6.9

CVSS4.0

CVE-2026-7271 - DV0x creative-ad-agent creative-ad-agent-server sdk-server.ts path traversal

A vulnerability was detected in DV0x creative-ad-agent up to 751b9e5146604dc65049bd0f62dcbdad6212f8a3. Impacted is an unknown function of the file server/sdk-server.ts of the component creative-ad-agent-server. Performing a manipulation of the argument req.params results in path traversal. Remote e…

πŸ“… Published: April 28, 2026, 12:15 p.m. πŸ”„ Last Modified: April 29, 2026, 10:10 a.m.

4.8

CVSS4.0

CVE-2026-7269 - SourceCodester Pharmacy Sales and Inventory System index.php cross site scripting

A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected is an unknown function of the file /index.php?page=product. Performing a manipulation of the argument ID results in cross site scripting. It is possible to initiate the attack remotely. The exploit has bee…

πŸ“… Published: April 28, 2026, noon πŸ”„ Last Modified: April 29, 2026, 2:22 p.m.

7.3

CVSS3.1

CVE-2026-5435 - Potential buffer overflow in ns_sprintrrf TSIG handling path

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.

πŸ“… Published: April 28, 2026, 11:58 a.m. πŸ”„ Last Modified: May 5, 2026, 5:38 p.m.

8.5

CVSS4.0

CVE-2026-5781 - Multiple vulnerabilities in MphRx's Minerva

An authorization vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/moUser/update' endpoint, could allow an authenticated user with user modification privileges to escalate their privileges by sending an HTTP request with a manipulated 'identifier' field. Successful exploitation…

πŸ“… Published: April 28, 2026, 11:44 a.m. πŸ”„ Last Modified: May 5, 2026, 2:24 p.m.

8.5

CVSS4.0

CVE-2026-5780 - Multiple vulnerabilities in MphRx's Minerva

An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the endpoint '/minerva/moUser/show/'. If this vulnerability is successfully exploited, an authenticated user can access the data of other registered users simply by modifying the ID. This allows an a…

πŸ“… Published: April 28, 2026, 11:43 a.m. πŸ”„ Last Modified: May 5, 2026, 2:22 p.m.

9.4

CVSS4.0

CVE-2026-5779 - Multiple vulnerabilities in MphRx's Minerva

An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/user/updateUserProfile' endpoint. This allows an authenticated user to modify the information of other registered users. Successful exploitation of this vulnerability allows an authenti…

πŸ“… Published: April 28, 2026, 11:41 a.m. πŸ”„ Last Modified: May 5, 2026, 2:20 p.m.

5.3

CVSS4.0

CVE-2026-7268 - SourceCodester Pizzafy Ecommerce System ajax.php save_category sql injection

A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. This impacts the function save_category of the file /admin/ajax.php?action=save_category. Such manipulation of the argument Name leads to sql injection. The attack may be performed from remote. The exploit has been discl…

πŸ“… Published: April 28, 2026, 11:15 a.m. πŸ”„ Last Modified: April 28, 2026, 12:30 p.m.

5.3

CVSS4.0

CVE-2026-7267 - SourceCodester Pizzafy Ecommerce System view_prod.php sql injection

A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. This affects an unknown function of the file /view_prod.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.

πŸ“… Published: April 28, 2026, 11 a.m. πŸ”„ Last Modified: April 28, 2026, 1:49 p.m.

5.3

CVSS4.0

CVE-2026-7266 - SourceCodester Pizzafy Ecommerce System ajax.php save_order sql injection

A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. The impacted element is the function save_order of the file /admin/ajax.php?action=save_order. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit is now public an…

πŸ“… Published: April 28, 2026, 10:45 a.m. πŸ”„ Last Modified: April 28, 2026, 2:33 p.m.

5.3

CVSS4.0

CVE-2026-7265 - SourceCodester Pizzafy Ecommerce System index.php category sql injection

A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the function Category of the file pizza/index.php?page=category. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit …

πŸ“… Published: April 28, 2026, 10:30 a.m. πŸ”„ Last Modified: April 28, 2026, 1 p.m.
Total resulsts: 348450
Page 149 of 34,845
Β« previous page Β» next page
Filters