5.3

CVSS4.0

CVE-2026-5472 - ProjectsAndPrograms School Management System Profile Picture settings.php unrestricted upload

A flaw has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. The affected element is an unknown function of the file /admin_panel/settings.php of the component Profile Picture Handler. This manipulation of the argument File causes unrestricte…

📅 Published: April 3, 2026, 4 p.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.

6.3

CVSS4.0

CVE-2026-25118 - immich-server: Insecure Transmission of Authentication Credentials via Password Parameter in HTTP R…

immich is a high performance self-hosted photo and video management solution. Prior to version 2.6.0, the Immich application is vulnerable to credential disclosure when a user authenticates to a shared album. During the authentication process, the application transmits the album password within the…

📅 Published: April 3, 2026, 3:51 p.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.

8.7

CVSS3.1

CVE-2026-35218 - Budibase: Stored XSS via unsanitized entity names rendered with {@html} in Builder Command Palette

Budibase is an open-source low-code platform. Prior to version 3.32.5, Budibase's Builder Command Palette renders entity names (tables, views, queries, automations) using Svelte's {@html} directive without any sanitization. An authenticated user with Builder access can create a table, automation, v…

📅 Published: April 3, 2026, 3:47 p.m. 🔄 Last Modified: April 8, 2026, 9:18 p.m.

9.1

CVSS3.1

CVE-2026-35216 - Budibase: Unauthenticated Remote Code Execution via Webhook Trigger and Bash Automation Step

Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Budibase server by triggering an automation that contains a Bash step via the public webhook endpoint. No authentication is required to trigger the explo…

📅 Published: April 3, 2026, 3:45 p.m. 🔄 Last Modified: April 8, 2026, 9:19 p.m.

4.8

CVSS4.0

CVE-2026-5471 - Investory Toy Planet Trouble App app.investory.toyfactory google-services-desktop.json hard-coded k…

A vulnerability was detected in Investory Toy Planet Trouble App up to 1.5.5 on Android. Impacted is an unknown function of the file assets/google-services-desktop.json of the component app.investory.toyfactory. The manipulation of the argument current_key results in use of hard-coded cryptographic…

📅 Published: April 3, 2026, 3:45 p.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.

8.7

CVSS3.1

CVE-2026-35214 - Budibase: Path traversal in plugin file upload enables arbitrary directory deletion and file write

Budibase is an open-source low-code platform. Prior to version 3.33.4, the plugin file upload endpoint (POST /api/plugin/upload) passes the user-supplied filename directly to createTempFolder() without sanitizing path traversal sequences. An attacker with Global Builder privileges can craft a multi…

📅 Published: April 3, 2026, 3:43 p.m. 🔄 Last Modified: April 8, 2026, 9:19 p.m.

9.6

CVSS3.1

CVE-2026-31818 - Budibase: Server-Side Request Forgery via REST Connector with Empty Default Blacklist

Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST datasource connector. The platform's SSRF protection mechanism (IP blacklist) is rendered completely ineffective because the BLACKLIST_IPS environment …

📅 Published: April 3, 2026, 3:41 p.m. 🔄 Last Modified: April 8, 2026, 9:19 p.m.

8.7

CVSS4.0

CVE-2026-25044 - Budibase: Command Injection in Bash Automation Step

Budibase is an open-source low-code platform. Prior to version 3.33.4, the bash automation step executes user-provided commands using execSync without proper sanitization or validation. User input is processed through processStringSync which allows template interpolation, potentially allowing arbit…

📅 Published: April 3, 2026, 3:38 p.m. 🔄 Last Modified: April 8, 2026, 9:19 p.m.

5.3

CVSS3.1

CVE-2026-25043 - Budibase: Unauthenticated Password Reset Endpoint Lacks Rate Limiting, Enabling Email Flooding

Budibase is an open-source low-code platform. Prior to version 3.23.25, a business logic vulnerability exists in Budibase’s password reset functionality due to the absence of rate limiting, CAPTCHA, or abuse prevention mechanisms on the “Forgot Password” endpoint. An unauthenticated attacker can re…

📅 Published: April 3, 2026, 3:35 p.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.

5.3

CVSS4.0

CVE-2026-5470 - mixelpixx Google-Research-MCP Model Context Protocol content-extractor.service.ts extractContent se…

A security vulnerability has been detected in mixelpixx Google-Research-MCP 1e062d7bd887bfe5f6e582b6cc288bb897b35cf2/ca613b736ab787bc926932f59cddc69457185a83. This issue affects the function extractContent of the file src/services/content-extractor.service.ts of the component Model Context Protocol…

📅 Published: April 3, 2026, 3:30 p.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.
Total resulsts: 343945
Page 184 of 34,395
« previous page » next page
Filters