9.3

CVSS3.1

CVE-2026-40959 - Lua sandbox escape via crafted module in Luanti using LuaJIT

Luanti 5 before 5.15.2, when LuaJIT is used, allows a Lua sandbox escape via a crafted mod.

πŸ“… Published: April 16, 2026, 12:51 a.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

8.7

CVSS4.0

CVE-2026-40502 - OpenHarness Remote Administrative Command Injection via Gateway Handler

OpenHarness prior to commit dd1d235 contains a command injection vulnerability that allows remote gateway users with chat access to invoke sensitive administrative commands by exploiting insufficient distinction between local-only and remote-safe commands in the gateway handler. Attackers can execu…

πŸ“… Published: April 16, 2026, 12:08 a.m. πŸ”„ Last Modified: April 23, 2026, 7:48 p.m.

7.1

CVSS4.0

CVE-2026-40503 - OpenHarness Path Traversal Information Disclosure via /memory show

OpenHarness prior to commit dd1d235 contains a path traversal vulnerability that allows remote gateway users with chat access to read arbitrary files by supplying path traversal sequences to the /memory show slash command. Attackers can manipulate the path input parameter to escape the project memo…

πŸ“… Published: April 16, 2026, 12:08 a.m. πŸ”„ Last Modified: April 23, 2026, 7:39 p.m.

6.5

CVSS3.1

CVE-2026-37100 - Unauthenticated BLE Control Access on Yamaha SR-B30A Sound Bar

An issue in the Bluetooth Low Energy (BLE) control interface of the Yamaha SR-B30A sound bar firmware 2.40 (Mobile App: Sound Bar Remote / version: 2.40) allows remote attackers within BLE radio range to connect without authentication via the Sound Bar Remote protocol

πŸ“… Published: April 16, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 9:30 a.m.

9.8

CVSS3.1

CVE-2026-37345 - SQL Injection in Vehicle Parking Area Management System v1.0

SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_park.php.

πŸ“… Published: April 16, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:15 p.m.

7.1

CVSS3.1

CVE-2026-30459 - Unauthenticated Retrieval of Password Reset Tokens via Forged Email Links in FuelCMS

An issue in the Forgot Password feature of Daylight Studio FuelCMS v1.5.2 allows unauthenticated attackers to obtain the password reset token of a victim user via a crafted link placed in a valid e-mail message.

πŸ“… Published: April 16, 2026, midnight πŸ”„ Last Modified: April 23, 2026, 3:15 p.m.

7.2

CVSS3.1

CVE-2026-37342 -

SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/view_parked_details.php.

πŸ“… Published: April 16, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 5:30 p.m.

4.7

CVSS3.1

CVE-2026-37346 - SQL Injection in /payroll/view_account.php of SourceCodester Payroll Management System v1.0

SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_account.php?emp_id=.

πŸ“… Published: April 16, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:15 p.m.

7.3

CVSS3.1

CVE-2026-37336 - SQL Injection in /music/view_music.php of Simple Music Cloud Community System

SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_music.php.

πŸ“… Published: April 16, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:15 p.m.

9.8

CVSS3.1

CVE-2026-37340 -

SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/edit_music.php.

πŸ“… Published: April 16, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 5:30 p.m.
Total resulsts: 346649
Page 180 of 34,665
Β« previous page Β» next page
Filters