8.8

CVSS3.1

CVE-2026-28805 - OpenSTAManager: Time-Based Blind SQL Injection via `options[stato]` Parameter

OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, multiple AJAX select handlers in OpenSTAManager are vulnerable to Time-Based Blind SQL Injection through the options[stato] GET parameter. The user-supplied value is read from $supe…

πŸ“… Published: April 2, 2026, 1:44 p.m. πŸ”„ Last Modified: April 2, 2026, 8:21 p.m.

7.2

CVSS3.1

CVE-2026-29782 - OpenSTAManager: Remote Code Execution via Insecure Deserialization in OAuth2

OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, the oauth2.php file in OpenSTAManager is an unauthenticated endpoint ($skip_permissions = true). It loads a record from the zz_oauth2 table using the attacker-controlled GET paramet…

πŸ“… Published: April 2, 2026, 1:42 p.m. πŸ”„ Last Modified: April 2, 2026, 8:12 p.m.

6.9

CVSS4.0

CVE-2026-5333 - DefaultFuction Content-Management-System tools.php command injection

A security flaw has been discovered in DefaultFuction Content-Management-System 1.0. This issue affects some unknown processing of the file /admin/tools.php. The manipulation of the argument host results in command injection. The attack can be executed remotely. The exploit has been released to the…

πŸ“… Published: April 2, 2026, 1:30 p.m. πŸ”„ Last Modified: April 2, 2026, 1:30 p.m.

8.5

CVSS4.0

CVE-2026-2737 - Possibility of unintended actions when an administrator clicks a malicious link in the Progress Flo…

A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web session.

πŸ“… Published: April 2, 2026, 1:28 p.m. πŸ”„ Last Modified: April 2, 2026, 8:21 p.m.

8.7

CVSS4.0

CVE-2026-3692 - Unintended command execution during report generation in Progress Flowmon

In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the report generation process that results in unintended commands being executed on the server.

πŸ“… Published: April 2, 2026, 1:27 p.m. πŸ”„ Last Modified: April 2, 2026, 1:27 p.m.

5.1

CVSS4.0

CVE-2026-5332 - Xiaopi Panel WAF Firewall demo.php cross site scripting

A vulnerability was identified in Xiaopi Panel 1.0.0. This vulnerability affects unknown code of the file /demo.php of the component WAF Firewall. The manipulation of the argument param leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available a…

πŸ“… Published: April 2, 2026, 1:15 p.m. πŸ”„ Last Modified: April 2, 2026, 1:15 p.m.

9.1

CVSS3.1

CVE-2026-2701 - RCE vulnerability in Progress ShareFile Storage Zones Controller (SZC)

Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.

πŸ“… Published: April 2, 2026, 1:04 p.m. πŸ”„ Last Modified: April 2, 2026, 8:21 p.m.

9.8

CVSS3.1

CVE-2026-2699 - EAR vulnerability in Progress ShareFile Storage Zones Controller (SZC)

Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.

πŸ“… Published: April 2, 2026, 1:04 p.m. πŸ”„ Last Modified: April 2, 2026, 8:21 p.m.

5.1

CVSS4.0

CVE-2026-5331 - OpenCart Extension Installer installer.php path traversal

A vulnerability was determined in OpenCart 4.1.0.3. This affects an unknown part of the file installer.php of the component Extension Installer Page. Executing a manipulation can lead to path traversal. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized…

πŸ“… Published: April 2, 2026, 1 p.m. πŸ”„ Last Modified: April 2, 2026, 1 p.m.

6.5

CVSS3.1

CVE-2026-34890 - WordPress MSTW League Manager plugin <= 2.10 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark O’Donnell MSTW League Manager allows DOM-Based XSS.This issue affects MSTW League Manager: from n/a through 2.10.

πŸ“… Published: April 2, 2026, 12:58 p.m. πŸ”„ Last Modified: April 2, 2026, 12:58 p.m.
Total resulsts: 341940
Page 17 of 34,194
Β« previous page Β» next page
Filters