5.3

CVSS4.0

CVE-2026-7716 - code-projects Gym Management System In PHP/Windows NT index.php sql injection

A vulnerability was found in code-projects Gym Management System In PHP and Windows NT 1.0. This vulnerability affects unknown code of the file /index.php. Performing a manipulation of the argument day results in sql injection. The attack can be initiated remotely. The exploit has been made public …

📅 Published: May 4, 2026, 12:45 a.m. 🔄 Last Modified: May 4, 2026, 7:44 p.m.

6.5

CVSS3.1

CVE-2026-42367 - GeoVision LPC2011/LPC2211 Web Interface / ssi.cgi privilege escalation vulnerability via leak of Ad…

A privilege escalation vulnerability exists in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to credentials leak. An attacker can visit a webpage to trigger this vulnerability.

📅 Published: May 4, 2026, 12:43 a.m. 🔄 Last Modified: May 5, 2026, 2:45 a.m.

7.4

CVSS3.1

CVE-2026-7371 - GeoVision LPC2011/LPC2211 Web Interface / ssi.cgi reflected cross-site scripting (XSS) vulnerabilit…

Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerabili…

📅 Published: May 4, 2026, 12:43 a.m. 🔄 Last Modified: May 5, 2026, 2:39 a.m.

7.4

CVSS3.1

CVE-2026-42366 - GeoVision LPC2011/LPC2211 Web Interface / ssi.cgi reflected cross-site scripting (XSS) vulnerabilit…

Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerabili…

📅 Published: May 4, 2026, 12:42 a.m. 🔄 Last Modified: May 5, 2026, 2:43 a.m.

8.6

CVSS3.1

CVE-2026-42365 - GeoVision LPC2011/LPC2211 Web Interface guessable session cookie vulnerability

A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted series of HTTP requests can lead to an authentication bypas. An attacker can bruteforce session cookies to trigger this vulnerability.

📅 Published: May 4, 2026, 12:42 a.m. 🔄 Last Modified: May 5, 2026, 2:44 a.m.

9.9

CVSS3.1

CVE-2026-42364 - GeoVision LPC2011/LPC2211 Web Interface / DdnsSetting.cgi OS command injection vulnerability

An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted DDNS configuration can lead to arbitrary command execution. An attacker can modify a configuration value to trigger this vulnerability.

📅 Published: May 4, 2026, 12:41 a.m. 🔄 Last Modified: May 4, 2026, 7:44 p.m.

9.3

CVSS3.1

CVE-2026-7161 - GeoVision GV-IP Device Utility Device Authentication insufficient encryption vulnerability

An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to credentials leak. An attacker can listen to broadcast messages to trigger this vulnerability. When interacting with variou…

📅 Published: May 4, 2026, 12:39 a.m. 🔄 Last Modified: May 4, 2026, 7:44 p.m.

5.3

CVSS4.0

CVE-2026-7715 - ravenwits mcp-server-arangodb MCP tools.ts arango_backup path traversal

A vulnerability has been found in ravenwits mcp-server-arangodb up to 0.4.7. This affects the function arango_backup of the file src/tools.ts of the component MCP Interface. Such manipulation of the argument outputDir leads to path traversal. It is possible to launch the attack remotely. The exploi…

📅 Published: May 4, 2026, 12:30 a.m. 🔄 Last Modified: May 4, 2026, 12:30 a.m.

6.9

CVSS4.0

CVE-2026-7714 - crocodilestick Calibre-Web-Automated Admin Endpoint cwa_functions.py missing authentication

A flaw has been found in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this issue is some unknown functionality of the file cps/cwa_functions.py of the component Admin Endpoint. This manipulation causes missing authentication. It is possible to initiate the attack remotely. The expl…

📅 Published: May 4, 2026, 12:15 a.m. 🔄 Last Modified: May 4, 2026, 4:06 p.m.

5.3

CVSS4.0

CVE-2026-7713 - crocodilestick Calibre-Web-Automated Kobo auth-token Route kobo_auth.py generate_auth_token imprope…

A vulnerability was detected in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this vulnerability is the function generate_auth_token of the file cps/kobo_auth.py of the component Kobo auth-token Route. The manipulation results in improper authorization. The attack may be performed f…

📅 Published: May 4, 2026, midnight 🔄 Last Modified: May 4, 2026, 4:06 p.m.
Total resulsts: 349182
Page 141 of 34,919
« previous page » next page
Filters