5.1

CVSS4.0

CVE-2025-40986 - Reflected Cross-Site Scripting in PideTuCita

Reflected Cross-Site Scripting (XSS) vulnerability in PideTuCita. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL using the endpoint 'cookies/indes.php/<XSS>'. This vulnerability can be exploited to steal confidential user …

πŸ“… Published: Feb. 23, 2026, 10:31 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-40701 - Reflected Cross-Site scripting (XSS) in SOTE's SOTESHOP

Reflected Cross-Site Scripting vulnerability in SOTESHOP, version 8.3.4. THis vulnerability allows an attacker execute JavaScript code in the victim's browser when a malicious URL with the 'id' parameter in '/adsTracker/checkAds' is sent to the victim. The vulnerability can be exploited to steal se…

πŸ“… Published: Feb. 23, 2026, 10:23 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2026-2984 - SourceCodester Student Result Management System drop_user.php denial of service

A vulnerability was identified in SourceCodester Student Result Management System 1.0. This affects an unknown function of the file /admin/core/drop_user.php. Such manipulation of the argument ID leads to denial of service. The attack can be executed remotely. The exploit is publicly available and …

πŸ“… Published: Feb. 23, 2026, 10:02 a.m. πŸ”„ Last Modified: April 18, 2026, 11:15 a.m.

6.9

CVSS4.0

CVE-2026-2983 - SourceCodester Student Result Management System Bulk Import import_users.php access control

A vulnerability was determined in SourceCodester Student Result Management System 1.0. The impacted element is an unknown function of the file /admin/core/import_users.php of the component Bulk Import. This manipulation of the argument File causes improper access controls. Remote exploitation of th…

πŸ“… Published: Feb. 23, 2026, 9:32 a.m. πŸ”„ Last Modified: April 17, 2026, 4:30 p.m.

9.3

CVSS4.0

CVE-2025-41002 - SQL injection in Infoticketing

SQL injection vulnerability in Infoticketing. This vulnerability allows an unauthenticated attacker to retrieve, create, update, and delete the database by sending a POST request using the 'code'Β parameter in '/components/cart/cartApplyDiscount.php'.

πŸ“… Published: Feb. 23, 2026, 9:30 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2026-2981 - UTT HiPER 810G formTaskEdit_ap strcpy buffer overflow

A vulnerability was found in UTT HiPER 810G up to 1.7.7-1711. The affected element is the function strcpy of the file /goform/formTaskEdit_ap. The manipulation of the argument txtMin2 results in buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used.

πŸ“… Published: Feb. 23, 2026, 9:02 a.m. πŸ”„ Last Modified: April 18, 2026, 11:15 a.m.

8.8

CVSS3.1

CVE-2026-25747 - Apache Camel LevelDB: Deserialization of Untrusted Data in Camel LevelDB

Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes data read from the LevelDB aggregation repository using java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. A…

πŸ“… Published: Feb. 23, 2026, 8:45 a.m. πŸ”„ Last Modified: April 15, 2026, 8:30 p.m.

9.1

CVSS3.1

CVE-2026-23552 - Apache Camel: Camel-Keycloak: Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy

Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component.Β  The Camel-Keycloak KeycloakSecurityPolicy does not validate the iss (issuer) claim of JWT tokens against the configured realm. A token issued by one Keycloak realm is silently accepted by a policy confi…

πŸ“… Published: Feb. 23, 2026, 8:45 a.m. πŸ”„ Last Modified: April 18, 2026, 11:15 a.m.

8.6

CVSS4.0

CVE-2026-2980 - UTT HiPER 810G setSysAdm strcpy buffer overflow

A vulnerability has been found in UTT HiPER 810G up to 1.7.7-1711. Impacted is the function strcpy of the file /goform/setSysAdm. The manipulation of the argument passwd1 leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

πŸ“… Published: Feb. 23, 2026, 8:32 a.m. πŸ”„ Last Modified: April 17, 2026, 4:30 p.m.

5.3

CVSS4.0

CVE-2026-2979 - FastApiAdmin Scheduled Task API controller.py user_avatar_upload_controller unrestricted upload

A flaw has been found in FastApiAdmin up to 2.2.0. This issue affects the function user_avatar_upload_controller of the file /backend/app/api/v1/module_system/user/controller.py of the component Scheduled Task API. Executing a manipulation can lead to unrestricted upload. The attack can be launched…

πŸ“… Published: Feb. 23, 2026, 8:02 a.m. πŸ”„ Last Modified: April 18, 2026, 11:15 a.m.
Total resulsts: 349182
Page 1483 of 34,919
Β« previous page Β» next page
Filters