5.1

CVSS4.0

CVE-2026-5338 - Tenda G103 Setting system.lua action_set_system_settings command injection

A security vulnerability has been detected in Tenda G103 1.0.0.5. The affected element is the function action_set_system_settings of the file system.lua of the component Setting Handler. Such manipulation of the argument lanIp leads to command injection. The attack may be performed from remote. The…

πŸ“… Published: April 2, 2026, 2 p.m. πŸ”„ Last Modified: April 2, 2026, 2 p.m.

5.7

CVSS3.1

CVE-2026-30867 - CocoaMQTT: Denial of Service via Reachable Assertion in `PUBLISH` Packet Parsing

CocoaMQTT is a MQTT 5.0 client library for iOS and macOS written in Swift. Prior to version 2.2.2, a vulnerability exists in the packet parsing logic of CocoaMQTT that allows an attacker (or a compromised/malicious MQTT broker) to remotely crash the host iOS/macOS/tvOS application. If an attacker p…

πŸ“… Published: April 2, 2026, 1:57 p.m. πŸ”„ Last Modified: April 2, 2026, 8:21 p.m.

8.8

CVSS3.1

CVE-2026-35168 - OpenSTAManager: SQL Injection via Aggiornamenti Module

OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, the Aggiornamenti (Updates) module in OpenSTAManager contains a database conflict resolution feature (op=risolvi-conflitti-database) that accepts a JSON array of SQL statements via …

πŸ“… Published: April 2, 2026, 1:48 p.m. πŸ”„ Last Modified: April 2, 2026, 1:48 p.m.

6.9

CVSS4.0

CVE-2026-5334 - itsourcecode Online Enrollment System Parameter index.php sql injection

A weakness has been identified in itsourcecode Online Enrollment System 1.0. Impacted is an unknown function of the file /enrollment/index.php?view=edit&id=3 of the component Parameter Handler. This manipulation of the argument deptid causes sql injection. The attack is possible to be carried out r…

πŸ“… Published: April 2, 2026, 1:45 p.m. πŸ”„ Last Modified: April 2, 2026, 1:45 p.m.

8.8

CVSS3.1

CVE-2026-28805 - OpenSTAManager: Time-Based Blind SQL Injection via `options[stato]` Parameter

OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, multiple AJAX select handlers in OpenSTAManager are vulnerable to Time-Based Blind SQL Injection through the options[stato] GET parameter. The user-supplied value is read from $supe…

πŸ“… Published: April 2, 2026, 1:44 p.m. πŸ”„ Last Modified: April 2, 2026, 8:21 p.m.

7.2

CVSS3.1

CVE-2026-29782 - OpenSTAManager: Remote Code Execution via Insecure Deserialization in OAuth2

OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, the oauth2.php file in OpenSTAManager is an unauthenticated endpoint ($skip_permissions = true). It loads a record from the zz_oauth2 table using the attacker-controlled GET paramet…

πŸ“… Published: April 2, 2026, 1:42 p.m. πŸ”„ Last Modified: April 2, 2026, 8:12 p.m.

6.9

CVSS4.0

CVE-2026-5333 - DefaultFuction Content-Management-System tools.php command injection

A security flaw has been discovered in DefaultFuction Content-Management-System 1.0. This issue affects some unknown processing of the file /admin/tools.php. The manipulation of the argument host results in command injection. The attack can be executed remotely. The exploit has been released to the…

πŸ“… Published: April 2, 2026, 1:30 p.m. πŸ”„ Last Modified: April 2, 2026, 1:30 p.m.

8.5

CVSS4.0

CVE-2026-2737 - Possibility of unintended actions when an administrator clicks a malicious link in the Progress Flo…

A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web session.

πŸ“… Published: April 2, 2026, 1:28 p.m. πŸ”„ Last Modified: April 3, 2026, 3:55 a.m.

8.7

CVSS4.0

CVE-2026-3692 - Unintended command execution during report generation in Progress Flowmon

In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the report generation process that results in unintended commands being executed on the server.

πŸ“… Published: April 2, 2026, 1:27 p.m. πŸ”„ Last Modified: April 3, 2026, 3:55 a.m.

5.1

CVSS4.0

CVE-2026-5332 - Xiaopi Panel WAF Firewall demo.php cross site scripting

A vulnerability was identified in Xiaopi Panel 1.0.0. This vulnerability affects unknown code of the file /demo.php of the component WAF Firewall. The manipulation of the argument param leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available a…

πŸ“… Published: April 2, 2026, 1:15 p.m. πŸ”„ Last Modified: April 2, 2026, 1:15 p.m.
Total resulsts: 341964
Page 19 of 34,197
Β« previous page Β» next page
Filters