7.2

CVSS3.1

CVE-2026-37748 -

Visitor Management System 1.0 by sanjay1313 is vulnerable to Unrestricted File Upload in vms/php/admin_user_insert.php and vms/php/update_1.php. The move_uploaded_file() function is called without any MIME type, extension, or content validation, allowing an authenticated admin to upload a PHP webshโ€ฆ

๐Ÿ“… Published: April 21, 2026, midnight ๐Ÿ”„ Last Modified: April 22, 2026, 4:02 p.m.

4.9

CVSS3.1

CVE-2026-35236 - mysql: InnoDB unspecified vulnerability (CPU Apr 2026)

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Serverโ€ฆ

๐Ÿ“… Published: April 21, 2026, midnight ๐Ÿ”„ Last Modified: April 23, 2026, 3:09 p.m.

6.5

CVSS3.1

CVE-2026-34303 - mysql: Optimizer unspecified vulnerability (CPU Apr 2026)

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Myโ€ฆ

๐Ÿ“… Published: April 21, 2026, midnight ๐Ÿ”„ Last Modified: April 23, 2026, 3:09 p.m.

2.7

CVSS3.1

CVE-2026-22001 - mysql: Information Schema unspecified vulnerability (CPU Apr 2026)

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to comโ€ฆ

๐Ÿ“… Published: April 21, 2026, midnight ๐Ÿ”„ Last Modified: April 23, 2026, 3:04 p.m.

8.8

CVSS3.1

CVE-2026-31019 - Website Module Bypass Enables Remote Code Execution in Dolibarr ERP & CRM

In the Website module of Dolibarr ERP & CRM 22.0.4 and below, the application uses blacklist-based filtering to restrict dangerous PHP functions related to system command execution. An authenticated user with permission to edit PHP content can bypass this filtering, resulting in full remote code exโ€ฆ

๐Ÿ“… Published: April 21, 2026, midnight ๐Ÿ”„ Last Modified: April 23, 2026, 4:10 p.m.

6.3

CVSS3.1

CVE-2026-31014 - Crossโ€‘Site Request Forgery Enables Unauthorized User Account Modification

Dovestones Softwares AD Self Update <4.0.0.5 is vulnerable to Cross Site Request Forgery (CSRF). The affected endpoint processes state-changing requests without requiring a CSRF token or equivalent protection. The endpoint accepts application/x-www-form-urlencoded requests, and an originally POST-bโ€ฆ

๐Ÿ“… Published: April 21, 2026, midnight ๐Ÿ”„ Last Modified: April 23, 2026, 4:21 p.m.

4.9

CVSS3.1

CVE-2026-35234 - mysql: Partition unspecified vulnerability (CPU Apr 2026)

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Partition). Supported versions that are affected are 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attackโ€ฆ

๐Ÿ“… Published: April 21, 2026, midnight ๐Ÿ”„ Last Modified: April 23, 2026, 3:10 p.m.

8.4

CVSS3.1

CVE-2026-40706 - NTFS-3G SUID-root Heap Buffer Overflow Enables Privilege Escalation

In NTFS-3G 2022.10.3 before 2026.2.25, a heap buffer overflow exists in ntfs_build_permissions_posix() in acls.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered on the READ path (stat, readdir, open) when pโ€ฆ

๐Ÿ“… Published: April 21, 2026, midnight ๐Ÿ”„ Last Modified: April 22, 2026, 9:23 p.m.

4.9

CVSS3.1

CVE-2026-35239 - mysql: DML unspecified vulnerability (CPU Apr 2026)

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Sโ€ฆ

๐Ÿ“… Published: April 21, 2026, midnight ๐Ÿ”„ Last Modified: April 23, 2026, 3:08 p.m.

4.9

CVSS3.1

CVE-2026-22004 - mysql: InnoDB unspecified vulnerability (CPU Apr 2026)

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Serverโ€ฆ

๐Ÿ“… Published: April 21, 2026, midnight ๐Ÿ”„ Last Modified: April 23, 2026, 3:03 p.m.
Total resulsts: 346903
Page 151 of 34,691
ยซ previous page ยป next page
Filters