavaScript to execute in the victimโ€™s browser. This issue was fixed in 4.6.7.

๐Ÿ“… Published: Feb. 27, 2026, 10:32 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 2:15 p.m.
Total resulsts: 349182
Page 1405 of 34,919
ยซ previous page ยป next page
Filters