8.8

CVSS3.1

CVE-2026-22256 - Salvo is vulnerable to reflected XSS in the list_html function

Salvo is a Rust web backend framework. Prior to version 0.88.1, the function list_html generate an file view of a folder which include a render of the current path, in which its inserted in the HTML without proper sanitation, this leads to reflected XSS using the fact that request path is decoded aโ€ฆ

๐Ÿ“… Published: Jan. 8, 2026, 6:21 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 7:45 a.m.

5.8

CVSS4.0

CVE-2026-21896 - Kirby is missing permission checks in the content changes API

Kirby is an open-source content management system. From versions 5.0.0 to 5.2.1, Kirby is missing permission checks in the content changes API. This vulnerability affects all Kirby sites where user permissions are configured to prevent specific role(s) from performing write actions, specifically byโ€ฆ

๐Ÿ“… Published: Jan. 8, 2026, 6:09 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 7:45 a.m.

5.7

CVSS3.1

CVE-2025-68158 - Authlib: 1-click Account Takeover

Authlib is a Python library which builds OAuth and OpenID Connect servers. In versions 1.0.0 through 1.6.5, cache-backed state/request-token storage is not tied to the initiating user session, so CSRF is possible for any attacker that has a valid state (easily obtainable via an attacker-initiated aโ€ฆ

๐Ÿ“… Published: Jan. 8, 2026, 5:58 p.m. ๐Ÿ”„ Last Modified: March 30, 2026, 12:20 p.m.

8.7

CVSS4.0

CVE-2026-22235 - OPEXUS eComplaint IDOR

OPEXUS eComplaint before version 9.0.45.0 allows an attacker to visit the the 'DocumentOpen.aspx' endpoint, iterate through predictable values of 'chargeNumber', and download any uploaded files.

๐Ÿ“… Published: Jan. 8, 2026, 5:13 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4:45 p.m.

9.3

CVSS4.0

CVE-2026-22234 - OPEXUS eCasePortal unauthenticated IDOR

OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predictable values of 'formid', and download or delete all user-uploaded files, or upload new files.

๐Ÿ“… Published: Jan. 8, 2026, 5:12 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 7:45 a.m.

4.8

CVSS4.0

CVE-2026-22233 - OPEXUS eCASE Audit Project Cost stored XSS

OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript as a comment in the "Estimated Staff Hours" field. The JavaScript is executed whenever another user visits the Project Cost tab. Fixed in OPEXUS eCASE Audit 11.14.2.0.

๐Ÿ“… Published: Jan. 8, 2026, 5:11 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 7:45 a.m.

4.8

CVSS4.0

CVE-2026-22232 - OPEXUS eCASE Audit Project Setup stored XSS

OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript in the "A or SIC Number" field within the Project Setup functionality. The JavaScript is executed whenever another user views the project. Fixed in OPEXUS eCASE Audit 11.14.2.0.

๐Ÿ“… Published: Jan. 8, 2026, 5:10 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 7:30 p.m.

4.8

CVSS4.0

CVE-2026-22231 - OPEXUS eCASE Audit Document Check Out stored XSS

OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript as a comment within the Document Check Out functionality. The JavaScript is executed whenever another user views the Action History Log. Fixed in OPEXUS eCASE Platform 11.14.1.0.

๐Ÿ“… Published: Jan. 8, 2026, 5:10 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4:45 p.m.

7.2

CVSS4.0

CVE-2026-22230 - OPEXUS eCASE Audit incorrect access control

OPEXUS eCASE Audit allows an authenticated attacker to modify client-side JavaScript or craft HTTP requests to access functions or buttons that have been disabled or blocked by an administrator. Fixed in eCASE Platform 11.14.1.0.

๐Ÿ“… Published: Jan. 8, 2026, 5:10 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4:45 p.m.

4.8

CVSS4.0

CVE-2026-22587 - Ideagen DevonWay Reports page stored XSS

Ideagen DevonWay contains a stored cross site scripting vulnerability. A remote, authenticated attacker could craft a payload in the 'Reports' page that executes when another user views the report. Fixed in 2.62.4 and 2.62 LTS.

๐Ÿ“… Published: Jan. 8, 2026, 5:09 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4:45 p.m.
Total resulsts: 349182
Page 2221 of 34,919
ยซ previous page ยป next page
Filters