9.1

CVSS3.1

CVE-2026-2701 - RCE vulnerability in Progress ShareFile Storage Zones Controller (SZC)

Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.

📅 Published: April 2, 2026, 1:04 p.m. 🔄 Last Modified: April 3, 2026, 3:55 a.m.

9.8

CVSS3.1

CVE-2026-2699 - EAR vulnerability in Progress ShareFile Storage Zones Controller (SZC)

Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.

📅 Published: April 2, 2026, 1:04 p.m. 🔄 Last Modified: April 3, 2026, 3:55 a.m.

5.1

CVSS4.0

CVE-2026-5331 - OpenCart Extension Installer installer.php path traversal

A vulnerability was determined in OpenCart 4.1.0.3. This affects an unknown part of the file installer.php of the component Extension Installer Page. Executing a manipulation can lead to path traversal. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized…

📅 Published: April 2, 2026, 1 p.m. 🔄 Last Modified: April 2, 2026, 1 p.m.

6.5

CVSS3.1

CVE-2026-34890 - WordPress MSTW League Manager plugin <= 2.10 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark O’Donnell MSTW League Manager allows DOM-Based XSS.This issue affects MSTW League Manager: from n/a through 2.10.

📅 Published: April 2, 2026, 12:58 p.m. 🔄 Last Modified: April 2, 2026, 12:58 p.m.

6.9

CVSS4.0

CVE-2026-5330 - SourceCodester/mayuri_k Best Courier Management System User Delete ajax.php access control

A vulnerability was found in SourceCodester/mayuri_k Best Courier Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=delete_user of the component User Delete Handler. Performing a manipulation of the argument ID results in improper access contro…

📅 Published: April 2, 2026, 12:45 p.m. 🔄 Last Modified: April 2, 2026, 12:45 p.m.

5.3

CVSS4.0

CVE-2026-5328 - shsuishang modulithshop ProductItemDao ProductIndexServiceImpl.java listItem sql injection

A weakness has been identified in shsuishang modulithshop up to 829bac71f507e84684c782b9b062b8bf3b5585d6. The impacted element is the function listItem of the file src/main/java/com/suisung/shopsuite/pt/service/impl/ProductIndexServiceImpl.java of the component ProductItemDao Interface. Executing a…

📅 Published: April 2, 2026, 12:30 p.m. 🔄 Last Modified: April 2, 2026, 12:30 p.m.

8.1

CVSS3.1

CVE-2026-4636 - Keycloak: keycloak: uma policy bypass allows authenticated users to gain unauthorized access to vic…

A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) policy validation. This allows the attacker to include resource identifiers owned by other users in a policy creation request, even if the URL path specifies an attacker-owned resou…

📅 Published: April 2, 2026, 12:30 p.m. 🔄 Last Modified: April 2, 2026, 8:21 p.m.

7.5

CVSS3.1

CVE-2026-4634 - Keycloak: keycloak: denial of service via excessive processing of openid connect scope parameters

A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with an excessively long scope parameter to the OpenID Connect (OIDC) token endpoint. This leads to high resource consumption and prolonged processing times, ultimate…

📅 Published: April 2, 2026, 12:30 p.m. 🔄 Last Modified: April 2, 2026, 8:21 p.m.

5.3

CVSS3.1

CVE-2026-4325 - Keycloak: keycloak: replay of action tokens via improper handling of single-use entries

A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an attacker to delete arbitrary single-use entries, which can enable the replay of consumed action tokens, such as password reset links. This cou…

📅 Published: April 2, 2026, 12:30 p.m. 🔄 Last Modified: April 2, 2026, 8:21 p.m.

7.4

CVSS3.1

CVE-2026-4282 - Keycloak: keycloak: privilege escalation via forged authorization codes due to singleuseobjectprovi…

A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can lead to the creation of admin-capable access tokens, result…

📅 Published: April 2, 2026, 12:30 p.m. 🔄 Last Modified: April 2, 2026, 8:21 p.m.
Total resulsts: 341964
Page 20 of 34,197
« previous page » next page
Filters