4.8

CVSS4.0

CVE-2026-6219 - aandrew-me ytDownloader Compressor Feature compressor.js child_process.exec command injection

A vulnerability was determined in aandrew-me ytDownloader up to 3.20.2. This affects the function child_process.exec of the file src/compressor.js of the component Compressor Feature. This manipulation causes command injection. The attack can only be executed locally. The exploit has been publicly …

📅 Published: April 13, 2026, 8:45 p.m. 🔄 Last Modified: April 14, 2026, 7:37 p.m.

5.4

CVSS3.1

CVE-2026-33740 - EspoCRM: Email importEml can import and delete another user's attachment by raw fileId

EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/Email/importEml endpoint contains an Insecure Direct Object Reference (IDOR) vulnerability where the attacker-supplied fileId parameter is used to fetch any attachment directly from…

📅 Published: April 13, 2026, 8:37 p.m. 🔄 Last Modified: April 22, 2026, 12:04 a.m.

3.5

CVSS3.1

CVE-2026-33659 - EspoCRM: SSRF via DNS Rebinding in Attachment fromImageUrl Endpoint Allows Internal Network Access

EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/Attachment/fromImageUrl endpoint is vulnerable to Server-Side Request Forgery (SSRF) via a DNS rebinding (TOCTOU) condition. Host validation uses dns_get_record() but the actual HTT…

📅 Published: April 13, 2026, 8:32 p.m. 🔄 Last Modified: April 22, 2026, 12:07 a.m.

5.3

CVSS4.0

CVE-2026-6218 - aandrew-me ytDownloader Error Details Panel createTextNode cross site scripting

A vulnerability was found in aandrew-me ytDownloader up to 3.20.2. Affected by this issue is the function createTextNode of the component Error Details Panel. The manipulation results in cross site scripting. The attack may be performed from remote. The vendor was contacted early about this disclos…

📅 Published: April 13, 2026, 8:30 p.m. 🔄 Last Modified: April 14, 2026, 4:33 p.m.

8.7

CVSS4.0

CVE-2026-32272 - Craft Commerce: Blind SQL Injection via hasVariant/hasProduct

Craft Commerce is an ecommerce platform for Craft CMS. In versions 5.0.0 through 5.5.4, an SQL injection vulnerability exists where the ProductQuery::hasVariant and VariantQuery::hasProduct properties bypass the input sanitization blocklist added to ElementIndexesController in a prior security fix …

📅 Published: April 13, 2026, 8:25 p.m. 🔄 Last Modified: April 17, 2026, 3:26 p.m.

7.7

CVSS4.0

CVE-2026-32271 - Craft Commerce: SQL Injection can lead to Remote Code Execution via TotalRevenue Widget

Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, there is an SQL injection vulnerability in the Commerce TotalRevenue widget which allows any authenticated control panel user to achieve remote code execution through a four-step exploit…

📅 Published: April 13, 2026, 8:19 p.m. 🔄 Last Modified: April 17, 2026, 3:26 p.m.

5.1

CVSS4.0

CVE-2026-6216 - DbGate SVG Icon String FontIcon.svelte cross site scripting

A security vulnerability has been detected in DbGate up to 7.1.4. This affects an unknown function of the file packages/web/src/icons/FontIcon.svelte of the component SVG Icon String Handler. Such manipulation of the argument applicationIcon leads to cross site scripting. The attack may be launched…

📅 Published: April 13, 2026, 8:15 p.m. 🔄 Last Modified: April 14, 2026, 4:33 p.m.

1.7

CVSS4.0

CVE-2026-32270 - Craft Commerce: Unauthenticated information disclosure in `commerce/payments/pay` can leak some cus…

Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, the PaymentsController::actionPay discloses some order data to unauthenticated users when an order number is provided and the email check fails during an anonymous payment. The JSON erro…

📅 Published: April 13, 2026, 8:08 p.m. 🔄 Last Modified: April 17, 2026, 3:26 p.m.

4.6

CVSS3.1

CVE-2026-33657 - EspoCRM: Stored HTML injection in email notifications about stream notes via unescaped post field

EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have a stored HTML injection vulnerability that allows any authenticated user with standard (non-administrative) privileges to inject arbitrary HTML into system-generated email notifications by crafting…

📅 Published: April 13, 2026, 7:41 p.m. 🔄 Last Modified: April 22, 2026, 12:10 a.m.

5.3

CVSS4.0

CVE-2026-6215 - DbGate REST/GraphQL openApiDriver.ts apiServerUrl1 server-side request forgery

A weakness has been identified in DbGate up to 7.1.4. The impacted element is the function apiServerUrl1 of the file packages/rest/src/openApiDriver.ts of the component REST/GraphQL. This manipulation causes server-side request forgery. The attack may be initiated remotely. The exploit has been mad…

📅 Published: April 13, 2026, 7:30 p.m. 🔄 Last Modified: April 14, 2026, 4:33 p.m.
Total resulsts: 346671
Page 247 of 34,668
« previous page » next page
Filters