6.9

CVSS4.0

CVE-2026-6625 - moxi624 Mogu Blog v2 Picture Storage Service LocalFileServiceImpl.java LocalFileServiceImpl.uploadP…

A security vulnerability has been detected in moxi624 Mogu Blog v2 up to 5.2. Affected by this vulnerability is the function LocalFileServiceImpl.uploadPictureByUrl of the file mogu_picture/src/main/java/com/moxi/mogublog/picture/service/impl/LocalFileServiceImpl.java of the component Picture Stora…

πŸ“… Published: April 20, 2026, 9:30 a.m. πŸ”„ Last Modified: April 22, 2026, 8:22 p.m.

4.8

CVSS4.0

CVE-2026-6624 - BichitroGan ISP Billing Software Pool List add cross site scripting

A weakness has been identified in BichitroGan ISP Billing Software 2025.3.20. Affected is an unknown function of the file /?\_route=pool/add of the component Pool List Interface. Executing a manipulation can lead to cross site scripting. The attack may be performed from remote. The exploit has been…

πŸ“… Published: April 20, 2026, 9:15 a.m. πŸ”„ Last Modified: April 22, 2026, 8:22 p.m.

4.8

CVSS4.0

CVE-2026-6623 - BichitroGan ISP Billing Software Profile users-view cross site scripting

A security flaw has been discovered in BichitroGan ISP Billing Software 2025.3.20. This impacts an unknown function of the file /?_route=settings/users-view/ of the component Profile Page Handler. Performing a manipulation results in cross site scripting. The attack is possible to be carried out re…

πŸ“… Published: April 20, 2026, 9 a.m. πŸ”„ Last Modified: April 22, 2026, 8:22 p.m.

5.1

CVSS4.0

CVE-2025-13480 - Incorrect authorization in Fudo Enterprise

Fudo Enterprise in versions from 5.5.0 through 5.6.2 allows low privileged users to access certain administrator-only resources via improperly protected API endpoints. This includes sensitive information such as system logs and parts of system configuration settings. This vulnerability has been fix…

πŸ“… Published: April 20, 2026, 9 a.m. πŸ”„ Last Modified: April 20, 2026, 7:05 p.m.

4.8

CVSS4.0

CVE-2026-6622 - BichitroGan ISP Billing Software Customer edit cross site scripting

A vulnerability was identified in BichitroGan ISP Billing Software 2025.3.20. This affects an unknown function of the file /?\_route=customers/edit/ of the component Customer Handler. Such manipulation leads to cross site scripting. The attack can be executed remotely. The exploit is publicly avail…

πŸ“… Published: April 20, 2026, 8:45 a.m. πŸ”„ Last Modified: April 22, 2026, 8:22 p.m.

6.9

CVSS4.0

CVE-2026-6621 - 1024bit extend-deep index.js prototype pollution

A vulnerability was determined in 1024bit extend-deep up to 0.1.6. The impacted element is an unknown function of the file index.js. This manipulation of the argument __proto__ causes improperly controlled modification of object prototype attributes. Remote exploitation of the attack is possible. T…

πŸ“… Published: April 20, 2026, 8:30 a.m. πŸ”„ Last Modified: April 22, 2026, 8:22 p.m.

5.3

CVSS4.0

CVE-2026-6620 - SonicCloudOrg sonic-server File Upload Endpoint FileTool.java upload path traversal

A vulnerability was found in SonicCloudOrg sonic-server up to 2.0.0. The affected element is the function Upload of the file FileTool.java of the component File Upload Endpoint. The manipulation of the argument Type results in path traversal. The attack may be launched remotely. The exploit has bee…

πŸ“… Published: April 20, 2026, 8:15 a.m. πŸ”„ Last Modified: April 22, 2026, 8:22 p.m.

8.5

CVSS4.0

CVE-2026-39454 -

SKYSEA Client View and SKYMEC IT Manager provided by Sky Co.,LTD. configure the installation folder with improper file access permission settings. A non-administrative user may manipulate and/or place arbitrary files within the installation folder of the product. As a result, arbitrary code may be …

πŸ“… Published: April 20, 2026, 8:04 a.m. πŸ”„ Last Modified: April 20, 2026, 7:05 p.m.

5.1

CVSS4.0

CVE-2026-6619 - langgenius dify ImagePreview image-preview.tsx openInNewTab cross site scripting

A vulnerability has been found in langgenius dify up to 1.13.3. Impacted is the function openInNewTab of the file web/app/components/base/image-uploader/image-preview.tsx of the component ImagePreview. The manipulation of the argument filename leads to cross site scripting. The attack may be initia…

πŸ“… Published: April 20, 2026, 8 a.m. πŸ”„ Last Modified: April 22, 2026, 8:22 p.m.

5.3

CVSS4.0

CVE-2026-6618 - langgenius dify ApiBasedToolSchemaParser parser.py parse_openai_plugin_json_to_tool_bundle server-s…

A flaw has been found in langgenius dify up to 1.13.3. This issue affects the function parse_openai_plugin_json_to_tool_bundle of the file api/core/tools/utils/parser.py of the component ApiBasedToolSchemaParser. Executing a manipulation of the argument url can lead to server-side request forgery. …

πŸ“… Published: April 20, 2026, 7:45 a.m. πŸ”„ Last Modified: April 22, 2026, 8:22 p.m.
Total resulsts: 347398
Page 212 of 34,740
Β« previous page Β» next page
Filters