8.7

CVSS4.0

CVE-2026-5628 - Belkin F9K1015 Setting formSetSystemSettings stack-based overflow

A security vulnerability has been detected in Belkin F9K1015 1.00.10. Impacted is the function formSetSystemSettings of the file /goform/formSetSystemSettings of the component Setting Handler. The manipulation of the argument webpage leads to stack-based buffer overflow. Remote exploitation of the โ€ฆ

๐Ÿ“… Published: April 6, 2026, 5:30 a.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:20 p.m.

5.3

CVSS4.0

CVE-2026-5625 - assafelovic gpt-researcher WebSocket researcher.py cross site scripting

A weakness has been identified in assafelovic gpt-researcher up to 3.4.3. This issue affects some unknown processing of the file gpt_researcher/skills/researcher.py of the component WebSocket Interface. Executing a manipulation of the argument task can lead to cross site scripting. The attack may bโ€ฆ

๐Ÿ“… Published: April 6, 2026, 5:15 a.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:20 p.m.

5.3

CVSS4.0

CVE-2026-5624 - ProjectSend upload.php cross-site request forgery

A security flaw has been discovered in ProjectSend r2002. This vulnerability affects unknown code of the file upload.php. Performing a manipulation results in cross-site request forgery. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. Uโ€ฆ

๐Ÿ“… Published: April 6, 2026, 5 a.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:20 p.m.

5.3

CVSS4.0

CVE-2026-5623 - hcengineering Huly Platform Import Endpoint index.ts server-side request forgery

A vulnerability was identified in hcengineering Huly Platform 0.7.382. This affects an unknown part of the file server/front/src/index.ts of the component Import Endpoint. Such manipulation leads to server-side request forgery. The attack can be launched remotely. The exploit is publicly available โ€ฆ

๐Ÿ“… Published: April 6, 2026, 4:45 a.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:20 p.m.

6.3

CVSS4.0

CVE-2026-5622 - hcengineering Huly Platform JWT Token token.ts hard-coded key

A vulnerability was determined in hcengineering Huly Platform 0.7.382. Affected by this issue is some unknown functionality of the file foundations/core/packages/token/src/token.ts of the component JWT Token Handler. This manipulation of the argument SERVER_SECRET with the input secret causes use oโ€ฆ

๐Ÿ“… Published: April 6, 2026, 4:30 a.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:20 p.m.

4.8

CVSS4.0

CVE-2026-5621 - ChrisChinchilla Vale-MCP HTTP index.ts os command injection

A vulnerability was found in ChrisChinchilla Vale-MCP up to 0.1.0. Affected by this vulnerability is an unknown functionality of the file src/index.ts of the component HTTP Interface. The manipulation of the argument config_path results in os command injection. Attacking locally is a requirement. Tโ€ฆ

๐Ÿ“… Published: April 6, 2026, 4:15 a.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:20 p.m.

5.3

CVSS4.0

CVE-2026-5620 - itsourcecode Construction Management System Parameter borrowed_equip_report.php sql injection

A vulnerability has been found in itsourcecode Construction Management System 1.0. Affected is an unknown function of the file /borrowed_equip_report.php of the component Parameter Handler. The manipulation of the argument Home leads to sql injection. It is possible to initiate the attack remotely.โ€ฆ

๐Ÿ“… Published: April 6, 2026, 4 a.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:20 p.m.

4.8

CVSS4.0

CVE-2026-5619 - Braffolk mcp-summarization-functions summarize_command mcp-server.ts os command injection

A flaw has been found in Braffolk mcp-summarization-functions up to 0.1.5. This impacts an unknown function of the file src/server/mcp-server.ts of the component summarize_command. Executing a manipulation of the argument command can lead to os command injection. The attack requires local access. Tโ€ฆ

๐Ÿ“… Published: April 6, 2026, 3:45 a.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:20 p.m.

6.3

CVSS4.0

CVE-2026-5618 - kalcaddle kodbox shareMake/shareCheck server-side request forgery

A vulnerability was detected in kalcaddle kodbox up to 1.64. This affects an unknown function of the component shareMake/shareCheck. Performing a manipulation of the argument siteFrom/siteTo results in server-side request forgery. The attack is possible to be carried out remotely. The complexity ofโ€ฆ

๐Ÿ“… Published: April 6, 2026, 3:30 a.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:20 p.m.

6.9

CVSS4.0

CVE-2026-5616 - JeecgBoot AI Chat JeecgBizToolsProvider.java missing authentication

A security vulnerability has been detected in JeecgBoot 3.9.0/3.9.1. The impacted element is an unknown function of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/airag/JeecgBizToolsProvider.java of the component AI Chat Module. Such manipulation leads to mโ€ฆ

๐Ÿ“… Published: April 6, 2026, 3:15 a.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:20 p.m.
Total resulsts: 344072
Page 165 of 34,408
ยซ previous page ยป next page
Filters