8.4

CVSS4.0

CVE-2026-40551 - Use of Client-Side Authentication in mpGabinet

mpGabinet performs client-side authentication. An attacker with access to any application instance connected to the backend server can bypass the login verification process by manipulating the application binary and authenticate as an arbitrary user. This issue affects mpGabinet version 23.12.19…

📅 Published: April 28, 2026, 1:13 p.m. 🔄 Last Modified: April 29, 2026, 10:10 a.m.

6.9

CVSS4.0

CVE-2026-40550 - Privilege Escalation in mpGabinet

mpGabinet is vulnerable to Privilege Escalation due to excessive database privileges assigned to the user used by the application. An attacker with access to any running application instance connected to the backend server can extract database credentials from the application’s memory by inspecting…

📅 Published: April 28, 2026, 1:12 p.m. 🔄 Last Modified: April 29, 2026, 10:10 a.m.

6.5

CVSS3.1

CVE-2026-6706 -

Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to read documentation content from unauthorized vaults via a crafted API request. This issue affects Server: from 2026.1.6.0 through 2026.1.14.0, through 2025.3.18.0.

📅 Published: April 28, 2026, 1:11 p.m. 🔄 Last Modified: May 4, 2026, 1:37 p.m.

6.7

CVSS4.0

CVE-2026-5944 - Cisco Intersight Device Connector for Nutanix Prism Central Unauthenticated API Access

An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The service exposes an API passthrough endpoint on TCP port 7373 that is accessible within the network scope of the deployment environment without authentication. An unauthenticate…

📅 Published: April 28, 2026, 1:06 p.m. 🔄 Last Modified: April 28, 2026, 2:16 p.m.

6.9

CVSS4.0

CVE-2026-7272 - WilliamCloudQi matlab-mcp-server MCP index.ts execute_matlab_code path traversal

A flaw has been found in WilliamCloudQi matlab-mcp-server up to ab88f6b9bf5f36f725e8628029f7f6dd0d9913ca. The affected element is the function generate_matlab_code/execute_matlab_code of the file src/index.ts of the component MCP Interface. Executing a manipulation of the argument scriptPath can le…

📅 Published: April 28, 2026, 1 p.m. 🔄 Last Modified: April 29, 2026, 10:10 a.m.

6.9

CVSS4.0

CVE-2026-7271 - DV0x creative-ad-agent creative-ad-agent-server sdk-server.ts path traversal

A vulnerability was detected in DV0x creative-ad-agent up to 751b9e5146604dc65049bd0f62dcbdad6212f8a3. Impacted is an unknown function of the file server/sdk-server.ts of the component creative-ad-agent-server. Performing a manipulation of the argument req.params results in path traversal. Remote e…

📅 Published: April 28, 2026, 12:15 p.m. 🔄 Last Modified: April 29, 2026, 10:10 a.m.

4.8

CVSS4.0

CVE-2026-7269 - SourceCodester Pharmacy Sales and Inventory System index.php cross site scripting

A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected is an unknown function of the file /index.php?page=product. Performing a manipulation of the argument ID results in cross site scripting. It is possible to initiate the attack remotely. The exploit has bee…

📅 Published: April 28, 2026, noon 🔄 Last Modified: April 29, 2026, 2:22 p.m.

7.3

CVSS3.1

CVE-2026-5435 - Potential buffer overflow in ns_sprintrrf TSIG handling path

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.

📅 Published: April 28, 2026, 11:58 a.m. 🔄 Last Modified: May 5, 2026, 5:38 p.m.

8.5

CVSS4.0

CVE-2026-5781 - Multiple vulnerabilities in MphRx's Minerva

An authorization vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/moUser/update' endpoint, could allow an authenticated user with user modification privileges to escalate their privileges by sending an HTTP request with a manipulated 'identifier' field. Successful exploitation…

📅 Published: April 28, 2026, 11:44 a.m. 🔄 Last Modified: May 5, 2026, 2:24 p.m.

8.5

CVSS4.0

CVE-2026-5780 - Multiple vulnerabilities in MphRx's Minerva

An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the endpoint '/minerva/moUser/show/'. If this vulnerability is successfully exploited, an authenticated user can access the data of other registered users simply by modifying the ID. This allows an a…

📅 Published: April 28, 2026, 11:43 a.m. 🔄 Last Modified: May 5, 2026, 2:22 p.m.
Total resulsts: 348415
Page 145 of 34,842
« previous page » next page
Filters