6.9

CVSS4.0

CVE-2026-5805 - code-projects Easy Blog Site contact_us.php sql injection

A weakness has been identified in code-projects Easy Blog Site up to 1.0. The impacted element is an unknown function of the file /users/contact_us.php. Executing a manipulation of the argument Name can lead to sql injection. The attack can be launched remotely. The exploit has been made available …

📅 Published: April 8, 2026, 8:30 p.m. 🔄 Last Modified: April 8, 2026, 8:30 p.m.

7.3

CVSS4.0

CVE-2026-39883 - OpenTelemetry-Go has an incomplete fix for CVE-2026-24051: BSD kenv command not using absolute path…

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms. This vulnerab…

📅 Published: April 8, 2026, 8:26 p.m. 🔄 Last Modified: April 8, 2026, 8:26 p.m.

8.1

CVSS3.1

CVE-2026-5436 - MW WP Form <= 5.1.1 - Unauthenticated Arbitrary File Move via regenerate_upload_file_keys

The MW WP Form plugin for WordPress is vulnerable to Arbitrary File Move/Read in all versions up to and including 5.1.1. This is due to insufficient validation of the $name parameter (upload field key) passed to the generate_user_file_dirpath() function, which uses WordPress's path_join() — a funct…

📅 Published: April 8, 2026, 8:25 p.m. 🔄 Last Modified: April 8, 2026, 8:25 p.m.

6.4

CVSS3.1

CVE-2026-5451 - Extensions for Leaflet Map <= 4.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via '…

The Extensions for Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'elevation-track' shortcode in all versions up to, and including, 4.14. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…

📅 Published: April 8, 2026, 8:25 p.m. 🔄 Last Modified: April 8, 2026, 8:25 p.m.

5.3

CVSS3.1

CVE-2026-39882 - OpenTelemetry-Go OTLP HTTP exporters read unbounded HTTP response bodies

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to 1.43.0, the otlp HTTP exporters (traces/metrics/logs) read the full HTTP response body into an in-memory bytes.Buffer without a size cap. This is exploitable for memory exhaustion when the configured collector endpoint is attacker…

📅 Published: April 8, 2026, 8:24 p.m. 🔄 Last Modified: April 8, 2026, 8:24 p.m.

5

CVSS3.1

CVE-2026-39881 - Vim Ex command injection in Vims NetBeans integration

Vim is an open source, command line text editor. Prior to 9.2.0316, a command injection vulnerability in Vim's netbeans interface allows a malicious netbeans server to execute arbitrary Ex commands when Vim connects to it, via unsanitized strings in the defineAnnoType and specialKeys protocol messa…

📅 Published: April 8, 2026, 8:18 p.m. 🔄 Last Modified: April 8, 2026, 8:18 p.m.

8.2

CVSS3.1

CVE-2026-39429 - kcp's cache server is accessible without authentication or authorization checks

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.30.3 and 0.29.3, the cache server is directly exposed by the root shard and has no authentication or authorization in place. This allows anyone who can access the root shard t…

📅 Published: April 8, 2026, 8:16 p.m. 🔄 Last Modified: April 8, 2026, 8:16 p.m.

5.3

CVSS4.0

CVE-2026-5803 - bigsk1 openai-realtime-ui API Proxy Endpoint server.js server-side request forgery

A security flaw has been discovered in bigsk1 openai-realtime-ui up to 188ccde27fdf3d8fab8da81f3893468f53b2797c. The affected element is an unknown function of the file server.js of the component API Proxy Endpoint. Performing a manipulation of the argument Query results in server-side request forg…

📅 Published: April 8, 2026, 8:15 p.m. 🔄 Last Modified: April 8, 2026, 8:15 p.m.

5.9

CVSS3.1

CVE-2026-39844 - NiceGUI has a Path Traversal in NiceGUI Upload Filename on Windows via Backslash Bypass of PurePosi…

NiceGUI is a Python-based UI framework. Prior to 3.10.0, Since PurePosixPath only recognizes forward slashes (/) as path separators, an attacker can bypass this sanitization on Windows by using backslashes (\) in the upload filename. Applications that construct file paths using file.name (a pattern…

📅 Published: April 8, 2026, 8:13 p.m. 🔄 Last Modified: April 8, 2026, 8:13 p.m.

8.5

CVSS4.0

CVE-2026-39416 - Stored XSS in modal item preview for long item content in AIL Framework

AIL framework is an open-source platform to collect, crawl, process and analyse unstructured data. Prior to 6.8, a stored cross-site scripting (XSS) vulnerability was identified in the modal item preview functionality. When item content longer than 800 characters was processed, attacker-controlled …

📅 Published: April 8, 2026, 8:11 p.m. 🔄 Last Modified: April 8, 2026, 8:11 p.m.
Total resulsts: 343436
Page 15 of 34,344
« previous page » next page
Filters