8.8

CVSS4.0

CVE-2026-21445 - Langflow Missing Authentication on Critical API Endpoints

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0.dev45, multiple critical API endpoints in Langflow are missing authentication controls. The issue allows any unauthenticated user to access sensitive user conversation data, transaction histories, …

πŸ“… Published: Jan. 2, 2026, 7:11 p.m. πŸ”„ Last Modified: April 18, 2026, 8:45 a.m.

5.5

CVSS3.1

CVE-2026-21444 - libtpms returns wrong initialization vector when certain symmetric ciphers are used

libtpms, a library that provides software emulation of a Trusted Platform Module, has a flaw in versions 0.10.0 and 0.10.1. The commonly used integration of libtpms with OpenSSL 3.x contained a vulnerability related to the returned IV (initialization vector) when certain symmetric ciphers were used…

πŸ“… Published: Jan. 2, 2026, 7:05 p.m. πŸ”„ Last Modified: April 18, 2026, 8:45 a.m.

9.2

CVSS4.0

CVE-2026-21440 - AdonisJS Path Traversal in Multipart File Handling

AdonisJS is a TypeScript-first web framework. A Path Traversal vulnerability in AdonisJS multipart file handling may allow a remote attacker to write arbitrary files to arbitrary locations on the server filesystem. This impacts @adonisjs/bodyparser through version 10.1.1 and 11.x prerelease version…

πŸ“… Published: Jan. 2, 2026, 7:02 p.m. πŸ”„ Last Modified: April 18, 2026, 8:45 a.m.

6.9

CVSS4.0

CVE-2026-0570 - code-projects Online Music Site Feedback.php sql injection

A vulnerability was found in code-projects Online Music Site 1.0. This impacts an unknown function of the file /Frontend/Feedback.php. Performing a manipulation of the argument fname results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.

πŸ“… Published: Jan. 2, 2026, 7:02 p.m. πŸ”„ Last Modified: April 18, 2026, 8:45 a.m.

7.7

CVSS3.1

CVE-2026-21433 - Emlog vulnerable to Server-Side Request Forgery (SSRF)

Emlog is an open source website building system. Versions up to and including 2.5.19 are vulnerable to server-side Out-of-Band (OOB) requests / SSRF via uploaded SVG files. An attacker can upload a crafted SVG to http[:]//emblog/admin/media[.]php which contains external resource references. When th…

πŸ“… Published: Jan. 2, 2026, 7 p.m. πŸ”„ Last Modified: April 18, 2026, 8:45 a.m.

6.8

CVSS4.0

CVE-2026-21432 - Emlog has stored Cross-site Scripting issue that can lead to admin or another account ATO

Emlog is an open source website building system. Version 2.5.23 has a stored cross-site scripting vulnerability that can lead to account takeover, including takeover of admin accounts. As of time of publication, no known patched versions are available.

πŸ“… Published: Jan. 2, 2026, 6:58 p.m. πŸ”„ Last Modified: April 18, 2026, 7:30 p.m.

2

CVSS4.0

CVE-2026-21431 - Emlog vulnerable to stored Cross-site Scripting via image name

Emlog is an open source website building system. Version 2.5.23 has a stored cross-site scripting vulnerability in the `Resource media library ` function while publishing an article. As of time of publication, no known patched versions are available.

πŸ“… Published: Jan. 2, 2026, 6:49 p.m. πŸ”„ Last Modified: April 18, 2026, 8:45 a.m.

7

CVSS4.0

CVE-2026-21430 - Emlog: CSRF chained with stored XSS leads to ATO

Emlog is an open source website building system. In version 2.5.23, article creation functionality is vulnerable to cross-site request forgery (CSRF). This can lead to a user being forced to post an article with arbitrary, attacker-controlled content. This, when combined with stored cross-site scri…

πŸ“… Published: Jan. 2, 2026, 6:44 p.m. πŸ”„ Last Modified: April 18, 2026, 8:45 a.m.

6.9

CVSS4.0

CVE-2026-0569 - code-projects Online Music Site AlbumByCategory.php sql injection

A vulnerability has been found in code-projects Online Music Site 1.0. This affects an unknown function of the file /Frontend/AlbumByCategory.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public …

πŸ“… Published: Jan. 2, 2026, 6:32 p.m. πŸ”„ Last Modified: April 18, 2026, 8:45 a.m.

6.9

CVSS4.0

CVE-2026-0568 - code-projects Online Music Site ViewSongs.php sql injection

A flaw has been found in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /Frontend/ViewSongs.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.

πŸ“… Published: Jan. 2, 2026, 6:02 p.m. πŸ”„ Last Modified: April 18, 2026, 8:45 a.m.
Total resulsts: 349182
Page 2301 of 34,919
Β« previous page Β» next page
Filters