6.9

CVSS4.0

CVE-2026-1545 - itsourcecode School Management System index.php sql injection

A weakness has been identified in itsourcecode School Management System 1.0. The affected element is an unknown function of the file /course/index.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been made available…

📅 Published: Jan. 28, 2026, 9:32 p.m. 🔄 Last Modified: April 18, 2026, 1:45 a.m.

5.3

CVSS4.0

CVE-2026-1544 - D-Link DIR-823X set_mode sub_41E2A0 os command injection

A security flaw has been discovered in D-Link DIR-823X 250416. Impacted is the function sub_41E2A0 of the file /goform/set_mode. Performing a manipulation of the argument lan_gateway results in os command injection. The attack is possible to be carried out remotely. The exploit has been released to…

📅 Published: Jan. 28, 2026, 9:32 p.m. 🔄 Last Modified: April 18, 2026, 1:45 a.m.

5.5

CVSS4.0

CVE-2026-24857 - bulk_extractor has Heap-based Buffer Overflow vulnerability

`bulk_extractor` is a digital forensics exploitation tool. Starting in version 1.4, `bulk_extractor`’s embedded unrar code has a heap‑buffer‑overflow in the RAR PPM LZ decoding path. A crafted RAR inside a disk image causes an out‑of‑bounds write in `Unpack::CopyString`, leading to a crash under AS…

📅 Published: Jan. 28, 2026, 9:30 p.m. 🔄 Last Modified: April 18, 2026, 1:45 a.m.

7.8

CVSS3.1

CVE-2026-24856 - iccDEV has UB runtime error in <icTagTypeSignature>

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Versions prior to 2.3.1.2 have an undefined behavior issue when floating-point NaN values are converted to unsigned short integer types during ICC profile XML…

📅 Published: Jan. 28, 2026, 9:05 p.m. 🔄 Last Modified: April 18, 2026, 1:45 a.m.

6.9

CVSS4.0

CVE-2026-1535 - code-projects Online Music Site AdminReply.php sql injection

A security vulnerability has been detected in code-projects Online Music Site 1.0. This impacts an unknown function of the file /Administrator/PHP/AdminReply.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclose…

📅 Published: Jan. 28, 2026, 9:02 p.m. 🔄 Last Modified: April 18, 2026, 2:45 p.m.

6.9

CVSS4.0

CVE-2026-1534 - code-projects Online Music Site AdminEditUser.php sql injection

A weakness has been identified in code-projects Online Music Site 1.0. This affects an unknown function of the file /Administrator/PHP/AdminEditUser.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to…

📅 Published: Jan. 28, 2026, 9:02 p.m. 🔄 Last Modified: April 18, 2026, 1:45 a.m.

8.8

CVSS4.0

CVE-2026-24835 - Podman Desktop Extension System Vulnerable to Authentication Bypass

Podman Desktop is a graphical tool for developing on containers and Kubernetes. A critical authentication bypass vulnerability in Podman Desktop prior to version 1.25.1 allows any extension to completely circumvent permission checks and gain unauthorized access to all authentication sessions. The `…

📅 Published: Jan. 28, 2026, 8:42 p.m. 🔄 Last Modified: April 18, 2026, 1:45 a.m.

8.5

CVSS4.0

CVE-2026-24769 - NocoDB Vulnerable to Stored Cross-Site Scripting via SVG upload

NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, a stored cross-site scripting (XSS) vulnerability exists in NocoDB’s attachment handling mechanism. Authenticated users can upload malicious SVG files containing embedded JavaScript, which are later rendered inline…

📅 Published: Jan. 28, 2026, 8:36 p.m. 🔄 Last Modified: April 18, 2026, 1:45 a.m.

5.1

CVSS4.0

CVE-2026-1533 - code-projects Online Music Site AdminAddCategory.php sql injection

A security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /Administrator/PHP/AdminAddCategory.php. The manipulation results in sql injection. The attack may be performed from remote. The exploit has been released to the publi…

📅 Published: Jan. 28, 2026, 8:32 p.m. 🔄 Last Modified: April 18, 2026, 6:45 p.m.

4.8

CVSS4.0

CVE-2026-1532 - D-Link DCS-700L Music File Upload Service setUploadMusic uploadmusic path traversal

A vulnerability was identified in D-Link DCS-700L 1.03.09. The affected element is the function uploadmusic of the file /setUploadMusic of the component Music File Upload Service. The manipulation of the argument UploadMusic leads to path traversal. The attack can only be initiated within the local…

📅 Published: Jan. 28, 2026, 8:32 p.m. 🔄 Last Modified: April 18, 2026, 1:45 a.m.
Total resulsts: 349182
Page 1902 of 34,919
« previous page » next page
Filters