5.5

CVSS3.1

CVE-2026-21444 - libtpms returns wrong initialization vector when certain symmetric ciphers are used

libtpms, a library that provides software emulation of a Trusted Platform Module, has a flaw in versions 0.10.0 and 0.10.1. The commonly used integration of libtpms with OpenSSL 3.x contained a vulnerability related to the returned IV (initialization vector) when certain symmetric ciphers were used…

πŸ“… Published: Jan. 2, 2026, 7:05 p.m. πŸ”„ Last Modified: Feb. 25, 2026, 3:18 p.m.

9.2

CVSS4.0

CVE-2026-21440 - AdonisJS Path Traversal in Multipart File Handling

AdonisJS is a TypeScript-first web framework. A Path Traversal vulnerability in AdonisJS multipart file handling may allow a remote attacker to write arbitrary files to arbitrary locations on the server filesystem. This impacts @adonisjs/bodyparser through version 10.1.1 and 11.x prerelease version…

πŸ“… Published: Jan. 2, 2026, 7:02 p.m. πŸ”„ Last Modified: Jan. 8, 2026, 6:09 p.m.

6.9

CVSS4.0

CVE-2026-0570 - code-projects Online Music Site Feedback.php sql injection

A vulnerability was found in code-projects Online Music Site 1.0. This impacts an unknown function of the file /Frontend/Feedback.php. Performing a manipulation of the argument fname results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.

πŸ“… Published: Jan. 2, 2026, 7:02 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 8:10 a.m.

7.7

CVSS3.1

CVE-2026-21433 - Emlog vulnerable to Server-Side Request Forgery (SSRF)

Emlog is an open source website building system. Versions up to and including 2.5.19 are vulnerable to server-side Out-of-Band (OOB) requests / SSRF via uploaded SVG files. An attacker can upload a crafted SVG to http[:]//emblog/admin/media[.]php which contains external resource references. When th…

πŸ“… Published: Jan. 2, 2026, 7 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 6:11 p.m.

6.8

CVSS4.0

CVE-2026-21432 - Emlog has stored Cross-site Scripting issue that can lead to admin or another account ATO

Emlog is an open source website building system. Version 2.5.23 has a stored cross-site scripting vulnerability that can lead to account takeover, including takeover of admin accounts. As of time of publication, no known patched versions are available.

πŸ“… Published: Jan. 2, 2026, 6:58 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 5:13 p.m.

2

CVSS4.0

CVE-2026-21431 - Emlog vulnerable to stored Cross-site Scripting via image name

Emlog is an open source website building system. Version 2.5.23 has a stored cross-site scripting vulnerability in the `Resource media library ` function while publishing an article. As of time of publication, no known patched versions are available.

πŸ“… Published: Jan. 2, 2026, 6:49 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 5:13 p.m.

7

CVSS4.0

CVE-2026-21430 - Emlog: CSRF chained with stored XSS leads to ATO

Emlog is an open source website building system. In version 2.5.23, article creation functionality is vulnerable to cross-site request forgery (CSRF). This can lead to a user being forced to post an article with arbitrary, attacker-controlled content. This, when combined with stored cross-site scri…

πŸ“… Published: Jan. 2, 2026, 6:44 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 7:07 p.m.

6.9

CVSS4.0

CVE-2026-0569 - code-projects Online Music Site AlbumByCategory.php sql injection

A vulnerability has been found in code-projects Online Music Site 1.0. This affects an unknown function of the file /Frontend/AlbumByCategory.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public …

πŸ“… Published: Jan. 2, 2026, 6:32 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 8:10 a.m.

6.9

CVSS4.0

CVE-2026-0568 - code-projects Online Music Site ViewSongs.php sql injection

A flaw has been found in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /Frontend/ViewSongs.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.

πŸ“… Published: Jan. 2, 2026, 6:02 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 8:10 a.m.

6.9

CVSS4.0

CVE-2026-0567 - code-projects Content Management System pages.php sql injection

A vulnerability was detected in code-projects Content Management System 1.0. The affected element is an unknown function of the file /pages.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.

πŸ“… Published: Jan. 2, 2026, 5:32 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 8:09 a.m.
Total resulsts: 344032
Page 1788 of 34,404
Β« previous page Β» next page
Filters