6.9

CVSS4.0

CVE-2026-7396 - NousResearch hermes-agent WeChat Work Platform Adapter wecom.py path traversal

A vulnerability was identified in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/wecom.py of the component WeChat Work Platform Adapter. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The…

πŸ“… Published: April 29, 2026, 5:30 p.m. πŸ”„ Last Modified: April 29, 2026, 7:30 p.m.

8

CVSS3.1

CVE-2026-5712 - IdentityIQ Role Editor Incorrect Authorization Vulnerability

This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without having an assigned capability that would allow role editing.

πŸ“… Published: April 29, 2026, 5:18 p.m. πŸ”„ Last Modified: May 5, 2026, 12:48 p.m.

5.1

CVSS4.0

CVE-2026-7394 - SourceCodester Pizzafy Ecommerce System GET Parameter view_order.php sql injection

A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/view_order.php of the component GET Parameter Handler. Executing a manipulation of the argument ID can lead to sql injection. The attack may b…

πŸ“… Published: April 29, 2026, 5:15 p.m. πŸ”„ Last Modified: April 29, 2026, 7:30 p.m.

5.1

CVSS4.0

CVE-2026-7393 - SourceCodester Pizzafy Ecommerce System File Extension admin_class_novo.php save_menu unrestricted …

A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function save_menu of the file /admin/admin_class_novo.php of the component File Extension Handler. Performing a manipulation of the argument img results in unrestricted upload. The attack is possible to be ca…

πŸ“… Published: April 29, 2026, 5 p.m. πŸ”„ Last Modified: April 29, 2026, 6:30 p.m.

5.3

CVSS4.0

CVE-2026-6915 - Flaw in the updateUser Command May Allow Unauthorized Configuration Change

An authorization flaw in the user management command could allow an authenticated user to make limited changes to authentication-related data associated with another user account. This could affect how authentication is performed for the impacted account.

πŸ“… Published: April 29, 2026, 4:51 p.m. πŸ”„ Last Modified: May 6, 2026, 8:08 p.m.

7.1

CVSS4.0

CVE-2026-6914 - MD5 checksum creation may cause availability loss

Computing the MD5 checksum of a malformed BSON object under specific conditions may cause loss of availability in MongoDB server. This issue affects all MongoDB Server v8.2 versions, all MongoDB Server v8.1 versions, MongoDB Server v8.0 versions prior to 8.0.21, MongoDB Server v7.0 versions prior t…

πŸ“… Published: April 29, 2026, 4:47 p.m. πŸ”„ Last Modified: May 6, 2026, 8:11 p.m.

5.3

CVSS4.0

CVE-2026-7392 - SourceCodester Pharmacy Sales and Inventory System ajax.php delete_supplier sql injection

A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts the function delete_supplier of the file /ajax.php?action=delete_supplier. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been di…

πŸ“… Published: April 29, 2026, 4:45 p.m. πŸ”„ Last Modified: April 29, 2026, 6:30 p.m.

4.9

CVSS3.1

CVE-2026-0206 - Post‑Authentication Buffer Overflow in SonicOS Causes Firewall Crash

A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall.

πŸ“… Published: April 29, 2026, 4:21 p.m. πŸ”„ Last Modified: May 5, 2026, 4:12 p.m.

6.8

CVSS3.1

CVE-2026-0205 - Post-Authentication Path Traversal in SonicOS Enabling Restricted Service Access

A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services.

πŸ“… Published: April 29, 2026, 4:18 p.m. πŸ”„ Last Modified: May 5, 2026, 4:12 p.m.

8

CVSS3.1

CVE-2026-0204 - Access Control Bypass in SonicOS Management Functions

A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions.

πŸ“… Published: April 29, 2026, 4:15 p.m. πŸ”„ Last Modified: May 5, 2026, 4:11 p.m.
Total resulsts: 349182
Page 203 of 34,919
Β« previous page Β» next page
Filters