7.7

CVSS3.1

CVE-2026-41649 - Outline has IDOR in document share creation that allows unauthorized access to private documents acโ€ฆ

Outline is a service that allows for collaborative documentation. The `shares.create` API endpoint starting in version 0.86.0 and prior to version 1.7.0 has an insecure direct object reference.. When both `collectionId` and `documentId` are provided in the request, the authorization logic only checโ€ฆ

๐Ÿ“… Published: April 28, 2026, 8:11 p.m. ๐Ÿ”„ Last Modified: May 1, 2026, 3:54 p.m.

6.9

CVSS4.0

CVE-2026-7315 - eiceblue spire-pdf-mcp-server PDF File server.py get_pdf_path path traversal

A flaw has been found in eiceblue spire-pdf-mcp-server 0.1.1. This impacts the function get_pdf_path of the file src/spire_pdf_mcp/server.py of the component PDF File Handler. Executing a manipulation of the argument filepath can lead to path traversal. The attack can be launched remotely. The explโ€ฆ

๐Ÿ“… Published: April 28, 2026, 8 p.m. ๐Ÿ”„ Last Modified: April 29, 2026, 9:16 p.m.

6.9

CVSS4.0

CVE-2026-7314 - eiceblue spire-doc-mcp-server base.py get_doc_path path traversal

A vulnerability was detected in eiceblue spire-doc-mcp-server 1.0.0. This affects the function get_doc_path of the file src/spire_doc_mcp/api/base.py. Performing a manipulation of the argument document_name results in path traversal. The attack can be initiated remotely. The exploit is now public aโ€ฆ

๐Ÿ“… Published: April 28, 2026, 7:45 p.m. ๐Ÿ”„ Last Modified: April 29, 2026, 1:58 p.m.

6.3

CVSS4.0

CVE-2026-7306 - Xuxueli xxl-job OpenAPI Endpoint OpenApiController.java hard-coded key

A security vulnerability has been detected in Xuxueli xxl-job up to 3.3.2. The impacted element is an unknown function of the file xxl-job-admin/src/main/java/com/xxl/job/admin/scheduler/openapi/OpenApiController.java of the component OpenAPI Endpoint. Such manipulation of the argument default_tokeโ€ฆ

๐Ÿ“… Published: April 28, 2026, 7:30 p.m. ๐Ÿ”„ Last Modified: April 30, 2026, 12:58 p.m.

5.3

CVSS4.0

CVE-2026-7305 - Xuxueli xxl-job trigger Endpoint XxlJobServiceImpl.java triggerJob server-side request forgery

A weakness has been identified in Xuxueli xxl-job up to 3.3.2. The affected element is the function triggerJob of the file xxl-job-admin/src/main/java/com/xxl/job/admin/service/impl/XxlJobServiceImpl.java of the component trigger Endpoint. This manipulation of the argument addressList causes serverโ€ฆ

๐Ÿ“… Published: April 28, 2026, 7:15 p.m. ๐Ÿ”„ Last Modified: April 29, 2026, 1:09 p.m.

6.3

CVSS4.0

CVE-2026-7303 - Xuxueli xxl-job Execution Log JobLogController.java logDetailCat resource injection

A security flaw has been discovered in Xuxueli xxl-job up to 3.3.2. Impacted is the function logDetailCat of the file xxl-job-admin/src/main/java/com/xxl/job/admin/controller/biz/JobLogController.java of the component Execution Log Handler. The manipulation of the argument logId results in improperโ€ฆ

๐Ÿ“… Published: April 28, 2026, 7 p.m. ๐Ÿ”„ Last Modified: April 29, 2026, 1:11 p.m.

4.8

CVSS4.0

CVE-2026-7297 - SourceCodester Pizzafy Ecommerce System ajax.php save_user cross site scripting

A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects the function save_user of the file /admin/ajax.php?action=save_user. Executing a manipulation of the argument Name can lead to cross site scripting. The attack can be executed remotely. The expโ€ฆ

๐Ÿ“… Published: April 28, 2026, 6:45 p.m. ๐Ÿ”„ Last Modified: April 28, 2026, 11:30 p.m.

4.8

CVSS4.0

CVE-2026-7296 - SourceCodester Pizzafy Ecommerce System ajax.php save_order cross site scripting

A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_order of the file /admin/ajax.php?action=save_order. Performing a manipulation of the argument first_name results in cross site scripting. Remote exploitation of the attack is possible. The explโ€ฆ

๐Ÿ“… Published: April 28, 2026, 6:30 p.m. ๐Ÿ”„ Last Modified: April 29, 2026, 9:16 p.m.

4.8

CVSS4.0

CVE-2026-7295 - SourceCodester Pizzafy Ecommerce System ajax.php save_menu cross site scripting

A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this issue is the function save_menu of the file /admin/ajax.php?action=save_menu. Such manipulation of the argument Name leads to cross site scripting. The attack may be launched remotely. The exploit has beโ€ฆ

๐Ÿ“… Published: April 28, 2026, 6:15 p.m. ๐Ÿ”„ Last Modified: April 29, 2026, 2:56 p.m.

7.3

CVSS4.0

CVE-2026-42432 - OpenClaw < 2026.4.8 - Command Escalation via Node Pairing Reconnect Bypass

OpenClaw before 2026.4.8 contains a privilege escalation vulnerability allowing previously paired nodes to reconnect with exec-capable commands without operator.admin scope requirement. Attackers can bypass re-pairing authentication to execute privileged commands on the local assistant system.

๐Ÿ“… Published: April 28, 2026, 6:10 p.m. ๐Ÿ”„ Last Modified: April 28, 2026, 6:10 p.m.
Total resulsts: 348618
Page 156 of 34,862
ยซ previous page ยป next page
Filters