6.9

CVSS4.0

CVE-2026-7314 - eiceblue spire-doc-mcp-server base.py get_doc_path path traversal

A vulnerability was detected in eiceblue spire-doc-mcp-server 1.0.0. This affects the function get_doc_path of the file src/spire_doc_mcp/api/base.py. Performing a manipulation of the argument document_name results in path traversal. The attack can be initiated remotely. The exploit is now public a…

πŸ“… Published: April 28, 2026, 7:45 p.m. πŸ”„ Last Modified: April 29, 2026, 1:58 p.m.

6.3

CVSS4.0

CVE-2026-7306 - Xuxueli xxl-job OpenAPI Endpoint OpenApiController.java hard-coded key

A security vulnerability has been detected in Xuxueli xxl-job up to 3.3.2. The impacted element is an unknown function of the file xxl-job-admin/src/main/java/com/xxl/job/admin/scheduler/openapi/OpenApiController.java of the component OpenAPI Endpoint. Such manipulation of the argument default_toke…

πŸ“… Published: April 28, 2026, 7:30 p.m. πŸ”„ Last Modified: April 30, 2026, 12:58 p.m.

5.3

CVSS4.0

CVE-2026-7305 - Xuxueli xxl-job trigger Endpoint XxlJobServiceImpl.java triggerJob server-side request forgery

A weakness has been identified in Xuxueli xxl-job up to 3.3.2. The affected element is the function triggerJob of the file xxl-job-admin/src/main/java/com/xxl/job/admin/service/impl/XxlJobServiceImpl.java of the component trigger Endpoint. This manipulation of the argument addressList causes server…

πŸ“… Published: April 28, 2026, 7:15 p.m. πŸ”„ Last Modified: April 29, 2026, 1:09 p.m.

6.3

CVSS4.0

CVE-2026-7303 - Xuxueli xxl-job Execution Log JobLogController.java logDetailCat resource injection

A security flaw has been discovered in Xuxueli xxl-job up to 3.3.2. Impacted is the function logDetailCat of the file xxl-job-admin/src/main/java/com/xxl/job/admin/controller/biz/JobLogController.java of the component Execution Log Handler. The manipulation of the argument logId results in improper…

πŸ“… Published: April 28, 2026, 7 p.m. πŸ”„ Last Modified: April 29, 2026, 1:11 p.m.

4.8

CVSS4.0

CVE-2026-7297 - SourceCodester Pizzafy Ecommerce System ajax.php save_user cross site scripting

A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects the function save_user of the file /admin/ajax.php?action=save_user. Executing a manipulation of the argument Name can lead to cross site scripting. The attack can be executed remotely. The exp…

πŸ“… Published: April 28, 2026, 6:45 p.m. πŸ”„ Last Modified: April 28, 2026, 11:30 p.m.

4.8

CVSS4.0

CVE-2026-7296 - SourceCodester Pizzafy Ecommerce System ajax.php save_order cross site scripting

A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_order of the file /admin/ajax.php?action=save_order. Performing a manipulation of the argument first_name results in cross site scripting. Remote exploitation of the attack is possible. The expl…

πŸ“… Published: April 28, 2026, 6:30 p.m. πŸ”„ Last Modified: April 29, 2026, 9:16 p.m.

4.8

CVSS4.0

CVE-2026-7295 - SourceCodester Pizzafy Ecommerce System ajax.php save_menu cross site scripting

A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this issue is the function save_menu of the file /admin/ajax.php?action=save_menu. Such manipulation of the argument Name leads to cross site scripting. The attack may be launched remotely. The exploit has be…

πŸ“… Published: April 28, 2026, 6:15 p.m. πŸ”„ Last Modified: April 29, 2026, 2:56 p.m.

7.3

CVSS4.0

CVE-2026-42432 - OpenClaw < 2026.4.8 - Command Escalation via Node Pairing Reconnect Bypass

OpenClaw before 2026.4.8 contains a privilege escalation vulnerability allowing previously paired nodes to reconnect with exec-capable commands without operator.admin scope requirement. Attackers can bypass re-pairing authentication to execute privileged commands on the local assistant system.

πŸ“… Published: April 28, 2026, 6:10 p.m. πŸ”„ Last Modified: April 28, 2026, 6:10 p.m.

7.6

CVSS4.0

CVE-2026-42431 - OpenClaw < 2026.4.8 - Persistent Profile Mutation via node.invoke(browser.proxy) Bypass

OpenClaw before 2026.4.8 contains a security bypass vulnerability in node.invoke(browser.proxy) that allows mutation of persistent browser profiles. Attackers can exploit this path to circumvent the browser.request persistent profile-mutation guard and modify browser configurations.

πŸ“… Published: April 28, 2026, 6:10 p.m. πŸ”„ Last Modified: April 29, 2026, 1:12 p.m.

4.8

CVSS4.0

CVE-2026-42430 - OpenClaw < 2026.4.8 - Strict Browser SSRF Bypass via Playwright Redirect Handling

OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in Playwright redirect handling that allows attackers to bypass strict SSRF checks. Attackers can exploit request-time navigation to reach private targets that should be restricted by browser SSRF protections.

πŸ“… Published: April 28, 2026, 6:10 p.m. πŸ”„ Last Modified: April 30, 2026, 2:05 p.m.
Total resulsts: 348786
Page 173 of 34,879
Β« previous page Β» next page
Filters