6.3

CVSS3.1

CVE-2025-15344 - Tanium addressed a SQL injection vulnerability in Asset.

Tanium addressed a SQL injection vulnerability in Asset.

📅 Published: Jan. 28, 2026, 11:46 p.m. 🔄 Last Modified: March 9, 2026, 2:30 p.m.

5.3

CVSS4.0

CVE-2026-1551 - itsourcecode School Management System controller.php sql injection

A weakness has been identified in itsourcecode School Management System 1.0. This affects an unknown part of the file /ramonsys/course/controller.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been made available to t…

📅 Published: Jan. 28, 2026, 11:32 p.m. 🔄 Last Modified: April 18, 2026, 2:45 p.m.

5.3

CVSS4.0

CVE-2026-1550 - PHPGurukul Hospital Management System Admin Dashboard adminviews.py improper authorization

A security flaw has been discovered in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /hms/hospital/docappsystem/adminviews.py of the component Admin Dashboard Page. Performing a manipulation results in improper authorization. Remote expl…

📅 Published: Jan. 28, 2026, 11:02 p.m. 🔄 Last Modified: April 18, 2026, 1:45 a.m.

5.3

CVSS4.0

CVE-2026-1549 - jishenghua jshERP PluginController uploadPluginConfigFile path traversal

A vulnerability was identified in jishenghua jshERP up to 3.6. Affected by this vulnerability is an unknown functionality of the file /jshERP-boot/plugin/uploadPluginConfigFile of the component PluginController. Such manipulation of the argument configFile leads to path traversal. The attack may be…

📅 Published: Jan. 28, 2026, 11:02 p.m. 🔄 Last Modified: April 18, 2026, 1:45 a.m.

5.3

CVSS4.0

CVE-2026-1548 - Totolink A7000R cstecgi.cgi CloudACMunualUpdateUserdata command injection

A flaw has been found in Totolink A7000R 4.1cu.4154. This impacts the function CloudACMunualUpdateUserdata of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument url causes command injection. The attack can be initiated remotely. The exploit has been published and may be used.

📅 Published: Jan. 28, 2026, 10:32 p.m. 🔄 Last Modified: April 18, 2026, 2:45 p.m.

10

CVSS3.1

CVE-2026-24897 - Authenticated Remote Code Execution via Arbitrary File Upload

Erugo is a self-hosted file-sharing platform. In versions up to and including 0.2.14, an authenticated low-privileged user can upload arbitrary files to any specified location due to insufficient validation of user‑supplied paths when creating shares. By specifying a writable path within the public…

📅 Published: Jan. 28, 2026, 10:24 p.m. 🔄 Last Modified: April 18, 2026, 2:45 p.m.

5.3

CVSS4.0

CVE-2026-1547 - Totolink A7000R cstecgi.cgi setUnloadUserData command injection

A vulnerability was detected in Totolink A7000R 4.1cu.4154. This affects the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument plugin_name results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be use…

📅 Published: Jan. 28, 2026, 10:02 p.m. 🔄 Last Modified: April 18, 2026, 2:45 p.m.

5.3

CVSS4.0

CVE-2026-1546 - jishenghua jshERP com.jsh.erp.datasource.mappers.DepotItemMapperEx importItemExcel getBillItemByPar…

A security vulnerability has been detected in jishenghua jshERP up to 3.6. The impacted element is the function getBillItemByParam of the file /jshERP-boot/depotItem/importItemExcel of the component com.jsh.erp.datasource.mappers.DepotItemMapperEx. The manipulation of the argument barCodes leads to…

📅 Published: Jan. 28, 2026, 10:02 p.m. 🔄 Last Modified: April 18, 2026, 8 p.m.

5.3

CVSS3.1

CVE-2026-24889 - soroban-sdk has overflow in Bytes::slice, Vec::slice, GenRange::gen_range for u64

soroban-sdk is a Rust SDK for Soroban contracts. Arithmetic overflow can be triggered in the `Bytes::slice`, `Vec::slice`, and `Prng::gen_range` (for `u64`) methods in the `soroban-sdk` in versions up to and including `25.0.1`, `23.5.1`, and `25.0.2`. Contracts that pass user-controlled or computed…

📅 Published: Jan. 28, 2026, 10:01 p.m. 🔄 Last Modified: April 18, 2026, 1:45 a.m.

6.5

CVSS3.1

CVE-2026-24888 - Maker.js Vulnerable to Unsafe Property Copying in makerjs.extendObject

Maker.js is a 2D vector line drawing and shape modeling for CNC and laser cutters. In versions up to and including 0.19.1, the `makerjs.extendObject` function copies properties from source objects without proper validation, potentially exposing applications to security risks. The function lacks `ha…

📅 Published: Jan. 28, 2026, 9:35 p.m. 🔄 Last Modified: April 18, 2026, 2:45 p.m.
Total resulsts: 349182
Page 1901 of 34,919
« previous page » next page
Filters