6.9

CVSS4.0

CVE-2026-2690 - itsourcecode Event Management System Admin Login ajax.php sql injection

A flaw has been found in itsourcecode Event Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login of the component Admin Login. This manipulation of the argument Username causes sql injection. It is possible to initiate the attack…

πŸ“… Published: Feb. 19, 2026, 1:02 a.m. πŸ”„ Last Modified: Feb. 19, 2026, 1:02 a.m.

6.9

CVSS4.0

CVE-2026-2689 - itsourcecode Event Management System manage_booking.php sql injection

A vulnerability was detected in itsourcecode Event Management System 1.0. Affected is an unknown function of the file /admin/manage_booking.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.

πŸ“… Published: Feb. 19, 2026, 12:32 a.m. πŸ”„ Last Modified: Feb. 19, 2026, 12:32 a.m.

9.3

CVSS4.0

CVE-2026-2686 - SECCN Dingcheng G10 session_login.cgi qq os command injection

A security vulnerability has been detected in SECCN Dingcheng G10 3.1.0.181203. This impacts the function qq of the file /cgi-bin/session_login.cgi. The manipulation of the argument User leads to os command injection. The attack is possible to be carried out remotely. The exploit has been disclosed…

πŸ“… Published: Feb. 19, 2026, 12:02 a.m. πŸ”„ Last Modified: Feb. 19, 2026, 12:02 a.m.

6.7

CVSS4.0

CVE-2025-15585 -

Fileflows versions before 25.05.2 are affected by an authenticated SQL injection vulnerability in the library-file search function. Successful exploitation requires the system to use MySQL as the underlying database and could result in privilege escalation or data exfiltration.

πŸ“… Published: Feb. 18, 2026, 11:44 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 11:46 p.m.

6.9

CVSS4.0

CVE-2026-2684 - Tsinghua Unigroup Electronic Archives System uploadFile.html unrestricted upload

A vulnerability was determined in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). The impacted element is an unknown function of the file /Archive/ErecordManage/uploadFile.html. Executing a manipulation of the argument File can lead to unrestricted upload. The attack may be la…

πŸ“… Published: Feb. 18, 2026, 11:32 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 11:32 p.m.

7.3

CVSS3.1

CVE-2026-25926 - Notepad++ has an Untrusted Search Path

Notepad++ is a free and open-source source code editor. An Unsafe Search Path vulnerability (CWE-426) exists in versions prior to 8.9.2 when launching Windows Explorer without an absolute executable path. This may allow execution of a malicious explorer.exe if an attacker can control the process wo…

πŸ“… Published: Feb. 18, 2026, 11:07 p.m. πŸ”„ Last Modified: Feb. 19, 2026, 12:16 a.m.

6.6

CVSS3.1

CVE-2026-24126 - Weblate has an argument injection in management console

Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to `ssh-add`. Version 5.16.0 fixes the issue. As a workaround, properly limit access to the management con…

πŸ“… Published: Feb. 18, 2026, 11:05 p.m. πŸ”„ Last Modified: Feb. 19, 2026, 12:16 a.m.

4.4

CVSS3.1

CVE-2026-26281 - InvoicePlane has Stored Cross-Site Scripting (XSS) Issue in Sumex Invoice View

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A stored cross-site scripting (XSS) vulnerability in the Sumex invoice view allows an authenticated user with client and invoice management privileges to execute arbitrary JavaScript in the browser o…

πŸ“… Published: Feb. 18, 2026, 11:03 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 11:03 p.m.

5.3

CVSS4.0

CVE-2026-2683 - Tsinghua Unigroup Electronic Archives System downLoad.html path traversal

A vulnerability was found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). The affected element is an unknown function of the file /Using/Subject/downLoad.html. Performing a manipulation of the argument path results in path traversal. The attack may be initiated remotely. The expl…

πŸ“… Published: Feb. 18, 2026, 11:02 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 11:02 p.m.

5.4

CVSS3.1

CVE-2026-26270 - InvoicePlane has Stored Cross-Site Scripting Issue in Identifier Formatting

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability exists in InvoicePlane (latest version) that allows an authenticated user with permissions to manage Invoice Groups to inject malicious JavaScript in…

πŸ“… Published: Feb. 18, 2026, 11:01 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 11:01 p.m.
Total resulsts: 333347
Page 2 of 33,335
Β« previous page Β» next page
Filters