6.9

CVSS4.0

CVE-2026-5832 - atototo api-lab-mcp HTTP http-server.ts test_http_endpoint server-side request forgery

A weakness has been identified in atototo api-lab-mcp up to 0.2.1. This affects the function analyze_api_spec/generate_test_scenarios/test_http_endpoint of the file src/mcp/http-server.ts of the component HTTP Interface. This manipulation of the argument source/url causes server-side request forger…

πŸ“… Published: April 9, 2026, 2 a.m. πŸ”„ Last Modified: April 9, 2026, 2 a.m.

5.3

CVSS4.0

CVE-2026-5831 - Agions taskflow-ai terminal_execute handlers.ts os command injection

A security flaw has been discovered in Agions taskflow-ai up to 2.1.8. This impacts an unknown function of the file src/mcp/server/handlers.ts of the component terminal_execute. Performing a manipulation results in os command injection. The attack is possible to be carried out remotely. Upgrading t…

πŸ“… Published: April 9, 2026, 1:45 a.m. πŸ”„ Last Modified: April 9, 2026, 1:45 a.m.

8.7

CVSS4.0

CVE-2026-5830 - Tenda AC15 SysToolChangePwd websGetVar stack-based overflow

A vulnerability was identified in Tenda AC15 15.03.05.18. This affects the function websGetVar of the file /goform/SysToolChangePwd. Such manipulation of the argument oldPwd/newPwd/cfmPwd leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available an…

πŸ“… Published: April 9, 2026, 1:30 a.m. πŸ”„ Last Modified: April 9, 2026, 1:30 a.m.

8.8

CVSS3.1

CVE-2026-4326 - Vertex Addons for Elementor <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) Arbitra…

The Vertex Addons for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.6.4. This is due to improper authorization enforcement in the activate_required_plugins() function. Specifically, the current_user_can('install_plugins') capability chec…

πŸ“… Published: April 9, 2026, 1:25 a.m. πŸ”„ Last Modified: April 9, 2026, 1:25 a.m.

6.9

CVSS4.0

CVE-2026-5829 - code-projects Simple IT Discussion Forum content.php sql injection

A vulnerability was determined in code-projects Simple IT Discussion Forum 1.0. The impacted element is an unknown function of the file /pages/content.php. This manipulation of the argument post_id causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly di…

πŸ“… Published: April 9, 2026, 1:15 a.m. πŸ”„ Last Modified: April 9, 2026, 1:15 a.m.

6.9

CVSS4.0

CVE-2026-5828 - code-projects Simple IT Discussion Forum addcomment.php sql injection

A vulnerability was found in code-projects Simple IT Discussion Forum 1.0. The affected element is an unknown function of the file /functions/addcomment.php. The manipulation of the argument postid results in sql injection. The attack may be launched remotely. The exploit has been made public and c…

πŸ“… Published: April 9, 2026, 1 a.m. πŸ”„ Last Modified: April 9, 2026, 1 a.m.

6.9

CVSS4.0

CVE-2026-5827 - code-projects Simple IT Discussion Forum question-function.php sql injection

A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. Impacted is an unknown function of the file /question-function.php. The manipulation of the argument content leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and…

πŸ“… Published: April 9, 2026, 12:45 a.m. πŸ”„ Last Modified: April 9, 2026, 12:45 a.m.

5.3

CVSS4.0

CVE-2026-5826 - code-projects Simple IT Discussion Forum edit-category.php cross site scripting

A flaw has been found in code-projects Simple IT Discussion Forum 1.0. This issue affects some unknown processing of the file /edit-category.php. Executing a manipulation of the argument Category can lead to cross site scripting. The attack can be launched remotely. The exploit has been published a…

πŸ“… Published: April 9, 2026, 12:30 a.m. πŸ”„ Last Modified: April 9, 2026, 12:30 a.m.

5.3

CVSS4.0

CVE-2026-5825 - code-projects Simple Laundry System delmemberinfo.php cross site scripting

A vulnerability was detected in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /delmemberinfo.php. Performing a manipulation of the argument userid results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may …

πŸ“… Published: April 9, 2026, 12:15 a.m. πŸ”„ Last Modified: April 9, 2026, 12:15 a.m.

6.9

CVSS4.0

CVE-2026-5824 - code-projects Simple Laundry System userchecklogin.php sql injection

A security vulnerability has been detected in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /userchecklogin.php. Such manipulation of the argument userid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly…

πŸ“… Published: April 8, 2026, 11:45 p.m. πŸ”„ Last Modified: April 8, 2026, 11:45 p.m.
Total resulsts: 343419
Page 2 of 34,342
Β« previous page Β» next page
Filters