0.0

CVE-2026-23914 -

Not used

πŸ“… Published: Jan. 19, 2026, 12:45 p.m. πŸ”„ Last Modified: Jan. 20, 2026, 3:55 a.m.

0.0

CVE-2026-23916 -

Not used

πŸ“… Published: Jan. 19, 2026, 12:45 p.m. πŸ”„ Last Modified: Jan. 20, 2026, 3:55 a.m.

0.0

CVE-2026-23910 -

Not used

πŸ“… Published: Jan. 19, 2026, 12:45 p.m. πŸ”„ Last Modified: Jan. 20, 2026, 3:55 a.m.

0.0

CVE-2026-23913 -

Not used

πŸ“… Published: Jan. 19, 2026, 12:45 p.m. πŸ”„ Last Modified: Jan. 20, 2026, 3:55 a.m.

5.3

CVSS4.0

CVE-2026-1154 - SourceCodester E-Learning System Lesson index.php cross site scripting

A flaw has been found in SourceCodester E-Learning System 1.0. This impacts an unknown function of the file /admin/modules/lesson/index.php of the component Lesson Module Handler. Executing a manipulation of the argument Title/Description can lead to basic cross site scripting. The attack can be ex…

πŸ“… Published: Jan. 19, 2026, 12:32 p.m. πŸ”„ Last Modified: April 18, 2026, 5:15 a.m.

5.3

CVSS4.0

CVE-2026-1153 - technical-laohu mpay cross-site request forgery

A vulnerability was detected in technical-laohu mpay up to 1.2.4. This affects an unknown function. Performing a manipulation results in cross-site request forgery. Remote exploitation of the attack is possible. The exploit is now public and may be used.

πŸ“… Published: Jan. 19, 2026, 12:02 p.m. πŸ”„ Last Modified: April 18, 2026, 4 p.m.

9

CVSS3.1

CVE-2026-1181 - Altium 365 Over-Permissive CORS Configuration Allows Credentialed Cross-Origin Workspace Access

Altium 365 workspace endpoints were configured with an overly permissive Cross-Origin Resource Sharing (CORS) policy that allowed credentialed cross-origin requests from other Altium-controlled subdomains, including forum.live.altium.com. As a result, JavaScript executing on those origins could acc…

πŸ“… Published: Jan. 19, 2026, noon πŸ”„ Last Modified: April 18, 2026, 7:15 p.m.

5.1

CVSS4.0

CVE-2026-1152 - technical-laohu mpay QR Code Image unrestricted upload

A security vulnerability has been detected in technical-laohu mpay up to 1.2.4. The impacted element is an unknown function of the component QR Code Image Handler. Such manipulation of the argument codeimg leads to unrestricted upload. The attack may be launched remotely. The exploit has been discl…

πŸ“… Published: Jan. 19, 2026, 11:32 a.m. πŸ”„ Last Modified: April 18, 2026, 5:30 a.m.

4.8

CVSS4.0

CVE-2026-1151 - technical-laohu mpay User Center cross site scripting

A weakness has been identified in technical-laohu mpay up to 1.2.4. The affected element is an unknown function of the component User Center. This manipulation of the argument Nickname causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the publ…

πŸ“… Published: Jan. 19, 2026, 11:02 a.m. πŸ”„ Last Modified: April 18, 2026, 5:30 a.m.

5.3

CVSS4.0

CVE-2026-1150 - Totolink LR350 POST Request cstecgi.cgi setTracerouteCfg command injection

A security flaw has been discovered in Totolink LR350 9.3.5u.6369_B20220309. Impacted is the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument command results in command injection. The attack can be launched remotely. …

πŸ“… Published: Jan. 19, 2026, 10:32 a.m. πŸ”„ Last Modified: April 18, 2026, 4 p.m.
Total resulsts: 349182
Page 2079 of 34,919
Β« previous page Β» next page
Filters