9.3

CVSS4.0

CVE-2026-1480 - Out-of-band SQL injection in Quatuor Performance Evaluation

An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_usuario' in '/evaluacion_objetivos_anyo_sig_evalua.aspx', could allow an attacker…

📅 Published: Jan. 27, 2026, 4:31 p.m. 🔄 Last Modified: April 18, 2026, 2:15 a.m.

9.3

CVSS4.0

CVE-2026-1479 - Out-of-band SQL injection in Quatuor Performance Evaluation

An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameters 'Id_usuario' and 'Id_evaluacion’ in ‘/evaluacion_hca_ver_auto.asp', could allow an a…

📅 Published: Jan. 27, 2026, 4:31 p.m. 🔄 Last Modified: April 18, 2026, 2:15 a.m.

9.3

CVSS4.0

CVE-2026-1478 - Out-of-band SQL injection in Quatuor Performance Evaluation

An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_usuario' and 'Id_evaluacion’ in ‘/evaluacion_hca_evalua.aspx’, could allow an att…

📅 Published: Jan. 27, 2026, 4:30 p.m. 🔄 Last Modified: April 16, 2026, 7:30 a.m.

9.3

CVSS4.0

CVE-2026-1477 - Out-of-band SQL injection in Quatuor Performance Evaluation

An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_usuario' and 'Id_evaluacion’ in ‘/evaluacion_competencias_evalua_old.aspx’, could…

📅 Published: Jan. 27, 2026, 4:30 p.m. 🔄 Last Modified: April 18, 2026, 2:15 a.m.

9.3

CVSS4.0

CVE-2026-1476 - Out-of-band SQL injection in Quatuor Performance Evaluation

An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_usuario' in ‘/evaluacion_acciones_ver_auto.aspx’, could allow an attacker to extr…

📅 Published: Jan. 27, 2026, 4:29 p.m. 🔄 Last Modified: April 18, 2026, 2:15 a.m.

9.3

CVSS4.0

CVE-2026-1475 - Out-of-band SQL injection in Quatuor Performance Evaluation

An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter ‘Id_usuario' in ‘/evaluacion_acciones_evalua.aspx’, could allow an attacker to extrac…

📅 Published: Jan. 27, 2026, 4:28 p.m. 🔄 Last Modified: April 18, 2026, 3 p.m.

9.3

CVSS4.0

CVE-2026-1474 - Out-of-band SQL injection in Quatuor Performance Evaluation

An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_usuario' and 'Id_evaluacion' en ‘/evaluacion_inicio.aspx’, could allow an attacke…

📅 Published: Jan. 27, 2026, 4:27 p.m. 🔄 Last Modified: April 18, 2026, 2:15 a.m.

9.3

CVSS4.0

CVE-2026-1473 - Out-of-band SQL injection in Quatuor Performance Evaluation

An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_usuario’ in '/evaluacion_competencias_evalua.aspx', could allow an attacker to ex…

📅 Published: Jan. 27, 2026, 4:27 p.m. 🔄 Last Modified: April 18, 2026, 2:15 a.m.

9.3

CVSS4.0

CVE-2026-1472 - Out-of-band SQL injection in Quatuor Performance Evaluation

An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'txAny' in '/evaluacion_competencias_autoeval_list.aspx', could allow an attacker to …

📅 Published: Jan. 27, 2026, 4:26 p.m. 🔄 Last Modified: April 18, 2026, 7 p.m.

7.5

CVSS3.1

CVE-2026-22258 - Suricata DCERPC: unbounded fragment buffering leads to memory exhaustion

Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, crafted DCERPC traffic can cause Suricata to expand a buffer w/o limits, leading to memory exhaustion and the process getting killed. While reported for DCERPC over UDP, it is believed that DCERPC over TCP and SMB ar…

📅 Published: Jan. 27, 2026, 4:17 p.m. 🔄 Last Modified: April 18, 2026, 3 p.m.
Total resulsts: 349182
Page 1928 of 34,919
« previous page » next page
Filters