5.3

CVSS4.0

CVE-2026-33457 - Potential livestatus injection in prediction graph page

Livestatus injection in the prediction graph page in Checkmk <2.5.0b4, <2.4.0p26, and <2.3.0p47 allows an authenticated user to inject arbitrary Livestatus commands via a crafted service name parameter due to insufficient sanitization of the service description value.

📅 Published: April 10, 2026, 8:31 a.m. 🔄 Last Modified: April 10, 2026, 8:31 a.m.

5.1

CVSS4.0

CVE-2026-33456 - Potential livestatus injection in notification test

Livestatus injection in the notification test mode in Checkmk <2.5.0b4 and <2.4.0p26 allows an authenticated user with access to the notification test page to inject arbitrary Livestatus commands via a crafted service description.

📅 Published: April 10, 2026, 8:31 a.m. 🔄 Last Modified: April 10, 2026, 8:31 a.m.

5.3

CVSS4.0

CVE-2026-33455 - Livestatus injection in monitoring quicksearch

Livestatus injection in the monitoring quicksearch in Checkmk <2.5.0b4 allows an authenticated attacker to inject livestatus commands via the search query due to insufficient input sanitization in search filter plugins.

📅 Published: April 10, 2026, 8:30 a.m. 🔄 Last Modified: April 10, 2026, 8:30 a.m.

6.9

CVSS4.0

CVE-2026-6037 - code-projects Vehicle Showroom Management System AddVehicleFunction.php sql injection

A vulnerability was determined in code-projects Vehicle Showroom Management System 1.0. This affects an unknown function of the file /util/AddVehicleFunction.php. This manipulation of the argument BRANCH_ID causes sql injection. The attack is possible to be carried out remotely. The exploit has bee…

📅 Published: April 10, 2026, 8:30 a.m. 🔄 Last Modified: April 10, 2026, 8:30 a.m.

6.9

CVSS4.0

CVE-2026-6036 - code-projects Vehicle Showroom Management System VehicleDetailsFunction.php sql injection

A vulnerability was found in code-projects Vehicle Showroom Management System 1.0. The impacted element is an unknown function of the file /util/VehicleDetailsFunction.php. The manipulation of the argument VEHICLE_ID results in sql injection. The attack can be executed remotely. The exploit has bee…

📅 Published: April 10, 2026, 8:15 a.m. 🔄 Last Modified: April 10, 2026, 8:15 a.m.

5.3

CVSS4.0

CVE-2026-6035 - code-projects Vehicle Showroom Management System ServiceAndSalesReport.php cross site scripting

A vulnerability has been found in code-projects Vehicle Showroom Management System 1.0. The affected element is an unknown function of the file /BranchManagement/ServiceAndSalesReport.php. The manipulation of the argument BRANCH_ID leads to cross site scripting. Remote exploitation of the attack is…

📅 Published: April 10, 2026, 8 a.m. 🔄 Last Modified: April 10, 2026, 3:14 p.m.

5.3

CVSS4.0

CVE-2026-6034 - code-projects Vehicle Showroom Management System ProfitAndLossReport.php cross site scripting

A flaw has been found in code-projects Vehicle Showroom Management System 1.0. Impacted is an unknown function of the file /BranchManagement/ProfitAndLossReport.php. Executing a manipulation of the argument BRANCH_ID can lead to cross site scripting. The attack may be launched remotely. The exploit…

📅 Published: April 10, 2026, 7:45 a.m. 🔄 Last Modified: April 10, 2026, 3:54 p.m.

6

CVSS3.1

CVE-2026-5525 - Stack-Based Buffer Overflow in Notepad++ File Drop Handler leads to DoS

A stack-based buffer overflow vulnerability exists in Notepad++ version 8.9.3 in the file drop handler component. When a user drags and drops a directory path of exactly 259 characters without a trailing backslash, the application appends a backslash and null terminator without proper bounds checki…

📅 Published: April 10, 2026, 7:40 a.m. 🔄 Last Modified: April 10, 2026, 7:40 a.m.

7.5

CVSS3.1

CVE-2026-22750 - SSL bundle configuration silently bypassed in Spring Cloud Gateway

When configuring SSL bundles in Spring Cloud Gateway by using the configuration property spring.ssl.bundle, the configuration was silently ignored and the default SSL configuration was used instead. Note: The 4.2.x branch is no longer under open source support. If you are using Spring Cloud Gateway…

📅 Published: April 10, 2026, 7:32 a.m. 🔄 Last Modified: April 10, 2026, 2:40 p.m.

5.3

CVSS4.0

CVE-2026-6033 - CodeAstro Online Classroom updatedetailsfromstudent.php sql injection

A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected is an unknown function of the file /updatedetailsfromstudent.php?eno=146891650. Executing a manipulation of the argument fname can lead to sql injection. The attack may be performed from remote. The exploit has been publicly…

📅 Published: April 10, 2026, 7:30 a.m. 🔄 Last Modified: April 10, 2026, 7:30 a.m.
Total resulsts: 343921
Page 18 of 34,393
« previous page » next page
Filters