9.1

CVSS3.1

CVE-2025-40540 - SolarWinds Serv-U Type Confusion Remote Code Execution Vulnerability

A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequent…

πŸ“… Published: Feb. 24, 2026, 7:41 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 2:44 p.m.

9.1

CVSS3.1

CVE-2025-40539 - SolarWinds Serv-U Type Confusion Remote Code Execution Vulnerability

A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequent…

πŸ“… Published: Feb. 24, 2026, 7:40 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 2:44 p.m.

9.1

CVSS3.1

CVE-2025-40538 - SolarWinds Serv-U Broken Access Control Remote Code Execution Vulnerability

A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to create a system admin user and execute arbitrary code as a privileged account via domain admin or group admin privileges. This issue requires administrative privileges to abuse. On W…

πŸ“… Published: Feb. 24, 2026, 7:40 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 2:44 p.m.

8.8

CVSS3.1

CVE-2025-15386 - Responsive Lightbox & Gallery < 2.6.1 - Unauthenticated Stored XSS

The Responsive Lightbox & Gallery WordPress plugin before 2.6.1 is vulnerable to an Unauthenticated Stored-XSS attack due to flawed regex replacement rules that can be abused by posting a comment with a malicious link when lightbox for comments are enabled and then approved.

πŸ“… Published: Feb. 24, 2026, 6 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-15589 - MuYuCMS Template Management Template.php delete_dir_file path traversal

A vulnerability was determined in MuYuCMS 2.7. Affected is the function delete_dir_file of the file application/admin/controller/Template.php of the component Template Management Page. This manipulation of the argument temn/tp causes path traversal. It is possible to initiate the attack remotely. T…

πŸ“… Published: Feb. 24, 2026, 5:52 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:25 p.m.

4.3

CVSS3.1

CVE-2026-24314 - Information Disclosure vulnerability in S/4HANA (Manage Payment Media)

Under certain conditions SAP S/4HANA (Manage Payment Media) allows an authenticated attacker to access information which would otherwise be restricted. This could cause low impact on confidentiality of the application while integrity and availability are not impacted.

πŸ“… Published: Feb. 24, 2026, 5:23 a.m. πŸ”„ Last Modified: April 17, 2026, 4 p.m.

5.3

CVSS4.0

CVE-2026-3070 - SourceCodester Modern Image Gallery App upload.php cross site scripting

A vulnerability was detected in SourceCodester Modern Image Gallery App 1.0. Affected by this vulnerability is an unknown functionality of the file upload.php. The manipulation of the argument filename results in cross site scripting. The attack may be launched remotely. The exploit is now public a…

πŸ“… Published: Feb. 24, 2026, 4:32 a.m. πŸ”„ Last Modified: April 17, 2026, 4 p.m.

6.9

CVSS4.0

CVE-2026-3069 - itsourcecode Document Management System edtlbls.php sql injection

A security vulnerability has been detected in itsourcecode Document Management System 1.0. Affected is an unknown function of the file /edtlbls.php. The manipulation of the argument field1 leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may …

πŸ“… Published: Feb. 24, 2026, 4:02 a.m. πŸ”„ Last Modified: April 18, 2026, 11 a.m.

6.9

CVSS4.0

CVE-2026-3068 - itsourcecode Document Management System deluser.php sql injection

A weakness has been identified in itsourcecode Document Management System 1.0. This impacts an unknown function of the file /deluser.php. Executing a manipulation of the argument user2del can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the publ…

πŸ“… Published: Feb. 24, 2026, 3:32 a.m. πŸ”„ Last Modified: April 18, 2026, 11 a.m.

5.3

CVSS4.0

CVE-2026-3067 - HummerRisk Archive Extraction CommandUtils.java extractZip path traversal

A vulnerability has been found in HummerRisk up to 1.5.0. This issue affects the function extractTarGZ/extractZip of the file hummer-common/hummer-common-core/src/main/java/com/hummer/common/core/utils/CommandUtils.java of the component Archive Extraction. The manipulation leads to path traversal. …

πŸ“… Published: Feb. 24, 2026, 3:32 a.m. πŸ”„ Last Modified: April 17, 2026, 4 p.m.
Total resulsts: 349182
Page 1470 of 34,919
Β« previous page Β» next page
Filters