4.2

CVSS3.1

CVE-2026-32602 - Homarr has a Race Condition in Invite Token Registration (TOCTOU)

Homarr is an open-source dashboard. Prior to 1.57.0, the user registration endpoint (/api/trpc/user.register) is vulnerable to a race condition that allows an attacker to create multiple user accounts from a single-use invite token. The registration flow performs three sequential database operation…

πŸ“… Published: April 6, 2026, 2:42 p.m. πŸ”„ Last Modified: April 10, 2026, 6 p.m.

7.2

CVSS3.1

CVE-2026-29047 - GLPI has an Authenticated SQL Injection via log exports

GLPI is a free asset and IT management software package. From 10.0.0 to before 10.0.24 and 11.0.6, an authenticated user can perform a SQL injection via the logs export feature. This vulnerability is fixed in 10.0.24 and 11.0.6.

πŸ“… Published: April 6, 2026, 2:39 p.m. πŸ”„ Last Modified: April 8, 2026, 7:50 p.m.

8.1

CVSS3.1

CVE-2026-26263 - GLPI has an Unauthenticated SQL Injection via Search engine

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GLPI's Search engine. This vulnerability is fixed in 11.0.6.

πŸ“… Published: April 6, 2026, 2:36 p.m. πŸ”„ Last Modified: April 8, 2026, 7:50 p.m.

7.5

CVSS3.1

CVE-2026-26027 - GLPI has an Unauthenticated Stored XSS via inventory

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store an XSS payload through the inventory endpoint. This vulnerability is fixed in 11.0.6.

πŸ“… Published: April 6, 2026, 2:35 p.m. πŸ”„ Last Modified: April 8, 2026, 7:50 p.m.

9.1

CVSS3.1

CVE-2026-26026 - GLPI has a Server-Side Template Injection via Double-Compilation

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, template injection by an administrator lead to RCE. This vulnerability is fixed in 11.0.6.

πŸ“… Published: April 6, 2026, 2:33 p.m. πŸ”„ Last Modified: April 8, 2026, 7:50 p.m.

7.2

CVSS3.1

CVE-2026-25932 - GLPI has Stored XSS in Supplier 'Website' field

GLPI is a Free Asset and IT Management Software package. From 0.60 to before 10.0.24, an authenticated technician user can store an XSS payload in a supplier fields. This vulnerability is fixed in 10.0.24.

πŸ“… Published: April 6, 2026, 2:31 p.m. πŸ”„ Last Modified: April 8, 2026, 7:50 p.m.

6.9

CVSS4.0

CVE-2026-5663 - OFFIS DCMTK storescp storescp.cc executeOnEndOfStudy os command injection

A security flaw has been discovered in OFFIS DCMTK up to 3.7.0. This impacts the function executeOnReception/executeOnEndOfStudy of the file dcmnet/apps/storescp.cc of the component storescp. Performing a manipulation results in os command injection. Remote exploitation of the attack is possible. T…

πŸ“… Published: April 6, 2026, 2:15 p.m. πŸ”„ Last Modified: April 7, 2026, 2:06 p.m.

6.9

CVSS4.0

CVE-2026-5661 - Free5GC NGSetupRequest denial of service

A vulnerability was identified in Free5GC 4.2.0. This affects an unknown function of the component NGSetupRequest Handler. Such manipulation leads to denial of service. The attack may be launched remotely. The exploit is publicly available and might be used.

πŸ“… Published: April 6, 2026, 2:08 p.m. πŸ”„ Last Modified: April 6, 2026, 3:17 p.m.

5.3

CVSS4.0

CVE-2026-5660 - itsourcecode Construction Management System Parameter borrowed_equip.php sql injection

A vulnerability was determined in itsourcecode Construction Management System 1.0. The impacted element is an unknown function of the file /borrowed_equip.php of the component Parameter Handler. This manipulation of the argument emp causes sql injection. The attack may be initiated remotely. The ex…

πŸ“… Published: April 6, 2026, 1:45 p.m. πŸ”„ Last Modified: April 6, 2026, 2:16 p.m.

5

CVSS3.1

CVE-2026-5704 - Tar: tar: hidden file injection via crafted archives

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files ont…

πŸ“… Published: April 6, 2026, 1:36 p.m. πŸ”„ Last Modified: April 11, 2026, 6:09 p.m.
Total resulsts: 343948
Page 149 of 34,395
Β« previous page Β» next page
Filters