9.1

CVSS3.1

CVE-2026-21643 -

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

๐Ÿ“… Published: Feb. 6, 2026, 8:24 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, midnight

8.4

CVSS3.1

CVE-2026-24926 - Outโ€‘ofโ€‘Bounds Write in HarmonyOS Camera Module

Out-of-bounds write vulnerability in the camera module. Impact: Successful exploitation of this vulnerability may affect availability.

๐Ÿ“… Published: Feb. 6, 2026, 8:23 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 11 p.m.

7.3

CVSS3.1

CVE-2026-24925 - Heap-Based Buffer Overflow in Image Module

Heap-based buffer overflow vulnerability in the image module. Impact: Successful exploitation of this vulnerability may affect availability.

๐Ÿ“… Published: Feb. 6, 2026, 8:22 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 11 p.m.

5.3

CVSS3.1

CVE-2026-2100 - P11-kit: null dereference via c_derivekey with specific null parameters

A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentiallโ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 8:08 a.m. ๐Ÿ”„ Last Modified: April 25, 2026, 1:11 a.m.

2.3

CVSS4.0

CVE-2026-2010 - Sanluan PublicCMS Trade Payment TradePaymentService.java paid improper authorization

A vulnerability has been found in Sanluan PublicCMS up to 4.0.202506.d/5.202506.d/6.202506.d. Impacted is the function Paid of the file publiccms-parent/publiccms-trade/src/main/java/com/publiccms/logic/service/trade/TradePaymentService.java of the component Trade Payment Handler. The manipulation โ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 8:02 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 11 p.m.

9.2

CVSS4.0

CVE-2026-21626 - Extension - stackideas.com - Information disclosure in post custom fields in EasyDiscuss 1.0.0-5.0.โ€ฆ

Access control settings for forum post custom fields are not applied to the JSON output type, leading to an ACL violation vector an information disclosure

๐Ÿ“… Published: Feb. 6, 2026, 7:49 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 6:30 p.m.

5.3

CVSS4.0

CVE-2026-2009 - SourceCodester Gas Agency Management System createUser.php access control

A flaw has been found in SourceCodester Gas Agency Management System 1.0. This issue affects some unknown processing of the file /gasmark/php_action/createUser.php. Executing a manipulation can lead to improper access controls. It is possible to launch the attack remotely. The exploit has been publโ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 7:32 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 1:45 p.m.

6.4

CVSS3.1

CVE-2026-1279 - Employee Directory <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'form_tiโ€ฆ

The Employee Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_title' parameter in the `search_employee_directory` shortcode in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for autโ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 7:24 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:32 p.m.

5.3

CVSS4.0

CVE-2026-2008 - abhiphile fermat-mcp eqn_chart.py eqn_chart code injection

A vulnerability was detected in abhiphile fermat-mcp up to 47f11def1cd37e45dd060f30cdce346cbdbd6f0a. This vulnerability affects the function eqn_chart of the file fmcp/mpl_mcp/core/eqn_chart.py. Performing a manipulation of the argument equations results in code injection. It is possible to initiatโ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 7:02 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 6:30 p.m.

6.4

CVSS3.1

CVE-2026-1401 - Tune Library <= 1.6.3 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scriโ€ฆ

The Tune Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via CSV import in all versions up to, and including, 1.6.3. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Subโ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 6:46 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:24 p.m.
Total resulsts: 348208
Page 1680 of 34,821
ยซ previous page ยป next page
Filters